Are you applying to the internship?
Job Description
SOC Program Manager | Mitsubishi UFJ Financial Group
The Tone:
This is a full-time role at Mitsubishi UFJ Financial Group (MUFG), coordinating cybersecurity services across global regions. MUFG is one of the world’s leading financial groups, striving to make a difference for every client, organization, and community. This role is critical for driving consistent, high-quality cybersecurity service delivery across the Global Security Operations Center (GSOC) Center of Excellence. The specialist will ensure operations align with enterprise risk objectives, governance standards, and evolving global requirements.
The TL;DR
• Role: Full Time
• Type: Full-time
• Location: Global
• Team: Information Security Services Team – Global Security Operations Center (GSOC) Center of Excellence
• Mission: Drive the delivery and execution of cybersecurity services across the Global Security Operations Center Center of Excellence, ensuring consistent, high-quality operations aligned with enterprise risk objectives and global requirements.
• Tech Stack: SIEM operations, Cyber Kill Chain, MITRE ATT&CK
What You’ll Actually Do
• Drive global GSOC service execution: Ensure consistent end-to-end delivery of GSOC services such as log ingestion, use case lifecycle management, threat detection, and incident response across all global regions.
• Coordinate new log source integration: Work with regional teams and technology partners to onboard and integrate new log sources, ensuring timely ingestion and coverage alignment with risk priorities.
• Lead use case development and governance: Oversee the development, tuning, and governance of GSOC use cases to improve detection accuracy, reduce false positives, and address emerging threat vectors.
• Oversee cross-functional program delivery: Manage cybersecurity programs from initiation through delivery, ensuring milestones are met and outcomes are effectively communicated to stakeholders across regions.
• Report operational performance: Develop and manage key performance indicators (KPIs) and service-level metrics reflecting operational health and risk appetite for transparent reporting to senior leadership.
The Must-Haves
• Background: Bachelor’s degree in Information Technology, Cybersecurity, Engineering, Business Administration, or a related field; equivalent experience also considered.
• Experience: 10-12 years in cybersecurity operations, security service delivery, program management, or risk management, ideally within financial services. Hands-on familiarity with GSOC functions such as log ingestion, SIEM operations, use case development, threat detection, and incident response workflows, with proven experience in strategic planning, program execution, and executive-level reporting.
• Skills: Demonstrated creative problem-solving abilities; experience creating trending, metrics, and management reports; skilled in developing briefing materials, managing logistics, and facilitating cross-functional collaboration across global teams; demonstrated ability to drive operational efficiency through technology and process innovation; excellent written and verbal communication skills.
• Bonus: Experience working in Japanese corporate environments or proficiency in Japanese; experience managing global, cross-cultural teams; broad exposure across cybersecurity domains (governance, risk, network security, threat/vulnerability management, incident response); familiarity with automation, AI, or light scripting for reporting and operational efficiency; relevant certifications (e.g., CISSP, CISM, Security+, ISSMP, SANS, GSEC, GCFA, GNFA, GIAC, GCIH); knowledge in security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, and Incident Response and Forensics; experience with cloud computing security, network, operating system, database, application, and mobile device security; experience with information security risk management, including conducting information security audits, reviews, and risk assessments.