What are the responsibilities and job description for the Penetration Tester, Associate Vice President position at MUFG?
Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.
Job Summary
We are seeking a Sr. Penetration Tester with experience in application and infrastructure penetration testing to join our growing team. Generally, we are looking for candidates with 5 years of Cyber Security experience with a focus in gray box penetration testing to join our Enterprise Information Security organization on the Penetration Testing team. The successful candidate will play a key role in applications and infrastructure assessment based on OWASP Top 10, SANS 25, OSSTMM, Mitre ATT&CK.
Major Responsibilities
MUFG Benefits Summary
We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance, (ii) the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, (iii) the Los Angeles County Fair Chance Ordinance, and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment, if any.
The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.
We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal, state, or local law.
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.
Job Summary
We are seeking a Sr. Penetration Tester with experience in application and infrastructure penetration testing to join our growing team. Generally, we are looking for candidates with 5 years of Cyber Security experience with a focus in gray box penetration testing to join our Enterprise Information Security organization on the Penetration Testing team. The successful candidate will play a key role in applications and infrastructure assessment based on OWASP Top 10, SANS 25, OSSTMM, Mitre ATT&CK.
Major Responsibilities
- Act as a subject matter expert in offensive information security performing penetration testing and vulnerability research of complex proprietary software and hardware
- Drive remediation by outlining a defense-in-depth approach to business stakeholders and providing strategic solutions to developers on effective security controls and counter measures
- Have strong technical writing and presentation skills to report and articulate the vulnerability assessment results to any audience
- Contribute to the review of internal processes and activities and assist in identifying potential opportunities for improvement and automation
- Collaborate with leaders and stakeholders on client kick-off and discovery sessions to answer questions from prospects and clients
- Create custom tool(s) and/or modify existing tool(s) to aid with vulnerability detection automation process
- Communicate and work closely with application managers and lead developers across business lines on security finding(s) to ensure their understanding of associated risks and actions needed to remediate those risks
- Continually research on new exploitation/attack techniques against technology stack(s) currently being used at the organization
- Maintain familiarity with industry trends and security best practices
- Provide technical training to junior and mid-tier team members
- Bachelor's Degree in Computer Science or related fields; applicable specialized training; or equivalent work experience - equally preferable
- 5 years of experience with testing frameworks and tools such as Burp Suite, Metasploit, Cobalt Strike, Kali Linux, Nessus, PowerShell Empire, AutoSploit, Ghidra, IDAPro, OllyDbg, Fiddler
- 3 years of experience in scripting languages such as Python, PowerShell, Bash, and Ruby
- 5 years of experience in application and infrastructure penetration testing, including experience using automated tools and manual testing techniques
- Possessing one or more of these certifications are highly desirable: OSEP, OSWE, CWEE, CAPE.
- In-depth understanding with two or more of the following technology areas:
- Network infrastructure (Routers, switches...)
- Security products and services (FW, IDS, IPS, AV...)
- Active Directory, servers, services, desktops and mobile devices
- Operating System (Windows, Unix/Linux/AIX)
- Databases (MySQL, SQL, DB2...)
- Cloud and container technologies like AWS, Azure, Oracle and Kubernetes
- In-depth knowledge in one or more of these programming languages: Java, C#, C, C , Assembly
- In-depth understanding of penetration-testing methodologies and security concepts such as OWASP Top 10, SANS 25, OSSTMM, Mitre ATT&CK
- In-depth knowledge in one or more of these programming languages: Java, C#, C, C , Assembly
- In-depth knowledge in one or more of these areas: Post exploitation, exploitation development, or binary reverse engineering
- Excellent communication and report-writing skills
MUFG Benefits Summary
We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance, (ii) the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, (iii) the Los Angeles County Fair Chance Ordinance, and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment, if any.
The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.
We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal, state, or local law.
Salary : $110,000 - $135,000