- Company Name
- MUFG
- Job Title
- Vice President, Threat and Vulnerability Management Team Lead
- Job Description
-
**Job Title**
Vice President, Threat and Vulnerability Management Team Lead
**Role Summary**
Lead and shape the Threat & Vulnerability Management (TVM) function for a global financial services organization, directing a team of engineers to assess, remediate, and automate security vulnerabilities across IT infrastructure and applications. Drive strategic planning, operational execution, and continuous improvement while ensuring compliance with internal controls, regulatory standards, and stakeholder expectations.
**Expectations**
- Demonstrate senior‑level leadership and influence across multiple business units.
- Translate business risk appetite into measurable TVM strategy and road‑map.
- Deliver measurable cost‑optimisation and risk‑reduction outcomes.
- Maintain visibility and accountability through KPI reporting and senior‑management briefings.
- Foster a high‑performance, collaboration‑centric team culture.
**Key Responsibilities**
- Design, develop, and manage the TVM strategy, road‑maps, and governance framework.
- Lead a team of ~5 engineers in daily TVM operations, patch management, and vulnerability triage.
- Automate patch deployment and post‑deployment validation across infrastructure.
- Use ServiceNow AVR/VR modules (and dashboards) to manage vulnerability lifecycle and reporting.
- Prioritise and drive remediation of weaknesses via risk‑based methodology, integrating results from SAST, SCA, and penetration testing.
- Partner with application, Cyber Security, and IT‑Risk teams to ensure secure coding, policy enforcement, and compliance.
- Produce and present KPI, MI, and risk‑management data to senior executives.
- Identify cost‑saving and optimisation opportunities within the EMEA and wider group.
**Required Skills**
- Strategic leadership and program management in a large, global financial services context.
- Deep technical knowledge of vulnerability assessment, patch management, and secure dev‑ops.
- Proficiency with ServiceNow (AVR/VR), vulnerability scanners, SAST/SCA tools.
- Strong analytical and risk‑rating capabilities; ability to translate findings into actionable road‑maps.
- Excellent stakeholder engagement, communication, and influence skills.
- Experience leading and developing high‑performance security engineering teams.
**Required Education & Certifications**
- Bachelor’s or Master’s degree in Computer Science, Information Systems, Cybersecurity, or related field.
- Minimum 8–10 years of progressively responsible experience in threat/vulnerability management.
- Relevant certifications: CISSP, CISM, GIAC (e.g., GWAPT, GCIA), PMP (preferred).
---