MUFG Union Bank Jobs

Mobile mufg Logo

Job Information

MUFG Union Bank Americas Regional Data Privacy Incident Response Lead, Vice President in Tempe, Arizona

Americas Regional Data Privacy Incident Response Lead, Vice President - 10043421-WD


Do you want your voice heard and your actions to count?

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), the 5th largest financial group in the world (as ranked by S&P Global, April 2020).In the Americas, we’re 13,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, developing positive relationships built on integrity and respect. It’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. We’re a team that accepts responsibility for the future by asking the tough questions and owning the solutions. Join MUFG and be empowered to make your voice heard and your actions count.

Job Summary:

MUFG is seeking a Vice President, Data Privacy Incident Response Lead to manage the Americas Privacy Incident Response program. Reporting to the Head of Data Privacy for the Americas, within the Americas Compliance organization, the candidate will be responsible for leading the Americas Privacy Incident Response team, with overall responsibility for supervising staff, maintaining the Privacy Incident Response Policy and Program and for timely and appropriate response to Privacy Incidents.

The Americas Privacy Incident Response Program includes processes for reporting and documenting Privacy Incidents, containing incidents, assessing impact, identifying root cause and remediation measures, evaluating notification obligations and training colleagues. The Program covers reported Privacy Incidents impacting MUFG in the U.S, Canada and Latin America.

This role will require leadership skills, strong incident and project management experience, and the ability to effectively collaborate across the enterprise, including with Information Security, Regulatory Affairs, Operations, Risk, Legal, Human Resources, Third Party Management and Fraud teams.

Major Responsibilities:

  • Provide leadership and direction for the privacy incident response team.

  • Lead and support incident investigations conduct in-depth analysis and communicate effectively to gather necessary information to identify impact, root cause and remediation measures.

  • Maintain the Privacy Incident Response Policy, procedures and program documentation.

  • Create senior management reports, including to the Executive Committee and Board of Directors.

  • Develop and present accurate and timely information to stakeholders and regulators outlining incident details, containment measures, impacts, remediation steps and post-mortem reviews (including lessons learned).

  • Assess and work with Legal partners in the review of state and federal or country-specific regulatory breach notification requirements and preparation of notification letters or other required documentation.

  • Partner with stakeholders from the business, Legal, Risk, Information Security, Human Resources during the lifecycle of an incident.

  • Participate in table-top exercises to enhance incident and breach response readiness.

  • Lead post-mortem reviews of incidents and identify enhanced controls to mitigate the risk of reoccurrence.

  • Develop employee training content and awareness messages and continuously educate employees on the Program and reporting and preventing privacy incidents.

  • Provide strategic leadership to drive continuous Program improvements and enhancements.

  • Support the goals and objectives of the Global Privacy Program including managing change initiatives to align with global program requirements.



  • Bachelor’s degree required; CIPP/US and/or information technology certifications are highly desirable.

  • Minimum of 2 years’ experience managing or supporting major incident management functions, with privacy or cybersecurity incident experience highly desirable. Minimum of 5 years' relevent business experience.

  • Experience leading teams, managing incident investigations and working with cross-functional groups.

  • Knowledgeable about U.S, Canada, Latin America privacy and data protection laws and regulations, best practices and industry standards/ frameworks and the GDPR.

  • Strong understanding of data breach notification laws.

  • High attention to detail and extremely organized to effectively manage multiple concurrent priorities including major incidents, program enhancements and requirements of the compliance organization.

  • Ability to work in a fast-paced environment with tight deadlines, and to adapt to unexpected changes in priorities.

  • Demonstrated ability to communicate verbally and in-writing complex incidents to stakeholders of varying levels, including to the Executive Committee and regulators.

  • Strong writing and presentation skills including the capability to prepare clear and concise incident summaries and reports.

  • Strong sense of ownership to drive tasks to completion and to identify opportunities for continuous improvement.

  • Project management experience highly desirable.

  • Proficient in managing incident response systems of record and in using Excel and PowerPoint to produce management ready presentations.

The above statements are intended to describe the general nature and level of the work being performed. They are not intended to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified .

We are proud to be an Equal Opportunity / Affirmative Action Employer and committed to leveraging the diverse backgrounds, perspectives, and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate in employment decisions on the basis of any protected category.

A conviction is not an absolute bar to employment. Factors such as the age of the offense, evidence of rehabilitation, seriousness of violation, and job relatedness are considered in all employment decisions. Additionally, it’s the bank’s policy to only inquire into a candidate’s criminal history after an offer has been made. Federal law

Job : Compliance

Primary Location : ARIZONA-Tempe

Other Locations : TEXAS-Irving

Job Posting : Jul 1, 2021, 12:55:13 PM

Shift: : Day

Schedule: : Full Time

Req ID: 10043421-WD