Phishing Simulation Program Lead at MUFG managing enterprise-wide training and campaigns to combat email threats while ensuring organizational security readiness.
Responsibilities
Lead all aspects of the phishing simulation program, including campaign development, operational workflows, analytics, and reporting.
Design and launch sophisticated simulations (phishing, smishing, quishing, deepfakes, spear-phishing, whaling, social engineering) using tools such as ProofPoint ZenGuide, Adaptive Security, KnowBe4, and Cofense PhishMe.
Conduct research on current threats and attack techniques, including those driven by generative AI, to ensure simulations reflect the latest risks.
Develop and deliver training materials and sessions to educate enterprise users on detection and risk/threat prevention related to email exploitation.
Analyze simulation results, manage reporting metrics (including 1x/2x/3x clickers), and provide actionable insights to stakeholders.
Work closely with other security teams to integrate simulation results into broader security awareness and data protection initiatives.
Continuously refine simulation strategies and techniques based on feedback, analytics, and evolving threat landscapes.
Requirements
3-5 years’ experience supporting a security awareness program, including phishing simulations.
2+ years’ experience in Financial Services or Banking, with a focus on information technology and information security (preferred).
Strong technical skills in campaign development, threat analysis, and security research.
Proficient in data analytics and Microsoft platforms.
Prior project or program management experience; ability to manage multiple activities simultaneously and influence indirect resources to achieve required outcomes.
Self-starter with the ability to coordinate activities across a global organization; able to work independently and as part of a team.
Excellent written and verbal communication skills.
Certification in information security or data privacy protection (e.g., Security+, CISSP) is a plus.
Benefits
Comprehensive health and wellness benefits
Retirement plans
Educational assistance and training programs
Income replacement for qualified employees with disabilities
Senior Security Engineer establishing and maintaining cybersecurity measures for a financial services company. Responsible for leading security event responses, documentation of policies, and training.
Senior Corporate Security Investigator at Duke Energy conducting complex investigations in support of Ethics, HR, Legal, Nuclear, and Enterprise Security with field mobility.
AI Enterprise Security Architect focusing on AI Security architectural standards and integrating security measures into AI development lifecycle. Leading a global team in securing AI systems.
Cloud Security Engineer supporting and securing client environments across AWS and hybrid infrastructures. Collaborating with Cloud Operations to monitor, investigate, and remediate security events.
Cybersecurity Risk Coordinator at Globo ensuring operational security across digital content. Analyzing risks and developing strategies to enhance business resilience.
Account Cybersecurity Lead providing cybersecurity governance and oversight at Capgemini. Leading client relationships, security management systems, and risk compliance oversight.
Senior SAP Security Specialist managing SAP Security responsibilities and projects. Collaborating on security tools and conducting workshops in Hamburg.
Sales Account Manager for Cyber Security and Awareness role at HvS - Consulting GmbH. Providing holistic consulting on Cyber Security services and managing client relationships.
Security Engineer at PRC - Saltillo safeguarding IT infrastructure from cyber threats. Collaborating with IT teams to design and maintain security controls in a hybrid work environment.
Information Security Manager leading cyber security initiatives at NVISO, enhancing clients’ security posture and managing a team of consultants in Germany.