MUFG
Assistant Vice President, IAM Governance

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Identity and Access Management Governance Manager
MUFG, one of the world’s leading financial groups with a rich heritage spanning over 350 years, is seeking an Identity and Access Management Governance Manager at Assistant Vice President level to join their IT Risk division in London. This pivotal role offers you the opportunity to shape and oversee the governance of identity and access management processes, ensuring robust risk management and compliance across a multi-year remediation programme.
What you'll do:
As an Identity and Access Management Governance Manager, you will play an essential role in overseeing risk management frameworks related to identity and access controls. Your day-to-day responsibilities will involve collaborating with various teams to define robust controls, developing monitoring strategies that provide transparency into performance metrics, coordinating remediation efforts across business units, and preparing detailed reports for governance meetings. You will also facilitate stakeholder engagement in managing toxic combinations within applications, act as a liaison for audit-related activities, address risks within development lifecycles, and ensure that all participants adhere to established standards.
- Work closely with the wider Identity and Access Management (IAM) team and other control functions to define key controls for IAM processes, ensuring alignment with audit and regulatory requirements.
- Design effective strategies for continuous control monitoring by developing Key Control Indicators (KCIs) and Key Risk Indicators (KRIs) that assess performance across IAM controls.
- Assist in creating formal testing strategies for IAM controls, collaborating with technical teams to ensure thorough evaluation and remediation.
- Monitor progress on remediation initiatives by partnering with technology and business application owners to ensure commitments are met throughout the programme lifecycle.
- Coordinate the Toxic Combination framework by facilitating full participation from business and technology stakeholders, ensuring violations are managed appropriately.
- Prepare comprehensive management information reports for IAM Governance meetings, transparently communicating process performance and escalating issues as needed.
- Act as a point of contact for addressing IAM risks within the Software Development Lifecycle (SDLC), ensuring risks are mitigated effectively.
- Engage proactively with internal and external audit teams regarding identity and access management risks, providing clear communication and documentation.
- Support the design and delivery of remediation programmes to ensure key risks are addressed efficiently while maintaining compliance with industry standards.
- Facilitate clear communication between organisational functions, business units, and offices both locally and internationally to promote understanding of IAM governance.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What you bring:
Your proven track record in identity and access management within financial services will enable you to bring valuable insights into risk mitigation strategies. You possess deep familiarity with regulatory expectations around technology risk—including audit cycles—and have demonstrated your ability to leverage best practice frameworks like NIST or SOX. Your experience spans both technical competencies (such as developing monitoring indicators or automating data production) as well as interpersonal skills: you excel at building relationships across business units, facilitating clear communication between local and international teams, and presenting complex information concisely.
- Demonstrable experience within an Identity and Access Management function in a regulated financial services environment is essential for success in this role.
- At least three years’ experience in technology-focused risk or control functions provides you with the foundation needed to understand complex operational challenges.
- Working knowledge of banking or securities products enables credible engagement with application owners on topics such as toxic combinations or segregation of duties.
- Proven understanding of Information Security and Technology Risk management practices ensures you can apply these domains effectively within financial institutions.
- Strong technical knowledge of external laws, regulations (including SOX), policies, frameworks such as NIST or DORA relevant to technology risk is required.
- Experience developing continuous control monitoring strategies—including automation of reporting—demonstrates your commitment to efficiency.
- Ability to develop effective control testing strategies shows your skill in evaluating risk mitigation measures thoroughly.
- Excellent written and verbal communication skills allow you to simplify complex concepts for diverse audiences.
- Educated to degree level; CISSP or CISM qualifications are desirable but not mandatory.
- Meticulous attention to detail combined with strong organisational skills ensures accuracy in reporting and process oversight.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
What sets this company apart:
This organisation stands out as one of the world’s most respected financial institutions thanks to its long-standing commitment to integrity, responsibility, fairness, transparency, honesty—and shared growth. Employees benefit from being part of an international network spanning over 50 countries; this global reach creates unique opportunities for personal development through cross-border collaboration. The company’s vision centres on nurturing talent: it invests heavily in training opportunities so individuals can stretch themselves professionally while enjoying flexible working arrangements that support work-life balance. The culture is inclusive—valuing diversity of thought—and supportive leadership ensures everyone feels connected within their team.
What's next:
If you are ready to take the next step in your career by joining a globally respected institution where your expertise will be valued—apply now!
Apply today by clicking on the link provided. We are open to considering flexible working requests in line with organisational requirements.
MUFG is committed to embracing diversity and building an inclusive culture where all employees are valued, respected and their opinions count. We support the principles of equality, diversity and inclusion in recruitment and employment, and oppose all forms of discrimination on the grounds of age, sex, gender, sexual orientation, disability, pregnancy and maternity, race, gender reassignment, religion or belief and marriage or civil partnership.
We make our recruitment decisions in a non-discriminatory manner in accordance with our commitment to identifying the right skills for the right role and our obligations under the law.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location