Simplify Logo
Mitsubishi UFG

Mitsubishi UFG

Global banking, trust, asset management, securities.

Application Security Engineer

Full-Time
$140k - $203k/yr

+ Performance-based bonus + Incentive compensation

Senior
Bachelor's
Jersey City, NJ, USA
Hybrid

Four days on-site and one day remote per week.

No H1B Sponsorship

About the job

Requirements
  • Five or more years of experience in application security, secure development, dynamic application security testing, and static application security testing.
  • Hands-on experience with dynamic application security testing tools such as Invicti (Netsparker), AppScan, Burp Suite, or Acunetix.
  • Experience with static application security testing tools such as Veracode and Fortify.
  • Hands-on experience performing manual testing with Burp Suite.
  • Strong knowledge of web security vulnerabilities, including the OWASP Top 10, SANS Top 25, and MITRE ATT&CK.
  • Strong software development experience with Java and Python and/or .NET, including the ability to write production-quality code and scripts for security engineering and automation.
  • Familiarity with the secure software development life cycle and continuous integration and continuous delivery pipelines.
  • Scripting skills in Python, Bash, and PowerShell to automate security tasks.
  • A Bachelor's degree in Computer Science or a closely related discipline, or an equivalent combination of formal education and experience.
Responsibilities
  • Conduct dynamic application security testing scans using Invicti to identify application vulnerabilities.
  • Conduct static application security testing scans using Veracode to identify source-code vulnerabilities.
  • Conduct software composition analysis scans using Veracode to identify vulnerabilities in open-source components.
  • Compare static and dynamic application security testing results to ensure comprehensive vulnerability coverage.
  • Analyze scan results, identify root causes, and collaborate with developers to implement effective remediations.
  • Integrate security testing into continuous integration and continuous delivery pipelines and DevOps workflows.
  • Conduct manual verification and authenticated scans using Burp Suite as needed to reduce false negatives.
  • Understand and evaluate vulnerabilities in Java, .NET, Python, and other application codebases.
  • Partner with development teams to remediate security flaws and reinforce secure coding practices.
  • Provide guidance on OWASP Top 10 and SANS Top 25 vulnerabilities, including how they arise and how to prevent them.
  • Write scripts and code in Java and Python as needed for security engineering and automation.
  • Ensure required dynamic application security testing, static application security testing, and software composition analysis release and periodic scanning occurs and findings are addressed within service-level agreements.
  • Review and approve false positives and mitigated-by-design requests for dynamic application security testing, static application security testing, and software composition analysis.
  • Review and approve software development life cycle tasks for dynamic application security testing, static application security testing, and software composition analysis.
  • Maintain compliance with NIST, PCI-DSS, FFIEC, SOX, and CIS security frameworks.
  • Store and organize security artifacts in archives following standardized documentation practices.
  • Work closely with developers, DevOps teams, and application owners to secure software across all stages of the software development life cycle.
  • Automate security scanning processes through scripting and improve reporting capabilities.
  • Stay updated on exploitation techniques, security research, and industry best practices.
  • Collaborate effectively with developers and provide security guidance in a constructive manner.
  • Communicate through technical reporting and vulnerability documentation.
  • Apply an analytical approach to improving software security and reducing risk exposure.
Desired Qualifications
  • Relevant security certifications such as OSCP, OSWE, GWAPT, or CEH.
  • AI/ML security experience, including securing LLM-enabled applications and AI features, testing for prompt injection and data leakage, and evaluating model and dependency supply-chain risks.
  • Experience with cloud security using AWS, Azure, or Oracle Cloud.

About the company

MUFG is a large financial services group formed in 2005 by merging Mitsubishi Tokyo Financial Group and UFJ Holdings. It provides a wide range of services, including commercial banking, trust banking, securities, credit cards, and asset management, through a global network of banks, trust banks, securities firms, and asset management subsidiaries. Its products work by offering loans and deposits, investment products, payment services, and financial advisory to individuals, businesses, and institutions via branches, digital platforms, and partnerships. The company differentiates itself with its size and global reach, a diversified mix of financial offerings, and strategic international investments (notably the 2008 stake in Morgan Stanley) that expand its US and global presence. MUFG’s goal is to support economic growth worldwide by providing comprehensive financial solutions and pursuing sustainable finance and innovation.

Company Size

10,001+

Company Stage

IPO

Headquarters

Tokyo, Japan

Founded

2006

Get referred to Mitsubishi UFG

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • MUFG is building an open Japanese private-credit platform with BlackRock and Morgan Stanley.
  • Generate Capital closed a $117 million community-solar facility with MUFG on September 2026.
  • EarnIn secured a $75 million revolving facility from MUFG, deepening fintech lending pipelines.

What critics are saying

  • Japan's FSA still enforces 2024 firewall violations involving MUFG Bank and Morgan Stanley affiliates.
  • Indonesia's KPPU opened proceedings August 7, 2026 over MUFG Bank's late Mandala notification.
  • Grow Inc still needs regulatory, shareholder, and court approvals; integration delays can erase returns.

What makes Mitsubishi UFG unique

  • MUFG pairs Japan's largest corporate network with BlackRock and Morgan Stanley private-credit access.
  • MUFG launched Japan's first domestically domiciled tokenized JGB fund on September 3, 2026.
  • MUFG's MPMS acquisition of Grow Inc extends its pensions technology footprint across Australia.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

401(k) Retirement Plan

Paid Vacation

Paid Sick Leave

Paid Holidays

Parental Leave

Professional Development Budget

Remote Work Options

Flexible Work Hours

Company News

StreetInsider
Sep 15th, 2026
Generate Capital closes $117M community solar financing with MUFG

Generate Capital has closed a $117 million term debt facility with MUFG to finance a portfolio of community solar projects. The facility supports Generate's Community Solar Fund 11, comprising 18 projects totalling 114MWdc across Illinois and New York. This marks Generate's first community solar financing with MUFG. The transaction builds on approximately $1.4 billion in financing commitments the company secured during the first half of 2026. First-half highlights included closing a 104MW community solar portfolio with Monarch Private Capital, expected to deliver approximately $200 million in investment tax credits, and a $61 million senior secured US private placement for energy efficiency projects. Founded in 2014, Generate Capital focuses on accelerating the energy transition by providing reliable and affordable energy solutions. Since inception, the company has raised more than $16 billion in capital.

PR TIMES
Sep 15th, 2026
Miki Mori secures $20.7M credit facility from Mizuho and MUFG to fuel AI, robotics and energy expansion

Miki-Mori has secured a ¥3 billion credit facility with Mizuho Bank and MUFG Bank. The Tokyo-based trading company, which positions itself as a next-generation trading house leveraging AI and digital transformation, said the arrangement reflects confidence in its financial base and governance. Miki-Mori operates distribution of electronics and luxury watches, and has expanded into AI robotics solutions through a dealership with cleaning robot maker Gaussium. The company also develops grid-scale battery storage and data centre projects. Chief executive Ahn Yong-su said the credit line will support the firm's goal of reaching ¥1 trillion in revenue. Founded in 2014, Miki-Mori is a subsidiary of Miki-Mori Holdings.

ACROFAN
Sep 14th, 2026
Qupital raises $300M Series C led by M Capital to scale AI-driven e-commerce trade finance

Qupital, Asia's leading AI-driven fintech platform specialising in cross-border e-commerce trade finance, has raised $300 million in combined new capital commitments. The Series C round was led by M Capital, with additional asset-backed security commitments from Mitsubishi UFJ Financial Group and Quester Capital. The Hong Kong-based company has processed cumulative loans exceeding $9.5 billion and serves tens of thousands of enterprises. Qupital has been profitable for the past two years and expects profit margins to expand to over 45% within twelve months. The fresh capital will expand Qupital's financing capabilities across China, the US, Japan, and Southeast Asia, whilst further scaling its proprietary AI risk engine. The company is exploring capital market opportunities including an IPO, fundraising, and strategic acquisitions.

Kalkine Media
Sep 10th, 2026
Mitsubishi UFJ Financial Group Acquires 6.32% Stake, Becoming Major Shareholder in Corporate Travel Management

Catch the latest updates from Australia's premier stock exchange & market indices.

Kalkine Media
Sep 8th, 2026
Mitsubishi UFJ Financial Group Declares 5.68% Stake in Pilbara Minerals

Catch the latest updates from Australia's premier stock exchange & market indices.