MUFG Logo

MUFG

Threat Detection and Response, Analyst

Posted Yesterday
Be an Early Applicant
In-Office or Remote
Hiring Remotely in United States
Mid level
In-Office or Remote
Hiring Remotely in United States
Mid level
Analyze cyber threats, perform detection and incident response, support forensic investigations, develop SIEM/SOAR use cases and playbooks, automate detection/remediation, monitor environments, and produce adversary behavior reports while mentoring junior staff.
The summary above was generated by AI

Do you want your voice heard and your actions to count?

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.

With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.

Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.

Position details

In this role you will focus on researching threats posed by cyber criminals to various systems, technologies, operations, and programs, and analyzing research to determine a cyber criminal’s capabilities, intentions, and attack approaches, including those with multiple phases. Responsibilities include rapidly responding to incidents to minimize risk exposure and ensure system availability; proactively monitoring internal and external-facing environments; seeking opportunities to automate detection and remediation and reduce response times for incidents; and producing reports and briefings that include perspectives on the behavior of adversaries.

Roles and Responsibilities

  • Perform cybersecurity threat detection, assessment, and mitigation efforts
  • Support inquiries from compliance teams such as IT risk management and internal and external audit, to ensure documentation is complete and in compliance with information security policies
  • Identify, evaluate, and monitor continually threats that could affect operational and business activities
  • Support development of security operations playbooks to ensure threat detection, monitoring, response, and forensics activities align with best practices, minimize gaps in detection and response, and provide comprehensive mitigation of threats
  • Create, Enhance and manage security use cases, dashboards and alerts using Splunk
  • Research and look for opportunities to adopt the best practices and industry standards to enhance the SIEM and SOAR platforms
  • Provide guidance to junior team members

Job Requirements:

  • Bachelor’s degree in business, Management, Computer Sciences, or equivalent prior work experience in a related field
  • Minimum of 3-5 years’ overall experience working in global, complex, matrix-managed organization
  • Minimum of 2 years’ working experience in Cybersecurity Operations or Information Security
  • Minimum of 2 years' experience in Incident Response and Forensic Investigations work
  • Minimum of 2 years' experience in threat and vulnerability management
  • Understanding of enterprise detection technologies and processes (advanced threat detection tools, intrusion detection system/intrusion prevention system (IDS/IPS), network packet analysis, endpoint protection, Anti malware/anti-virus).
  • Understanding of network protocols and operating systems (Windows, Unix, Linux, databases)
  • Knowledge in one or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, and Incident Response and Forensics
  • Knowledge of the following areas: IT security, incident handling and response, exploit analysis, intelligence gathering, digital forensics methods and procedures.
  • Knowledge of Splunk, Phantom, Python, CrowdStrike, Tanium, Defender, Azure, AWS and forensic security tools is preferred.
  • Knowledge of Information Assurance concepts and technologies
  • Knowledge of cloud computing security, network, operating system, database, application, and mobile device security.
  • Knowledge of vulnerability management and remediation.
  • A diverse skill base in both product security and information security including organizational structure and administration practices, system development and maintenance procedures, system software and hardware security controls, access controls, computer operations, physical and environmental controls, and backup and recovery procedures.
  • Solid experience in day-to-day operational processes such as security monitoring, data correlation, troubleshooting, security operations, etc.
  • Experience working within the Financial Services Industry preferred.
  • Experience in one or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, and Incident Response and Forensics preferred.
  • Experience with information security risk management, including conducting information security audits, reviews, and risk assessments.
  • Knowledge of the Amazon Web Services (AWS) and/or Azure for infrastructure is preferred
  • Working experience with MITRE ATT&CK or similar frameworks is preferred
  • One to three years of experience in Splunk, Splunk Enterprise Security or Splunk Phantom is preferred
  • Knowledge of scripting languages like Python is preferred
  • Knowledge in RegEx is preferred
  • Strong analytical skills (i.e., technical and non-technical problem solving skills).
  • Maintain certifications in an information security related field. The following are recommended:  CySA+, CISSP, ISSMP, SANS, GCIA, CISM, EnCE, CEH, GCFA, GCFE, GCIH, or GSEC and/or Splunk Certifications.

Mitsubishi UFJ Financial Group (MUFG) is an equal opportunity employer. We view our employees as our key assets as they are fundamental to our long-term growth and success. MUFG is committed to hiring based on merit and organsational fit, regardless of race, religion or gender.

Similar Jobs

10 Hours Ago
In-Office or Remote
United States
Senior level
Senior level
Fintech
Lead threat detection and response: research adversary behavior, monitor environments, respond to incidents, build SIEM/SOAR use cases (Splunk), perform forensics and cloud IR, produce reports, automate detection and remediation, and mentor junior analysts.
Top Skills: Anti-MalwareAWSAzureCrowdstrikeDatabasesEncaseFirewallFtkGCPIdsIpsKill ChainLinuxMdsMicrosoft DefenderMitre Att&CkProxyPythonRedlineRegexSIEMSiftSoarSplunkSplunk Enterprise SecuritySplunk PhantomTaniumTcpdumpUnixVolatilityVpnWafWindowsWireshark
Yesterday
In-Office or Remote
United States
Mid level
Mid level
Fintech
Investigate and analyze cyber threats, perform incident response and forensics, monitor and tune detection across environments, develop SIEM/SOAR use cases (Splunk/Phantom), automate detection/remediation, support audits and compliance, produce threat reports/briefings, and mentor junior analysts.
Top Skills: Anti-MalwareAWSAzureCrowdstrikeEndpoint ProtectionForensic Security ToolsIds/IpsMicrosoft DefenderMitre Att&CkNetwork Packet AnalysisPythonRegexSplunkSplunk Enterprise SecuritySplunk PhantomTanium
Yesterday
In-Office or Remote
United States
Senior level
Senior level
Fintech
Lead threat detection and response efforts: research adversary behavior, monitor environments, respond rapidly to incidents, develop SIEM/SOAR use cases and playbooks, perform forensics, automate detection/remediation, produce reports, and mentor junior analysts.
Top Skills: Anti-MalwareAnti-VirusAWSAzureCrowdstrikeEncaseEndpoint ProtectionFtkGCPIdsIpsKill ChainMdsMicrosoft DefenderMitre Att&CkProxyPythonRedlineRegexSIEMSiftSoarSplunkSplunk Enterprise SecuritySplunk PhantomTaniumTcpdumpVolatilityVpnWafWireshark

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account