Job Overview:
MUFG is seeking a highly motivated Security Data Architect & Governance person to be part of the Program Governance team to drive the Security Observability technical program with cutting-edge technology to improve security posture. This role drives the requirements, standards and governance across global implementation.
Education:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or relevant industry certifications. Equivalent work experience is equally preferable.
Key Functions:
- Data architecture, engineering and analytics using various databases, scripting and AI/ML
- Different types of data collection, Log data, Scanning data, Vulnerability data, Configuration data, and external intelligence data
- Data lake and/or data warehouse to manage the data in centralized or federated models
- Security Data Analytics using AI & ML including behavior & Pattern based analysis and maps with MITRE and CRI frameworks.
- Data monitoring to detect security issues, anomalies, etc.
- Threat hunting
- Generate different metrics, usage, KPI, KRI, etc.
Responsibilities:
- An expert in data engineering and management using various products such as S3, Snowflake, Databricks, SQL databases, no-SQL databases, Vector/Graph database, etc.
- A Security Data expert of various data types collected through different technologies such as SIEM, SOAR, DLP, EDR, ITDR, Cloud Monitoring, etc.
- Publish & manage Security Standards and Guidelines around Data Security with the alignment of NIST CSF, CRI, and ISO frameworks
- Publish and manage the capabilities and features for security data collection, security, management, monitoring, detection and alert as per Security Standards.
- Manage the close relationship with Architecture and Engineering teams to publish the 1-3 years of the roadmap
- Manage application onboarding and integration efforts by working with various teams
- Publish many documentations using Confluence, Spreadsheets, word, Visio, etc.
- Create presentations for different stakeholders including senior leadership
- Identify opportunities to enhance the current baseline processes and configuration
- Generate different types of reports, usage, performance, KPI, KRI, etc.
- Knowledge of various applications and systems that include security products, middleware, Clouds (SaaS, PaaS and IaaS), Containers, etc. to come up with the right approach of the integration
- Ability to understand security risks and controls, to analyze various methods of controlling information security problems, determine the strengths and weaknesses of each method and implement the best cost-justified solution
Qualifications:
- At least 8+ years of experience in Security Data Architecture, Engineering and Analytics with Security observability technology
- In depth knowledge of all Security Observability domains & technologies
- SIEM, Vulnerability management, Behavior Analytics, AI & ML based Analytics, Threat hunting, EDR, ITDR, DLP, Baseline configuration management, Cloud monitoring, etc.
- Working experience of databases
- Snowflake, Databricks, AWS S3, Oracle SQL Database, Graph and Vector databases, etc.
- Strong working experience in various scripting:
- KQL, SQL, JavaScript, Python, Claude, Co-Pilot
- Knowledge of same or similar products
- Splunk, Torq, Exabeam, Cribl, Anvilogic, 7AI, CrowdStrike, Tanium, Qualys, Zscaler, DLP & CASB, AWS Cloud trail, Cloud watch, Azure Security Event hub, etc.
- A security expert with a good understanding of NIST, MITRE, CRI, ISO and other Security frameworks
- Must be able map security requirements to technology solution.
- Experience in creating trending, metrics, and management reports. PowerBI or other reporting tool experience is a plus.
- Experience working in complex and large-scale environments.
- Knowledge and experience operating in a hybrid-cloud environment.
- Knowledge and experience in AWS & Azure
Preferred Certifications:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Systems Manager (CISM)
- Certified Information System Auditor (CISA)
- Certified Ethical Hacker (CEH)