This role will focus on integration and execution of an effective Threat Modeling program into MUFG's Enterprise Information Security Risk Next Generation across Combined U.S. Operations (CUSO) processes and overall Application Security model
Job Summary
This role will focus on integration and execution of an effective Threat Modeling program into MUFG's Enterprise Information Security Risk Next Generation across Combined U.S. Operations (CUSO) processes and overall Application Security model.
Responsibilities include preforming threat modeling and providing security consulting to business developers, system designs, and engineers; developing and implementing security threat modeling plans; and supporting threat modeling tools along with identifying associated controls.
The typical base pay range for this role is between $140k - $185k depending on job-related knowledge, skills, experience, and location.
Matching Summary
This role will focus on integration and execution of an effective Threat Modeling program into MUFG's Enterprise Information Security Risk Next Generation across Combined U.S. Operations (CUSO) processes and overall Application Security model.
Salary
Base: $140k - $185k; Bonus/Equity: discretionary performance-based bonuses and/or incentive compensation; Benefits: comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays
Skills & Requirements
Must-have
Threat Modeling program
Application Security model
MITRE ATT&CK framework
secure coding
web applications
development life cycle (SSDLC)
CI/CD pipelines
Agile methodologies
Nice-to-have
investing in talent
collaboration toward innovation
banking or finance industries
highly-regulated environment
Key Requirements
6+ years of experience
Information security standards knowledge
Threat Modeling experience
Research real-world threat actor tactics
Common software security issues knowledge
Analyzing vulnerabilities and reporting
Windows/AD/Linux systems administration
Bachelor's degree in Computer Science or equivalent
CISSP, GIAC, or other security certifications desired