MUFG
Vice President, Risk and Control Lead - Architecture, Middleware and Data Management

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
MUFG is one of the world’s leading financial groups, headquartered in Tokyo and with a global network across the Americas, Europe, the Middle East and Africa, Asia and Oceania. The group provides services including commercial banking, trust banking, securities, credit cards, consumer finance, asset management and leasing.
Architecture, Middleware, Data Management & Enterprise Services (AMD) is part of EMEA Technology. AMD brings together technology functions that support the delivery, operation and governance of key platforms and services across enterprise architecture, interfaces, data engineering and business intelligence, project delivery, finance technology, compliance technology, digital delivery and related enterprise services.
The Risk and Control Manager
The Risk and Control Manager will support AMD management by helping maintain a clear, evidence-based view of technology risk, control performance, audit readiness and remediation progress across the AMD portfolio. The role will work closely with AMD application, platform and service owners, Technology Risk & Control, Information Security, Operational Risk, Internal Audit and wider Technology stakeholders.
Main Purpose of the Role
The role is responsible for supporting the AMD leadership team in managing technology risk and controls across the AMD function. This includes maintaining risk and control MI, coordinating control testing and evidence, supporting risk appetite reporting, tracking issues and remediation actions, preparing for audits and regulatory reviews, and helping AMD teams operate in line with Technology policies, standards and governance requirements.
Key Responsibilities
- Partner with AMD management, service owners, control owners and lines of defence to identify, document, assess and manage technology risks, controls, issues and actions.
- Support the definition, maintenance and reporting of AMD’s risk appetite measures, including measures that are meaningful from a risk perspective, capable of being tracked, and within AMD’s ability to influence.
- Develop and maintain clear MI, dashboards and reporting for AMD risks and controls, including risks relating to vulnerabilities, end-of-life technology, incident management, change management, access management, resilience, data protection and operational hygiene.
- Coordinate control evidence across AMD teams for audits, self-assessments, control testing, regulatory reviews and management assurance activities, ensuring responses are complete, accurate and timely.
- Track audit findings, self-identified issues, risk acceptances, management actions and remediation plans, providing early escalation where delivery is off track, ownership is unclear or risk remains outside tolerance.
- Validate issue closure evidence before submission to the relevant governance, control or audit function, ensuring that remediation is sustainable and appropriately evidenced.
- Support AMD teams in the operation of core Technology governance processes, including change management, incident management, privileged access management, disaster recovery, business impact analysis and policy compliance.
- Work with Technology Risk & Control, Information Security, Operational Risk, Internal Audit and Head Office stakeholders to ensure AMD requirements are understood, coordinated and delivered.
- Challenge unclear ownership, weak evidence, inconsistent controls and incomplete risk assessments in a constructive and practical manner.
- Promote a strong risk and control culture within AMD by improving awareness, clarity of ownership and management understanding of key technology risk topics.
- Identify opportunities to simplify, automate and improve risk and control reporting, including use of data sources, workflow tools and analytics to reduce manual effort and improve transparency.
- Prepare concise, senior-management-ready materials for AMD governance meetings, risk forums, executive committees and other oversight bodies as required.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Skills and Experience
- Strong understanding of technology risk, IT controls and control frameworks such as COBIT, NIST, ISO 27001, ITIL and related financial services control expectations.
- Experience in first line technology risk and controls, internal audit, external audit, operational risk, information security or technology assurance within a financial services environment.
- Good understanding of application, infrastructure, data, integration and cloud technology risks, including resilience, cyber security, access, change, incident, vulnerability and end-of-life risks.
- Experience supporting audit, regulatory or control testing activity, including evidence collection, management action planning and issue closure validation.
- Strong knowledge of technology governance processes such as change management, incident/problem management, access management, service resilience, disaster recovery and policy attestation.
- Experience producing clear management information, dashboards, risk reports and executive-level materials.
- Ability to interpret policy and control requirements and translate them into practical actions for technology teams.
- Strong stakeholder management skills, with the ability to influence and constructively challenge senior managers, technical teams and control functions.
- Strong written communication skills, with the ability to explain risk and control matters clearly to both technical and non-technical audiences.
- Comfortable working with data, spreadsheets, workflow tools and reporting platforms to improve control transparency and reduce manual reporting effort.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Personal Requirements
- Self-motivated, proactive and comfortable working with limited direction.
- Able to balance risk with delivery priorities and apply sound judgement when escalating issues.
- Structured, organised and able to manage multiple priorities across a broad technology portfolio.
- Clear, concise and credible communicator, able to simplify complex control topics for senior stakeholders.
- Collaborative and able to build strong relationships with technology, risk, control, audit and business stakeholders.
- Analytical, objective and evidence-led, with strong attention to detail.
- Results driven, with a strong sense of ownership and accountability.
- Able to work effectively under pressure and to tight deadlines.
- Curious and willing to learn new technologies, tools and data-driven approaches to risk management.
- Demonstrates a global perspective and an understanding of the financial services and banking environment.
We are open to considering flexible working requests in line with organisational requirements.
MUFG is committed to embracing diversity and building an inclusive culture where all employees are valued, respected and their opinions count. We support the principles of equality, diversity and inclusion in recruitment and employment, and oppose all forms of discrimination on the grounds of age, sex, gender, sexual orientation, disability, pregnancy and maternity, race, gender reassignment, religion or belief and marriage or civil partnership.
We make our recruitment decisions in a non-discriminatory manner in accordance with our commitment to identifying the right skills for the right role and our obligations under the law.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location