Cyber Defense, Adversary Emulation

3 weeks ago


New York, United States Mizuho Bank Ltd Full time
Join the Mizuho team in Cyber Defense, Adversary Emulation

Major Duties & Responsibilities:

In this role you will report to the Head of Adversary Emulation, in the organization of the CISO. This role will play a pivotal role in safeguarding the company's digital assets and ensuring business continuity. You will be a leading member of the Cyber Defense team for Mizuho Americas Services, LLC (MAS). You will be responsible for day-to-day oversight and management of the Threat and Vulnerability Management program. You will work closely with other members of the MAS Information Security Office to actively identify and mitigate threats and vulnerabilities through various activities. You must combine hands-on experience with an understanding of theory and practice. You will also be involved with monitoring and oversight of security consultants and other supporting third parties. Your responsibilities include operational aspects of monitoring and remediating security events including working with vendors and other IT departments to address the event and escalating to senior members of the team as necessary.

  • Operational Responsibilities
    • Oversee the Threat and Vulnerability Management program
    • Prioritize work amongst full time staff and third-party resources
    • Oversee tools, technologies, and processes related to threat management
    • Ensure effective reporting of security activities, reporting status, risks, issues, and escalations to senior leadership (CISO, CIO, and other senior stakeholders).
    • Manage relationship with other Security, Infrastructure, and Application teams to identify, mitigate, and remediate vulnerabilities and other threats in the environment
    • Provide expertise on Security Incidents
    • Map TTPs and CVEs to identified threats and prioritize appropriately
    • Recommend and implement enhancements to existing processes, focusing on automation and integration between other security tools.
    • Ensure comprehensive threat identification of the entire Mizuho enterprise
    • Review daily, weekly, and monthly security reports for any anomalies or issues
    • Maintain documentation on security architecture, procedures, configurations
  • Project based work
    • Provide feedback to MAS teams to implement well engineered solutions to improve security posture
    • Identify workflow areas to proactively address potential vulnerabilities
    • Work with colleagues and vendors to assess different technologies and determine their impact within the Mizuho environment
    • Provide security requirements for the design, development, engineering, and implementation of hardware, networks, and applications
    • Conduct lessons learned exercises and RCAs after security incidents, detection of major system vulnerabilities, and ongoing compliance violations
    • Analyze threat intelligence, vulnerability and security assessments; produce vulnerability reports and work with IT teams to correct or mitigate found deficiencies


Qualifications & Requirements:
  • At least 10+ years security domain related experience, preferably within a financial services firm
  • 5+ years of experience in a similar position.
  • Proven experience in a vulnerability management program within a large enterprise.
  • Strong understanding of cybersecurity risk management and information security standards (SOX, NIST, FISMA, etc.)
  • Ability to manage and use various scanning technologies across different layers of the tech stack, such as SAST, DAST, cloud infrastructure
  • Strong understanding of OWASP and other common Application Security issues and frameworks.
  • Fundamental understanding of vulnerability reporting and management processes or tools
  • Solid grasp and understanding of vulnerability scoring and classification methodologies
  • Excellent communication and leadership skills, with the ability to manage and prioritize multiple projects and initiatives.
  • Strong knowledge of internet, web, application and network security platforms.
  • Strong knowledge of Linux & Windows operating system and security functions
  • Strong knowledge of Cloud Deployment and management
  • Develop, document, and maintain policies, procedures, and training plans for system administration and appropriate use
  • Strong written and verbal communication skills. Ability to clearly articulate ideas, solutions etc.
  • Educational background with BS / MS in Information Technology, Computer Science, Engineering or related area.
Additional Qualifications:
  • Possess security certifications (CISSP, CISM, CISA, GSEC, etc.)
  • Experience with project management and industry best practices
  • Experience working within the Financial Services industry
  • Experience in support projects and able to handle issues against defined SLA / KPI
  • Clear communication & presentation skills, and the ability to articulate complex issues concisely
  • Leadership, relationship-building and influencing skills to drive agendas across a number of teams
  • Proven track record of effectively interacting with senior management
  • Ability to work strategically and collaboratively across departments
  • Excellent organizational skills with the ability to multi-task, prioritize competing demands, be versatile and action-oriented


The expected base salary ranges from $105k-$170k. Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications and licenses obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus.

#LI-Hybrid

Other requirements

Mizuho has in place a hybrid working program, with varying opportunities for remote work depending on the nature of the role, needs of your department, as well as local laws and regulatory obligations. Roles in some of our departments have greater in-office requirements that will be communicated to you as part of the recruitment process

Company Overview

Mizuho Financial Group, Inc. is the 15th largest bank in the world as measured by total assets of ~$2 trillion. Mizuho's 60,000 employees worldwide offer comprehensive financial services to clients in 35 countries and 800 offices throughout the Americas, EMEA and Asia. Mizuho Americas is a leading provider of corporate and investment banking services to clients in the US, Canada, and Latin America. Through its acquisition of Greenhill, Mizuho provides M&A, restructuring and private capital advisory capabilities across Americas, Europe and Asia. Mizuho Americas employs approximately 3,500 professionals, and its capabilities span corporate and investment banking, capital markets, equity and fixed income sales & trading, derivatives, FX, custody and research. Visit www.mizuhoamericas.com.

Mizuho Americas offers a competitive total rewards package.

We are an EEO/AA Employer - M/F/Disability/Veteran.

We participate in the E-Verify program.

We maintain a drug-free workplace and reserve the right to require pre- and post-hire drug testing as permitted by applicable law.

#LI-MIZUHO

  • New York, United States Mizuho Americas Full time

    Join the Mizuho team in Cyber Defense, Adversary Emulation! Major Duties & Responsibilities: In this role you will report to the Head of Adversary Emulation, in the organization of the CISO. This role will play a pivotal role in safeguarding the company's digital assets and ensuring business continuity. You will be a leading member of the Cyber Defense team...


  • New York City, New York, New York City, NY, United States United States Army Full time

    Job Overview: As a Cyber Operations Specialist, you’ll use your cyber security skills to defend the Army’s crucial and complex weapons systems, which include satellites, navigation, and aviation systems against both foreign and domestic cyber threats. You’ll respond to adversary attacks, while enabling commanders to gain an advantage in cyberspace by...


  • New York, NY, United States MassMutual Full time

    The OpportunityWithin our Enterprise Cybersecurity organization, you will work closely with the Security Intelligence team and be responsible for leverage real world adversarial techniques to perform pen tests and simulate attacks on existing and upcoming services spanning across applications, servers, and end-user assets. The TeamWithin the Security...


  • New York, United States Mizuho Bank Ltd Full time

    Join the Mizuho team in Cyber Defense, Monitoring & Incident Management! Major Duties & Responsibilities: In this role you will report to the Head of Cyber Defense, in the organization of the CISO. You will play a pivotal role in safeguarding the company's digital assets and ensuring business continuity. You will be a leading member of the Cyber Defense...


  • New York, New York, United States Fidelity Information Services Full time

    Cyber Security Analyst Job DescriptionAs a seasoned Cyber Security Analyst at Fidelity Information Services, you will be part of a top-notch team responsible for protecting our company's digital assets from cyber threats. Your expertise in cyber security incident response will be invaluable in helping us maintain the highest level of security and minimize...


  • New York, United States Eleven Recruiting Full time

    Job Overview: We are seeking a proactive and skilled Lead Cyber Security Engineer to join our expanding team. This role is ideal for someone with strong leadership attributes who can help build and enhance our Security Operations Center (SOC). You will play a critical role in developing processes, metrics, and integration strategies, focusing on blue team...


  • New York, United States Eleven Recruiting Full time

    Job Overview: We are seeking a proactive and skilled Lead Cyber Security Engineer to join our expanding team. This role is ideal for someone with strong leadership attributes who can help build and enhance our Security Operations Center (SOC). You will play a critical role in developing processes, metrics, and integration strategies, focusing on blue team...


  • New York, United States Schonfeld Full time

    Senior Cybersecurity Analyst The Role The Schonfeld Cybersecurity Operations Team is looking for individuals who are excited by the idea of finding threats in ways no other defense mechanism can, eradicating threats, and building new intelligence to prevent future attacks from succeeding. This Senior Cybersecurity Analyst will be responsible for improving...


  • new york city, United States Eleven Recruiting Full time

    Job Overview: We are seeking a proactive and skilled Lead Cyber Security Engineer to join our expanding team. This role is ideal for someone with strong leadership attributes who can help build and enhance our Security Operations Center (SOC). You will play a critical role in developing processes, metrics, and integration strategies, focusing on blue team...


  • new york city, United States Eleven Recruiting Full time

    Job Overview: We are seeking a proactive and skilled Lead Cyber Security Engineer to join our expanding team. This role is ideal for someone with strong leadership attributes who can help build and enhance our Security Operations Center (SOC). You will play a critical role in developing processes, metrics, and integration strategies, focusing on blue team...


  • New York, New York, United States Darktrace Full time

    Darktrace is a global leader in cyber security AI, delivering complete AI-powered solutions to protect its customers from complex threats.Our cutting-edge technology is backed by over 130 patents and pending applications, and our team of expert trainers provides comprehensive onboarding and education to ensure success.We are seeking a highly motivated and...


  • New York, United States Della Infotech Full time

    Job Title: Cyber Security Specialist Duration: 13 months(35 hrs per week) Location: Brooklyn, NY(Day 1 onsite) SCOPE OF SERVICES Ensure security policies such as CJIS are in compliance throughout the design and build phase. Engage in working session with the ESINET, GIS and L&R vendors on detail designs and provide input to their proposed solutions. Provide...


  • New York, United States AXA XL Ltd Full time

    Senior Underwriting Risk Manager – Cyber New York, NY I USA A commercial lines (re)insurer, AXA XL is subject to a range of risks as a result of its underwriting activities. AXA XL’s Risk Management Function defines processes, rules and governance to empower the business to take on risks in a secured environment, thus enhancing value creation and...


  • New York, United States Saxon Global Full time

    FULL TIME POSITION: Title-Cyber Security Engineer/NIST Title Client - Peoples Bank - Location-Hybrid/Midtown, New York City - salary--$ 145K Salary Target -Visa:USC,GC,GC-EAD **We need a senior (7+ Years) Cyber Security Engineer with great experience working with Cyber Security and Information Risk management with Strong understanding and hands on...


  • New York, United States Crescens Full time

    Job Title: Cyber Security Threat Modeling Integration Engineer Location: New York (Remote) Duration: 8 Months contractDescription: The resource will directly contribute to the Client, including enhancing prevention, detection, response and recovery efforts through various technical and operational methods; to reduce the mean time to detection and response of...


  • New Bedford, Massachusetts, United States MITRE Full time

    Are you passionate about developing and implementing Operational Technology (OT) lab environments? Do you have a strong background in Cyber and an interest in managing vendor relationships, connecting IT and OT networks, and managing lab projects? MITRE's Cyber Infrastructure Protection Innovation Center is seeking a Cyber Security Engineer to develop our...


  • New York, United States APN Consulting Inc Full time

    APN Consulting has an immediate need for a direct client requirement: Role: Cyber Defense, Monitoring, Incident Management Location: NYC (Hybrid) Duration: FTE/Direct Hire Major Duties & Responsibilities: In this role you will report to the Head of Cyber Defense, in the organization of the CISO. You will play a pivotal role in safeguarding the...


  • New Orleans, Louisiana, United States Entergy Full time

    Job Title: Cyber Security Specialist for Electric UtilityJob Summary:The Entergy company is seeking a skilled Cyber Security Specialist to join its team. As a Cyber Security Specialist, you will be responsible for providing technical compliance subject matter expertise for the Entergy Nuclear Cyber Security Program and supporting all Entergy Nuclear Sites in...


  • New York, United States Booz Allen Hamilton Full time

    Job Number: R0197435Cyber Strategy and Risk Advisory Specialist The Opportunity: As a seasoned Cybersecurity and Risk Management Practitioner and Leader, you will collaborate with respected experts across our Cyber Strategy, Cyber Technology, and Incident Response Solution Groups to lead engagement teams to deliver tailored solutions to our clients....


  • New Bedford, Massachusetts, United States MITRE Full time

    About UsMaking a Difference in Cybersecurity.MITRE is a not-for-profit corporation chartered to work for the public interest. We operate R&D centers for the government, creating lasting impact in fields like cybersecurity, healthcare, aviation, defense, and enterprise transformation. Our mission is to tackle our nation's toughest challenges while promoting...