Vice President, CITB Risk and Control Lead
MUFG Bank, Ltd.
📍 On-site
Category: SecuritySubcategory: Compliance & RiskType: Full-time
Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
MAIN PURPOSE OF THE ROLE
· Accountable for defining, creating and governing the Corporate, Investment & Transaction Banking Technology (CITB) Risk and Control strategy in accordance with the wider EMEA Technology IT Risk and Control vision, strategy and risk appetite
· BISO for JCIB, GCIB, Operations and TB. Translate cybersecurity and other technology risks into business terms for CITB business partners. Act as the primary risk and security liaison for a JCIB, GCIB, TB and Operations.
· Accountable for defining the CITB risk appetite and framework in accordance with the overall Technology departments risk appetite and tolerance framework, managing the departments operational, regulatory and financial risk
· Primary contact for all risk, control and audit issues across all CITB teams – EOL, vulnerabilities, PAM and IAM. Define and own remediation governance, tracking and reporting.
· Provide assurance over the department’s controls design and effectiveness, ensuring controls are proportionate and embedded in day‑to‑day department activity
· Define and evolve the CITB Key Risk Indicators’ and Controls and govern accordingly. Including business side technology controls.
· Run the CITB Risk/Control/ Audit monthly forum committee presenting high quality risk reports and insights to Head of CITB and the Extended Leadership Team
· Responsible for providing visibility of the Extended Leaderships Teams EOL roadmap, the departments position and Product Owners remediation plan and progress
· Work in partnership with the CITB Product and Platform owners, challenging and advising on risk management for new products, processes and change programmes. Provide risk-based decision making, supporting the department to make informed, risk-based decisions by providing an aggregated view of risk exposures
· Work with relevant CITB to promote and mature the CMDB
· Handle potential sensitive information relating to Cyber Security events and assessments on behalf of CITB
· Work across all areas of the CITB department to ensure the CITB Control & Governance team provides necessary support services, oversight function and governance capabilities to all other extended leadership teams and stakeholders.
· Responsible for building strong relationships across the Bank and Securities functions, underpinned by trust and the core values of the bank. Developing strong relationships with key stakeholders such as IT Risk & Control, Cyber Security, other technology pillars, Operational Risk, Internal Audit, Compliance and external parties where applicable
· A senior role, that plays a pivotal part in strengthening a proactive, inclusive risk culture leading with example of the right leadership, culture and behaviours that are required in the bank.
KEY RESPONSIBILITIES
- Oversee CITB relationship with IT Risk and 3rd parties for all external audits and assessments.
- Oversee CITB relationship with IT Risk for all internal audits related to CITB.
· Attend JCIB, GCIB, Operations and TB RAFs alongside relevant L3. Take an active role in the RAFs, being the single point of contact for business side risks impacting technology or vice versa. Translate cybersecurity and other technology risks into business terms for CITB business partners. Act as the primary risk liaison for a JCIBN, GCIB, TB and Operations.
- Ensure strong governance, structures and processes are in place to support effective operational risk and control management across the department
- Support the definition and development of control related and metrics and monitor, report and escalate pillar related risk and control metric performance where required.
· Accountable for managing Open Issues on behalf of the CITB department, tracking and ensuring proactive and timely remediation
- Support CITB extended leadership teams with creation/attestation of key controls against the Operational Risk Framework.
- Manage engagement with stakeholders to design, plan and deliver remediation actions for control deficiencies. Oversee risk identification and mitigation efforts, ensuring understanding of strategic goals
- Ensure departments adherence to internal policies and external regulatory requirement
- Manage risk related loss events, conducting root cause analysis, working with Product and Platform owners to develop response plans
- Perform applicable operational control checks across CITB and engage with other areas of Technology when required
· Work in partnership with the departments Incident management and Threat and Vulnerability team to detect and address vulnerabilities
· Ensure that the team operates in a controlled manner in accordance with standards and procedures whilst adhering to all related security and compliance procedures
· In conjunction with IT Risk, Security and Control, ensure that all regulatory requirements are fully complied with, including SOX assessments and appropriate defences and controls are in place to deal with all cyber risks
- Provide support to CITB for pen test findings
- Produce and manage CITB owned Key Risk Indicators.
- Support disaster recovery exercises, ensuring new services are documented and deployed with BCP/DR in mind
- Provide advisory assistance to IT Risk and Control relating to My Access Live (MaL) and Access Management processes, acting as input into review processes with particular emphasis on CITB related platforms
- Escalate potential service issues to the Management
- Produce regular risk management data for Management. Chair the Departments Risk Oversight Committee
· Drive and adhere to strategic direction of accountable pillars, while supporting the rest of the department.
Culture and Leadership
- Support development of team with a strong focus on building future capabilities
- Lead and champion MUFG’s inclusive, diverse, and values-led culture while fostering a growth mindset to embrace new technologies, industry advancements, and innovative use cases
- Ensure appropriate risk awareness training is in place across the department to fulfil current and future requirements
- Lead and promote a dynamic, delivery driven culture that works alongside business units to provide responsive resolutions and value driven solutions
- Build and nurture strong relationships with internal and external stakeholders, including business teams, to promote collaboration, understand industry’s best practices, and influence positive change across the organization
- Support location strategies prescribed from MUFG and enable transitions (where appropriate) seamlessly
WORK EXPERIENCE
- Extensive Corporate, Investment and Transaction banking business exposure & experience
- Extensive proficiency in scenario analysis and developing mitigation strategies
- Experience representing risk and control on behalf of a large Technology department to an Executive level audience
- A strong track record of engaging credibly with Executives providing confident challenge and clear, decision‑ready insight.
- Experience of working alongside application and asset management functions
- Experienced in dealing with vendors and third-party suppliers
- Strong track record of managing teams and building effective partnerships with peers
- Experience with regulatory compliance issues as they apply to CITB
SKILLS AND EXPERIENCE
Skills and Experience
Essential:
- Extensive Corporate, Investment and Transaction banking business exposure & experience
- Experience working with Risk Management tools e.g Open Pages
- Proven track record of managing risk related issues for large departments, through the lifecycle of creation, reporting and remediation.
- Good knowledge of regulations such as SOX and external assessments such as CBEST
- Extensive experience working within a Corporate, Investment and Transaction Banking technology environment and high-level understanding of the environment, platforms and technology.
- Solid Understanding of threat & vulnerability management processes and technologies
- Extensive exposure of Incident Management and Problem management and route cause analysis
- Proven ability to communicate effectively with Senior Management providing governance oversight
- Ability to balance strategic goals with practical risk management solutions. Interpret and analyse risk data and provide relevant insights
- Experience of sitting within a Management Team directly reporting to L2 Management or above
Desirable:
- Understanding of the COBIT, NIST 2 framework
- Experience with industry-specific regulatory requirements and their impact on operational risk. In-depth understanding of compliance obligations related to AML, data privacy, cybersecurity, and FCA regulations.
- Knowledge of authentication services technology
Education/ Qualification
Essential
- Educated to a degree level or equivalent.
Desirable
- FRM
- PRM
- CFA
- Prince 2 Foundation
- ITIL
- CRISC
- CISA / CISM
PERSONAL REQUIREMENTS
- Excellent communication skills with strong leadership and people management skills to manage a team of technical specialists, inspiring trust and motivation
- Ability to manage constructive conflict effectively
- Ability to build strong and lasting relationships across the bank
- Results driven, with a strong sense of accountability, focused on business outcomes
- Strong decision-making skills, the ability to demonstrate sound judgement
- A structured and logical approach to work
- A creative and innovative approach to work
- Excellent interpersonal skills
- The ability to manage large workloads and tight deadlines
- Excellent attention to detail and accuracy
- A calm approach, with the ability to perform well in a pressurised environment
- A confident approach, with the ability to provide clear direction to your team
· Ability to lead a high performing team
· A strategic approach, with the ability to lead and motivate your team
- Conscientious, methodical and logical approach to work
We are open to considering flexible working requests in line with organisational requirements.
MUFG is committed to embracing diversity and building an inclusive culture where all employees are valued, respected and their opinions count. We support the principles of equality, diversity and inclusion in recruitment and employment, and oppose all forms of discrimination on the grounds of age, sex, gender, sexual orientation, disability, pregnancy and maternity, race, gender reassignment, religion or belief and marriage or civil partnership.
We make our recruitment decisions in a non-discriminatory manner in accordance with our commitment to identifying the right skills for the right role and our obligations under the law.