Full-Time

Vice President

Threat and Vulnerability Management

Mitsubishi UFG

Mitsubishi UFG

10,001+ employees

Global banking, trust, asset management, securities.

No salary listed

London, UK

In Person

Category
Cybersecurity (1)
Required Skills
PowerShell
Microsoft Azure
Python
Incident Response
Data Visualization
LDAP
Operating Systems
Cybersecurity
AWS
JIRA
Risk Management
VMWare
MongoDB
Penetration Testing
Confluence
Nutanix
Splunk
Oracle

Get referred to Mitsubishi UFG

See people who can refer or advise you

Requirements
  • Proven experience of directly managing a team of Threat and Vulnerability Engineers, including mentoring, developing, and guiding security professionals in a collaborative, high-performing environment.
  • Strong strategic thinking and visionary skills with the ability to co-develop and drive the function’s technical vision, strategy, and roadmap aligned with business goals and risk appetite.
  • Prior extensive experience working within infrastructure environments and cloud platforms, including AWS, Azure, and Oracle, with a high-level understanding of platforms, operating systems, and technologies.
  • Proven capability in creating and executing comprehensive threat and vulnerability management programmes, including vulnerability scanning, penetration testing, and security awareness training.
  • Proficiency in using vulnerability scanning tools such as Tenable, Qualys, Rapid7, Veracode, and JFrog Xray, as well as threat intelligence platforms and incident response tools.
  • Prior experience implementing automated solutions for vulnerability scanning, threat detection, and incident response, with a focus on continuous process improvement.
  • Strong familiarity with security frameworks and standards such as NIST and ISO 27001, and deep understanding of vulnerability management, threat intelligence, incident response, and offensive security techniques.
  • Experience gathering and analysing threat intelligence to understand emerging threats, attack vectors, and threat actors, while maintaining up-to-date knowledge of security threats, vulnerabilities, and best practices.
  • Strong analytical and problem-solving skills to analyse data, identify patterns, and develop effective solutions to mitigate risk.
  • Proven ability to communicate effectively with senior management, providing governance and risk oversight.
  • Excellent verbal and written communication skills to report findings and collaborate across cross-functional Technology and non-Technology teams.
  • Ability to translate technical risks into business-relevant language for technical and non-technical stakeholders, including executive leadership.
  • Recognised cybersecurity certification: Certified Information Systems Security Professional (CISSP) and/or Certified Information Security Manager (CISM).
  • Strong knowledge of Ivanti LANDesk, Qualys, Splunk, Windows Server/Desktop, RHEL/OEL Linux, PowerShell, and Python scripting.
  • Proven experience leading strategic security initiatives and process automation in large-scale environments.
Responsibilities
  • Lead the design, development, operation, and management of the department’s Threat and Vulnerability Management strategy and roadmaps, ensuring alignment with business requirements, services, strategic goals, and IT risk appetite.
  • Develop short-, medium-, and long-term strategic goals and objectives for DES Threat and Vulnerability Management, including documenting the current environment and defining the future roadmap.
  • Define measurable, repeatable processes and reporting metrics, subject to continuous improvement.
  • Define the DES Threat and Vulnerability function’s Key Risk Indicators and govern accordingly; produce regular Key Performance Indicator, management information, and risk management data for senior management.
  • Identify cost-saving and optimisation opportunities within MUFG EMEA and the wider MUFG group.
  • Lead a team of Threat and Vulnerability Engineers to deliver best-practice operations and strategic development while adhering to MUFG policies and procedures.
  • Oversee the successful deployment of routine and out-of-band security patches across IT infrastructure.
  • Automate patch deployments and associated post-deployment check-outs.
  • Triage vulnerabilities into Fix, Acknowledge, and Investigate categories using industry-aligned risk-rating methodologies.
  • Use ServiceNow Application Vulnerability Response and Vulnerability Response modules to manage and report on vulnerabilities and violations across the estate, integrating with dashboards and workflows for visibility and accountability.
  • Work with other technology teams to provide in-depth analysis of vulnerabilities and impacts to key stakeholders.
  • Collaborate with application teams to ensure secure coding practices and timely remediation of vulnerabilities, aligned with criticality-based policy enforcement.
  • Prioritise weaknesses in IT infrastructure and applications using manual and automated methods, including results from Static Application Security Testing and Software Composition Analysis tooling in conjunction with the Service Transition team.
  • Influence stakeholders to prioritise and drive remediation of process and technology gaps.
  • Work with Cyber Security, Application Teams, and IT Risk to ensure controls are met and vulnerabilities are addressed across infrastructure and applications.
  • Engage and support Cyber Security with remediation of penetration-test findings.
  • Engage with internal and external auditors as the subject-matter expert on matters relating to vulnerability management.
  • Act as the primary subject-matter expert and point of contact for the Threat and Vulnerability Management function within DES.
  • Work with industry partners, vendors, and the wider technology ecosystem to leverage external expertise and best practices; conduct market research to identify emerging risk and vulnerability trends.
  • Build strong relationships across Bank and Securities functions, including IT Risk and Control, Cyber Security, and Operational Risk.
  • Lead by example in building relationships across the Bank, strengthening peer networks and collaboration.
  • Champion staff cyber education and awareness to embed a proactive cyber-focused culture.
  • Promote a dynamic, delivery-driven culture that works alongside Technology and Business units to provide responsive resolutions and value-driven solutions.
Desired Qualifications
  • Additional certification: Certified Cloud Security Professional (CCSP).
  • Familiarity with CyberArk Privileged Access Management and ServiceNow SecOps Vulnerability Response/Application Vulnerability Response.
  • Familiarity with VMware, Nutanix, and Java Virtual Machine.
  • Familiarity with MSSQL, Oracle, and MongoDB.
  • Familiarity with Red Hat Satellite, Active Directory, LDAP, and Kerberos.
  • Familiarity with Confluence and JIRA.
  • Familiarity with General Data Protection Regulation and Sarbanes-Oxley compliance frameworks.

MUFG is a large financial services group formed in 2005 by merging Mitsubishi Tokyo Financial Group and UFJ Holdings. It provides a wide range of services, including commercial banking, trust banking, securities, credit cards, and asset management, through a global network of banks, trust banks, securities firms, and asset management subsidiaries. Its products work by offering loans and deposits, investment products, payment services, and financial advisory to individuals, businesses, and institutions via branches, digital platforms, and partnerships. The company differentiates itself with its size and global reach, a diversified mix of financial offerings, and strategic international investments (notably the 2008 stake in Morgan Stanley) that expand its US and global presence. MUFG’s goal is to support economic growth worldwide by providing comprehensive financial solutions and pursuing sustainable finance and innovation.

Company Size

10,001+

Company Stage

IPO

Headquarters

Tokyo, Japan

Founded

2006

Get referred to Mitsubishi UFG

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • August 3, 2026 quarterly profit jumped 48%, driven by higher loan margins.
  • MUFG kept its fiscal 2027 profit target at ¥2.7 trillion on August 3, 2026.
  • September 3, 2026 tokenized JGB fund and September 1, 2026 private credit talks expand fee businesses.

What critics are saying

  • Japan FSA firewall penalties still haunt MUFG after the 2024 client-data breach.
  • Mitsubishi UFJ Morgan Stanley Securities faces Credit Suisse AT1 suits through 2026.
  • A UK forex cartel mass claim named MUFG in July 2026; damages remain open.

What makes Mitsubishi UFG unique

  • MUFG combines Japan's largest lender balance sheet with Morgan Stanley ties since 2008.
  • Progmat and September 2, 2026 stablecoin work make MUFG Japan's tokenization leader.
  • September 1, 2026 BlackRock and MSIM talks widen MUFG's private credit distribution edge.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

401(k) Retirement Plan

Paid Vacation

Paid Sick Leave

Paid Holidays

Parental Leave

Professional Development Budget

Remote Work Options

Flexible Work Hours

Company News

Kalkine Media
Sep 8th, 2026
Mitsubishi UFJ Financial Group Declares 5.68% Stake in Pilbara Minerals

Catch the latest updates from Australia's premier stock exchange & market indices.

Finadium
Sep 3rd, 2026
BigGo: MUFG launches Japan's first domestic JGB tokenized fund.

BigGo: MUFG launches Japan's first domestic JGB tokenized fund. September 3, 2026 Four Mitsubishi UFJ Financial Group companies - Mitsubishi UFJ Asset Management, Mitsubishi UFJ Morgan Stanley Securities, Mitsubishi UFJ Trust Bank, and Progmat - established the first domestically domiciled tokenized investment trust in Japan and began verification in a live production environment, reports BigGo Finance. The fund deploys ¥200 million (approximately $1.3 million) of proprietary capital in short-term Japanese government bonds with remaining maturities of three months or less, and will not be offered to external investors. Beneficiary registry management is conducted on a blockchain, while the certificate-based representation of units is maintained. The objective is to connect the fund with stablecoins and tokenized deposits, transforming investment trusts into "usable assets" that can serve as settlement instruments or collateral. However, institutional constraints remain, as the legal framework for Japanese investment trusts presupposes the physical certificate representation of beneficiary rights. Your Finadium username has not changed. In most cases, your existing password will continue to work on this updated site. If your password does not work, please click the "Lost your password?" link below to set a new password on the upgraded system.

Web-Release
Sep 2nd, 2026
MUFG EMEA appoints Bénédicte de Giafferri as Head of Digital Infrastructure Coverage.

MUFG EMEA appoints Bénédicte de Giafferri as Head of Digital Infrastructure Coverage. MUFG EMEA today announces the appointment of Bénédicte de Giafferri as Managing Director, Head of Digital Infrastructure Coverage for EMEA. In this newly created role, Bénédicte will further develop client relationships to deliver MUFG's pipeline of digital transactions, including data centres, in a product-agnostic role. As part of MUFG's EMEA coverage business, she will support clients with diversification of funding for this growing sector, which is evolving from traditional project financing to include corporate and securitisation structures. Bénédicte, with over 25 years' experience in banking and infrastructure finance, will build out the digital infrastructure strategy for EMEA and lead the EMEA team, working in close collaboration with colleagues in U.S. and APAC regions. She will be based in Paris and report locally to Genoveva Ramon-Borja, Head of Global Corporate and Investment Banking EU Platform and Corporate Coverage, and functionally to Holly Villiers, Deputy Head of Global Corporate and Investment Banking, EMEA. Bénédicte spent the past 16 years at Natixis, most recently leading the Real Assets worldwide origination teams for five years. Her previous roles included various positions at the European Investment Bank and Dexia Crédit Local. Genoveva Ramon-Borja, Head of Global Corporate and Investment Banking EU Platform and Corporate Coverage, said: "This role was designed with a truly regional mandate, supporting digital infrastructure clients across EMEA, irrespective of location. Reflecting that, we conducted a talent search across the entire region to identify the strongest leader for the business, and Bénédicte emerged as the clear standout candidate. Her deep sector expertise, strong client relationships and international perspective will be invaluable as we continue to strengthen our digital infrastructure franchise and support clients across EMEA in this fast-evolving market." Holly Villiers, Deputy Head of Global Corporate and Investment Banking, EMEA, said: "Digital infrastructure is one of the most dynamic and strategically important sectors in EMEA today, necessitating the rapid evolution of financing structures. Bénédicte's experience will be instrumental as we continue to build our pipeline in the sector and support clients in navigating an increasingly diversified funding landscape. Her leadership will further enhance our ability to deliver innovative financing solutions across the capital structure and deepen our relationships with clients across the region." Bénédicte de Giafferri, Managing Director, Head of Digital Infrastructure Coverage, EMEA, said: "I am delighted to be joining MUFG at such an exciting time for both the bank and the digital infrastructure sector. Demand for digital infrastructure continues to accelerate, creating significant opportunities for clients as funding models evolve and new pools of capital enter the market. I look forward to working with colleagues across EMEA, the U.S. and APAC to build on MUFG's strong franchise and support clients with their strategic ambitions in this rapidly growing sector."

Royal Crescent Publishing Limited
Sep 1st, 2026
MUFG taps BlackRock and Morgan Stanley as it eyes Japanese private credit.

MUFG taps BlackRock and Morgan Stanley as it eyes Japanese private credit. September 1 2026 Mitsubishi UFJ Financial Group (MUFG) is exploring separate collaborations with BlackRock and Morgan Stanley Investment Management (MSIM) to develop an open platform for institutional investment in Japanese private credit. MUFG has entered into discussions with both firms on developing Japan's private credit segment, as the country's nascent market starts to attract global investors and managers look to expand their presence in the region. The potential collaborations aim to connect domestic and global capital with Japanese companies, MUFG said. The discussions will cover the evaluation, sourcing and investment in private credit opportunities, it added. MUFG brings a large Japanese corporate client network and local market access to the partnerships, while BlackRock contributes global private credit expertise through its HPS platform. MSIM, also brings its experience in the space, having provided debt solutions to businesses globally for more than 15 years. Japan's private credit market remains at a relatively early stage of development compared with those in Europe and the US. However, private credit firms, encouraged by a combination of macroeconomic factors and changing investor attitudes towards alternative credit, have recently been expanding their presence in Japan. For example, Fiera Capital opened a Tokyo office in October 2025 and made a number of hires, including Chinatsu Aoyama as director, private markets specialist, earlier this year.

The SaaS News
Sep 1st, 2026
EarnIn raises $75M Debt Financing.

EarnIn raises $75M Debt Financing. EarnIn secures a $75M debt financing facility from MUFG to support the expansion of its real-time earnings management platform and financial wellness products. Updated August 31, 2026 EarnIn, a fintech company providing earnings management and financial wellness solutions, has secured a $75M senior secured revolving credit facility from Mitsubishi UFJ Financial Group (MUFG). Investors. Mitsubishi UFJ Financial Group (MUFG) served as the sole lender for this financing facility. EarnIn use of funds. The company plans to use the capital to provide scalable and cost-effective funding to support its growth and the expansion of its suite of products, including its flagship offering, Live Pay. About EarnIn. EarnIn is a fintech company focused on earned wage access and financial wellness. Its products include Early Pay, which gives workers access to wages up to two days before payday, and Cash Out, which allows employees to access a portion of their earned income before payday. Its Live Pay product enables employees to stream their earnings in real time. Funding details. Company: EarnIn Raised: $75M Round: Debt Financing Funding Date: September 4, 2025 Lead Investor: Mitsubishi UFJ Financial Group (MUFG) Software Category: FinTech Source: https://fintech.global/2025/09/04/earnings-platform-earnin-secures-75m-financing-from-mufg/ Updated August 31, 2026