M
Posted 11 hours ago
Cybersecurity Control Testing & CRI Maturity Assessor - Manager
MUFG Global Service Private Ltd.
Requirements
8-12 years in risk management or IT audit, Experience with on-premises and cloud control validation, Third-party/vendor cybersecurity assessment experience, CRI Profile maturity assessment expertise, Knowledge of banking regulations (FFIEC, OCC, GDPR), SDLC and secure engineering control validation, Bachelor's degree in Information Security or Computer Science, CISSP, CISM, CRISC, or CISA certifications preferred
Skills
CybersecurityComplianceAudit
About the role
Responsibilities
- Plan and execute control testing engagements by defining scope, test approach, and evidence requirements for on-premises and cloud environments.
- Test control design and operating effectiveness across identity, network, endpoint, data protection, and vulnerability management.
- Perform CRI Profile maturity assessments by mapping controls to requirements and documenting gaps or improvement opportunities.
- Conduct third-party and vendor cybersecurity assessments through questionnaires, interviews, and evidence reviews such as SOC reports.
- Validate security controls embedded within the SDLC, including secure design, threat modeling, and CI/CD build/release controls.
- Produce high-quality assessment workpapers, test scripts, and formal reports detailing risk ratings and remediation actions.
- Perform remediation validation by re-testing controls to confirm that corrective actions adequately address identified deficiencies.
Requirements
- 8-12 years of experience in risk management, information security, technology risk, IT audit, or IT operations.
- Proven ability to validate controls across on-premises infrastructure and cloud-native services.
- Experience performing third-party cyber risk assessments and mapping controls to standards like NIST, CIS, or ISO.
- Expertise in CRI Profile maturity evaluations and scoring.
- Strong knowledge of banking and privacy regulations such as FFIEC, OCC, FRB, or GDPR.
- Experience validating SDLC control effectiveness, including SAST/DAST and dependency scanning.
- Bachelor's degree in Information Security, Computer Science, Information Systems, or a related discipline.
Preferred Qualifications
- Professional certifications such as CISSP, CISM, CRISC, CISA, or CGEIT.
- Cloud security certifications such as CCSK or CCAK.
- Specialized credentials in vendor/third-party risk or audit/assurance.
About the Company
Mitsubishi UFJ Financial Group (MUFG) is one of the world’s leading financial groups, with 150,000 colleagues globally. We strive to make a difference for every client, organization, and community we serve by building long-term relationships and fostering sustainable growth. At MUFG, we put people first, value diverse ideas, and invest in the talent and technologies that empower our employees to own their careers.
ScoutJobs Agent
Get matches like this delivered daily
Sign up free — we'll pull jobs that fit your CV from across the web and rank them for you.
Get started — it's freeCybersecurity Control Testing & CRI Maturity Assessor - Manager
MUFG Global Service Private Ltd. · Bengaluru
