Overview In this role you will lead MUFG's Continuous Control Monitoring program to provide real-time assurance across critical technology and security domains. You will design automated control testing and work with cross-functional teams to strengthen regulatory compliance. You'll translate control requirements into automated tests and drive insights via dashboards and GRC integration. This is a high-impact, data-driven position that shapes risk management at scale. You'll join a collaborative culture focused on innovation and responsible growth.
Compensation / Benefits- comprehensive health and wellness benefits
- retirement plans
- educational assistance and training programs
- income replacement for disabled employees
- paid maternity and parental bonding leave
- paid vacation, sick days, and holidays
Responsibilities- Build and scale CCM to continuously test technology and security controls across infrastructure, cloud, and applications
- Onboard systems of record and telemetry sources (IAM, vulnerability, logging, CMDB, cloud posture) into automated pipelines
- Convert control requirements into machine-testable rules with pass/fail logic and evidence capture
- Aggregate test results into dashboards and scorecards; integrate results into GRC platforms for issue management and regulatory reporting
- Maintain a traceability model from objectives to automated tests and evidence artifacts for audits
- Collaborate with Compliance, Internal Audit, and Technology to ensure outputs meet attestation and examination standards
- Drive continuous CCM improvement by monitoring threats, regulatory expectations, and best practices
Key requirements- 8+ years in cybersecurity, technology risk, or IT audit
- At least 3 years in control automation or CCM programs
- Strong understanding of CRI 2.1, NIST CSF, and financial sector regulatory requirements
- Hands-on experience with data pipelines, APIs, and automation tools for control testing
- Familiarity with SIEM, CSPM, vulnerability management, and identity platforms
- Proficiency in dashboarding/reporting tools (Power BI, Tableau) and GRC integration (ServiceNow, Archer, MetricStream)
- SQL and scripting: PowerShell, DAX/MDX, Python
- Knowledge of cloud security controls across AWS, Azure, or GCP
- Excellent communication with ability to influence senior stakeholders and regulators
- Relevant certifications preferred: CISSP, CISM, CISA, or cloud security certifications
- Education: Bachelor's degree in Computer Science or a closely-related discipline
- excellent communication
- influencing senior stakeholders
- collaboration with cross-functional teams
- SQL
- PowerShell
- Python