- Company Name
- MUFG
- Job Title
- Vice President, Incident Respond Lead
- Job Description
-
**Job Title**
Vice President, Incident Response Lead
**Role Summary**
Lead and oversee the organization’s incident response capability, ensuring robust prevention, detection, analysis, containment, and recovery processes for all cyber, IT, and information risk incidents. Align incident response strategy with global security governance, regulatory requirements, and business objectives while collaborating with internal and external stakeholders, including auditors, management committees, and external regulators.
**Expectations**
- Deliver an integrated, auditable incident response framework that protects the organization’s assets and reputation.
- Maintain a proactive threat intelligence posture and continually refine incident response playbooks.
- Demonstrate decisive leadership during incidents, coordinating cross‑functional teams and ensuring minimal business impact.
- Serve as the primary liaison for incident reporting, escalation, and post‑incident reviews with senior leadership and external auditors.
**Key Responsibilities**
- Develop, implement, and continually improve the organization’s Incident Response Plan, policies, and procedures in accordance with ISO 27001, NIST 800‑61, and relevant regulatory mandates.
- Lead, mentor, and manage the Incident Response Team, ensuring high levels of readiness, skill development, and clear command‑and‑control during incidents.
- Coordinate incident investigations, manage documentation, evidence collection, root‑cause analysis, and remediation actions.
- Oversee the integration of threat intelligence feeds, security monitoring tools, and automation to support early detection and rapid response.
- Ensure consistent application of security controls across business units and technology infrastructure.
- Prepare and present incident reports, metrics, and lessons‑learned to executive management, technology governance committees, and external auditors.
- Manage incident‑related communication with stakeholders, including public relations, legal, compliance, and regulatory bodies when applicable.
- Continuously benchmark and adopt best practices, emerging technologies, and industry standards to elevate the organization’s security posture.
**Required Skills**
- Executive‑level leadership with a proven track record in cyber incident response and information security management.
- Deep understanding of threat landscape, cyber attack techniques, and risk assessment methodologies.
- Experience with security frameworks (ISO 27001, NIST, SOC 2, PCI‑DSS) and regulatory compliance (GDPR, FFIEC, SOC 2).
- Strong analytical and investigative skills; ability to synthesize technical evidence into actionable conclusions.
- Excellent communication, stakeholder‑management, and cross‑functional collaboration.
- Ability to manage complex, high‑pressure incidents while maintaining clear decision‑making and documentation.
- Familiarity with security operations tools (SIEM, SOAR, EDR) and incident‑management platforms.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (Master’s preferred).
- Industry certifications: CISSP, CISM, CRISC, CEH, GIAC, or equivalent.
- Additional certifications (e.g., CISA, ISO 27001 Lead Implementer) are highly desirable.
---