About the role
Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
Job Summary
As an Incident Response Team Lead, you will play a critical role in leading and developing the Incident Response function across the region. You will guide team members in investigating, containing, and responding to cybersecurity incidents, while also driving proactive improvements to incident response processes, readiness, playbooks, and operating procedures. The role requires strong hands-on technical capability, sound judgment during high-pressure incidents, and the ability to coordinate stakeholders, mentor incident response team members, and continuously strengthen the organization’s cyber resilience.
Job Responsibilities
- Lead and coordinate the Incident Response team during cybersecurity incidents, ensuring timely triage, investigation, containment, eradication, recovery, and post-incident follow-up.
- Provide technical direction, coaching, and quality review for team members performing incident investigations, forensic analysis, breach assessments, and remediation activities.
- Drive continuous improvement of the cybersecurity incident response process, including playbooks, escalation procedures, reporting templates, evidence-handling practices, and lessons-learned activities.
- Enhance incident response readiness through tabletop exercises, attack simulation exercises, process walkthroughs, and coordination with internal and external stakeholders.
- Conduct and oversee analysis of artifacts, alerts, logs, network traffic, endpoints, and compromised systems to determine intrusion methods, scope of impact, root cause, and required remediation actions.
- Coordinate cross-functional incident response activities with Security Operations, IT, business stakeholders, legal, risk management, compliance, and external partners as required.
- Produce and review clear incident reports, executive updates, technical findings, and post-incident recommendations that support decision-making and long-term security improvements.
- Research evolving threats, techniques, tools, and vulnerabilities, and translate relevant insights into improved detections, response procedures, and mitigation strategies.
- Support compliance inquiries, audits, and risk management requests by maintaining complete documentation and ensuring incident response processes align with internal policies and industry good practices.
- Contribute to the development of security operations detections, automation, monitoring improvements, and forensic capabilities to reduce response time and strengthen overall threat mitigation.
Job Requirements
- Minimum 10 years of experience working in the Cybersecurity Operations or Information Security
- Proven experience leading or supervising cybersecurity operations, incident response, security investigations, or a related technical team.
- Demonstrated ability to coordinate incident response activities across technical teams, management stakeholders, and external parties during high-pressure situations.
- Bachelor’s degree in Information Technology, Cyber Security, Computer Science, or related discipline
- Relevant technical and industry certifications, such as GCFA, GCFE, GCIH, GCIA, CISSP, ISSMP, CISM, CEH, or GSEC are preferred
- Experience in Security Operation Center, Incident Response and Computer Forensics preferred
- Ability to lead by influence, build team capability, set investigation standards, and promote a culture of continuous improvement, accountability, and operational readiness.
- Strong knowledge and experience in Incident Response including security event triage, investigation, containment, recovery and the overall incident response process.
- Proficient in operating systems (Linux, Windows), network security, application security and mobile device security.
- Experience with security data collection, analysis, correlation, and risk analysis using logs and various data sources.
- Well-developed analytical, qualitative, and quantitative reasoning skills, with demonstrated creative problem-solving abilities.
- Understanding of offensive security, common attack methods, and the ability to pivot across multiple datasets to correlate artifacts for a single security event.
- Diverse skill base in product and information security, including system development, maintenance procedures, and security controls.
- Detailed knowledge of security and regulatory frameworks (ISO 27001, NIST 800 series, etc.) and enterprise detection and response technologies (advanced threat detection tools, intrusion detection/prevention systems, etc.).
- Experience with tools like CrowdStrike, Microsoft Defender, Tanium, Proofpoint, and open-source incident response and forensic tools.
- Ability to document and explain technical details concisely and understandably.
- Strong leadership, prioritization, and stakeholder management skills, with the ability to guide team members, manage multiple concurrent incidents, and maintain clear communication under pressure.
- Fundamental understanding of enterprise cybersecurity frameworks such as MITRE ATT&CK and Cyber Kill Chain.
Mitsubishi UFJ Financial Group (MUFG) is an equal opportunity employer. We view our employees as our key assets as they are fundamental to our long-term growth and success. MUFG is committed to hiring based on merit and organsational fit, regardless of race, religion or gender.
Aplyr's read
Mitsubishi UFJ Financial Group is a cornerstone of Japan's financial sector, attracting professionals in banking, asset management, and global markets operations.
What's promising
- •MUFG offers diverse career paths across multiple financial services sectors.
- •The company is a leader in Japan's financial market, providing stability.
- •Recent roles show a focus on technology and compliance, indicating growth areas.
What to watch
- •Limited public information about work-life balance within the company.
- •The financial sector faces regulatory challenges that may impact operations.
- •Global economic shifts could affect MUFG's international business strategies.
Why Mitsubishi UFG
- •MUFG is one of the largest financial groups in Japan, influencing the market.
- •The company has a strong emphasis on integrating technology in financial services.
- •MUFG's global presence offers international career opportunities for employees.
Aplyr’s read is generated by AI from public sources. Was it useful?
About Mitsubishi UFG
三菱UFJフィナンシャル・グループ (MUFG) is a leading financial group in Japan, providing a wide range of financial services including banking, trust banking, securities, credit cards, and asset management.
Similar roles
Assistant Vice President, Crisis & Incident Responder
Mitsubishi UFG
Cloud Incident Responder (Vice President)
Citigroup
Incident Manager (Global Incident Management) - Assistant Vice President
Deutsche Bank
Incident Response Lead Specialist, Vice President
Mitsubishi UFG
Incident Response Senior Specialist, Associated Vice President
Mitsubishi UFG
Senior Incident Optimization & Reliability Specialist - End-User Technology – Vice President
Citigroup