MUFG
Assistant Vice President, Vulnerability Management

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About the Opportunity
Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
About MUFG
MUFG (Mitsubishi UFJ Financial Group) is one of the world's leading financial groups. Headquartered in Tokyo and with approximately 350 years of history, MUFG is a global network with around 2,300 offices in over 50 countries including the Americas, Europe, the Middle East and Africa, Asia and Oceania, and East Asia. The group has over 150,000 employees, offering services including commercial banking, trust banking, securities, credit cards, consumer finance, asset management, and leasing.
As one of the top financial groups globally with a vision to be the world's most trusted, we want to attract, nurture and retain the most talented individuals in the market. The size and range of MUFG's global business creates opportunities for our employees to stretch themselves and reap the rewards, whilst our common values, to behave with integrity and responsibility, and to build a culture which is fair, transparent, and honest, underpin everything that we do. We aim to be the financial partner of choice for our clients, whatever their requirements, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
MUFG’s shares trade on the Tokyo, Nagoya, and New York (NYSE: MTU) stock exchanges. The group’s operating companies include, but are not limited to, Bank of Tokyo-Mitsubishi UFJ, Mitsubishi UFJ Trust and Banking (Japan's leading trust bank), Mitsubishi UFJ Securities Holdings (one of Japan's largest securities firms), and MUFG Americas Holdings.
Please visit our website for more information - mufgemea.com.
About the Role
The IT Security function is responsible for cyber security strategy, governance, risk reduction, and operational security oversight across the organisation. This includes the implementation and oversight of security controls, vulnerability management, threat monitoring, compliance alignment, and incident/threat readiness to reduce cyber risk in line with business, regulatory, and enterprise expectations.
NUMBER OF DIRECT REPORTS
0
MAIN PURPOSE OF THE ROLE
The Assistant Vice President of Vulnerability Management supports the Vice President of Vulnerability Management in driving the operational evolution of MUFG’s Vulnerability Management and Security Compliance capabilities across EMEA Banking and Securities technology environments. The role combines deep cybersecurity expertise, risk-based decision making, and AI-driven security operations to reduce organisational cyber risk, improve remediation outcomes, and enhance overall security posture.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
This individual elevates traditional vulnerability management practices by addressing current industry challenges, including vulnerability volume growth, prioritisation complexity, remediation resource constraints, alert fatigue, and increasing exploit sophistication. Through the intelligent use of AI-driven analytics, threat intelligence, exposure assessment, and automation, the role will enable more effective identification, prioritisation, and remediation of vulnerabilities based on actual business risk and threat relevance.
The role is accountable for ensuring that vulnerability management, security governance, policy compliance, and risk management processes are effective, measurable, and aligned with MUFG security standards while supporting regulatory, audit, and operational risk requirements across EMEA.
Key Responsibilities
Vulnerability Management & Risk Reduction
- Reduce the vulnerability footprint across EMEA technologies by partnering with technology owners and product teams to drive remediation and mitigation activities.
- Develop strategic approaches to address vulnerability management challenges, including escalating vulnerability volumes, patching constraints, legacy technology risks, and limited remediation resources.
- Identify opportunities to automate vulnerability triage, risk assessment, reporting, and remediation workflows.
- Lead major risk reduction initiatives focused on critical vulnerabilities, attack path analysis, and exposure management.
Vulnerability Governance & Compliance
- Drive compliance with CIS Benchmarks, asset hardening standards, and other security frameworks.
- Ensure vulnerability management processes and procedures are documented and maintained in accordance with MUFG standards and regulatory expectations.
- Review and validate vulnerability assessment outputs and support consistent risk classification methodologies.
Security Risk Assessment & Prioritisation
- Assess emerging vulnerabilities impacting crown-jewel assets and critical business services, leveraging AI Mythos insights, threat intelligence, exploitability analysis, and business context to determine risk exposure and drive remediation priorities.
- Support the evolution of vulnerability management from a compliance-focused activity to a risk-based exposure management capability through continuous assessment of security posture, attack paths, and threat-informed risk analytics.
Stakeholder Management & Security Advisory
- Act as a trusted advisor to technology, infrastructure, application, and business teams on vulnerability management and cyber risk matters.
- Collaborate with stakeholders to define practical remediation and mitigation plans that balance security requirements with operational considerations.
- Promote consistent security standards, controls, and best practices across Banking and Securities technology functions.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Security Monitoring & Posture Management
- Identify security control weaknesses and coordinate corrective actions.
- Ensure that technical safeguards across operating systems, databases, networks, cloud platforms, and applications are appropriately implemented and managed.
- Support proactive identification and management of security threats, vulnerabilities, and emerging attack techniques.
Audit, Regulatory & Risk Management Support
- Support internal and external audits, regulatory reviews, and information security assessments.
- Act as a key liaison between Technology, Operational Risk, Compliance, regulators, auditors, and Head Office stakeholders.
Work Experience
Essential:
- 10 years of experience in vulnerability management or cyber risk functions
- Experience in financial services or highly regulated environments
- Qualys Cloud Portal & PowerBI
- Knowledge of cloud security frameworks, AI Mythos, Cyber tools and technologies
- Experience collaborating with DLP, Endpoint Security, Infrastructure, and Application Security teams to support risk remediation and control effectiveness.
Skills and Experience
Essential
- Degree educated or equivalent experience
- Expertise in vulnerability scanning tools (e.g., Qualys, ServiceNow SecOps VR)
- Knowledge of patch management and system hardening practices
- Strong analytical and problem-solving skills
- Stakeholder management
Education / Qualifications
Essential
- Degree educated and / or equivalent experience.
Personal Requirements
- Excellent communication skills
- Results driven, with a strong sense of accountability
- A proactive, motivated approach.
- The ability to operate with urgency and prioritise work accordingly
- Strong decision making skills, the ability to demonstrate sound judgement
- A structured and logical approach to work
- Strong problem solving skills
- A creative and innovative approach to work
- Excellent interpersonal skills
- The ability to manage large workloads and tight deadlines
- Excellent attention to detail and accuracy
- A calm approach, with the ability to perform well in a pressurised environment
We are open to considering flexible working requests in line with organisational requirements.
Diversity and Inclusion
MUFG is committed to embracing diversity and building an inclusive culture where all employees are valued, respected and their opinions count. We support the principles of equality, diversity and inclusion in recruitment and employment, and oppose all forms of discrimination on the grounds of age, sex, gender, sexual orientation, disability, pregnancy and maternity, race, gender reassignment, religion or belief and marriage or civil partnership.
We make our recruitment decisions in a non-discriminatory manner in accordance with our commitment to identifying the right skills for the right role and our obligations under the law.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location