Cyber Proactive Security - Associate

Mizuho EMEA

Greater London

Hybrid

GBP 65,000 - 90,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Competitive salary + bonus
Non-contributory pension
27 days annual leave
Hybrid work
Virtual GP
Wellbeing benefits

Job summary

Mizuho EMEA is seeking a Proactive Security Engineer focused on Privileged Access Management and security engineering to support CyberArk PAM and broader preventative controls across the bank. You will work with infrastructure, DevOps, and risk teams to design, implement, and automate security tooling, credential management, and incident prevention.

The role offers hybrid work, a competitive salary with discretionary bonus, and a path to progression within a global financial services

Qualifications

  • Experience supporting enterprise cybersecurity, security engineering, infrastructure or identity security technologies.
  • Good understanding of Privileged Access Management concepts and CyberArk solutions.
  • Understanding of identity security, least privilege and Zero Trust.

Responsibilities

  • Support Privileged Access Management and CyberArk PAM platform operations.
  • Design and implement preventative security controls across infrastructure, apps and cloud environments.
  • Develop automation scripts and repeatable processes for onboarding, reconciliation and control improvements.
  • Produce operational reports and maintain SOPs for Proactive Security and PAM.

Skills

Privileged Access Management
CyberArk knowledge
Scripting (PowerShell/Python)
Cloud security
Audit/Regulatory experience
Stakeholder communication

Education

Security+ or SC-200/SC-300 or AZ-500
Bachelor's degree in CS/IS or related

Tools

CyberArk
Azure
AWS
Security tooling

Job description

Select how often (in days) to receive an alert:

Responsible for supporting the Proactive Security function, with an approximately equal focus on Privileged Access Management and broader security engineering. The role supports the CyberArk PAM service while helping Proactive Security design, implement, integrate and improve preventative security controls across the Bank. Working with infrastructure, application, architecture, risk and security teams, the role contributes to secure technology delivery, automation, security tool engineering, control improvement and cyber resilience. Proactive Security identifies and reduces security risk before it becomes an incident by strengthening privileged access, engineering preventative controls and improving the security technology environment.

Duties and Responsibilities
1. Privileged Access Management:
  • Manage and support the multi-region CyberArk PAM platform, including Digital Vault, CPM, PSM, PSMP, CCP, AIM/AAM, PTA and supporting components.
  • Onboard, maintain and decommission privileged accounts, service accounts, SSH keys, certificates and application credentials.
  • Design and maintain CyberArk Safes, role-based access controls, platforms and policies aligned with least privilege, Zero Trust and applicable security standards.
  • Support CyberArk upgrades, maintenance, disaster recovery testing, service improvements and future migration initiatives.
  • Develop automation scripts and repeatable processes for onboarding, reconciliation, reporting, recertification and operational efficiency.
  • Configure and support third-party integrations, connection components and non-standard connectors for business applications.
  • Support application and DevOps teams with secrets management, credential rotation and secure application authentication.
2. Proactive Security Engineering:
  • Support the Proactive Security function in designing, implementing and improving preventative security controls across infrastructure, applications, identity and cloud environments.
  • Support evaluations, proof-of-concept exercises and pilot deployments for new security technologies.
  • Assist with the onboarding, configuration, integration, tuning, testing and operational handover of cybersecurity tools.
  • Work with engineering, infrastructure, application, architecture and third-party teams to deliver Proactive Security projects and control improvements.
  • Contribute practical technical input to security designs, requirements, solution assessments, implementation plans and technical testing.
  • Develop scripts, integrations and repeatable engineering processes that reduce manual effort and improve the reliability of security controls.
  • Support certificate lifecycle management, secrets management, identity security, endpoint security, network security and cloud security initiatives where assigned.
  • Identify control gaps and recommend practical engineering improvements that reduce risk before security incidents occur.
  • Support security tooling upgrades, platform maintenance, service transition, resilience testing and technical lifecycle management.
3. Reporting and Documentation:
  • Produce clear operational reports, dashboards, metrics and management information for Proactive Security and PAM activities.
  • Maintain Proactive Security and PAM SOPs, runbooks, onboarding guides, platform diagrams, support procedures and control evidence.
  • Ensure monitoring and review activities are documented with appropriate timestamps, screenshots and supporting records where required.
  • Support Proactive Security standards, procedures, risk actions, control assessments and audit remediation plans.
  • Deliver Proactive Security knowledge-sharing sessions and provide practical guidance to internal stakeholders.
Qualifications, Skills and Experience
  • Experience supporting enterprise cybersecurity, security engineering, infrastructure or identity security technologies.
  • Good understanding of Privileged Access Management concepts and practical knowledge of CyberArk solutions.
  • Understanding of identity security, least privilege, credential lifecycle management and Zero Trust principles.
  • Working knowledge of Windows Server, Active Directory, Linux and enterprise networking concepts.
  • Understanding of firewalls, proxies, VPNs, network segmentation and remote access technologies.
  • Familiarity with security frameworks and standards such as NIST CSF, NIST 800-53, CIS Controls or ISO 27001.
  • Ability to use PowerShell, Python or similar scripting technologies for automation and data handling.
  • Strong analytical, troubleshooting, documentation and problem-solving skills.
  • Ability to communicate clearly with technical and non-technical stakeholders and manage assigned work to agreed deadlines.
  • Flexibility to provide occasional weekend or out-of-hours support in line with business requirements is expected.
  • Experience with Azure, AWS or other cloud platforms and cloud security controls.
  • Knowledge of DevSecOps, secrets management, CI/CD security and certificate lifecycle management.
  • Experience supporting audit, regulatory, risk or compliance evidence requirements in a financial services environment.
  • Relevant professional certification such as Security+, SC-200, SC-300, AZ-500, CyberArk Defender/Sentry or equivalent.
  • Experience integrating and engineering preventative security controls in an enterprise environment.
  • Experience with security tooling evaluation, proof-of-concept delivery, technical implementation or operational handover.

What Mizuho Can Offer You

Here at Mizuho, there are fantastic progression opportunities and clear paths to promotion. We will give you ample opportunity to affect change and to help grow our business.

In addition to the great opportunity outlined above we are also currently able to offer:

  • Competitive starting salary, plus discretionary bonus
  • Non-contributory pension
  • 27 days' annual leave
  • Core working hours*
  • Hybrid working - office and home based*
  • Virtual GP
  • Wellbeing benefits, including Mental Health Allies and First Aiders

*For applicable roles only

At Mizuho, we embrace flexible ways of working when the role permits. We offer different working arrangements like part-time, job-sharing and hybrid (office and home) working. Our purpose-led culture and global infrastructure help us connect, collaborate, and work together in agile ways to meet all our business needs.

We are committed to supporting equality and diversity, and seek to create a workplace that is fully inclusive. We welcome applications from all sections of the community that we operate in and from all ethnic backgrounds, sexual orientation, beliefs, gender identities and disabilities

If you require more information about our equal opportunities policy or wish to discuss any accessibility requirements or reasonable adjustments please contact the recruitment team – recruitment@mizuhoemea.com and we will be happy to help.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Engineer - Assistant Vice President
Cyber Security Engineer - Assistant Vice President

Mizuho EMEA • Greater London

On-site
GBP 100,000 - 140,000
Competitive salary + discretionary 3–5
Hybrid working – office and home based
27 days annual leave
+2
Cyber Security Engineer - Assistant Vice President
Cyber Security Engineer - Assistant Vice President

Mizuho • Greater London

Hybrid
GBP 60,000 - 80,000
Competitive starting salary
Non-contributory pension
27 days annual leave
+2
Risk Collateral Management Team - Vice President
Risk Collateral Management Team - Vice President

Mizuho • Greater London

Hybrid
GBP 65,000 - 90,000
Competitive starting salary
Discretionary bonus
Non-contributory pension
+4
Credit & Middle Office - Analyst
Credit & Middle Office - Analyst

myGwork - LGBTQ+ Business Community • Greater London

On-site
GBP 30,000 - 40,000
Competitive starting salary
Non-contributory pension
27 days' annual leave
+1
Japanese Banking Europe, Relationship Manager - Vice President
Japanese Banking Europe, Relationship Manager - Vice President

Mizuho EMEA • Greater London

Hybrid
GBP 120,000 - 170,000
Competitive starting salary
Discretionary bonus
Non-contributory pension
+5
KYC Coordination team - Vice President
KYC Coordination team - Vice President

Mizuho EMEA • Greater London

Hybrid
GBP 90,000 - 140,000
Discretionary bonus
Non-contributory pension
27 days’ annual leave
+1
Legal Counsel, Data Privacy & Commercial Contracts - Vice President
Legal Counsel, Data Privacy & Commercial Contracts - Vice President

Mizuho • Greater London

Hybrid
GBP 120,000 - 180,000
Hybrid working
Competitive salary and discretionary '
Financial Crime Compliance, Sanctions - AVP
Financial Crime Compliance, Sanctions - AVP

Mizuho EMEA • Greater London

Hybrid
GBP 65,000 - 95,000
Hybrid working
27 days annual leave
Non-contributory pension
+2
Compliance Surveillance - Vice President
Compliance Surveillance - Vice President

Mizuho EMEA • Greater London

Hybrid
GBP 65,000 - 75,000
Competitive starting salary
Discretionary bonus
Non-contributory pension
+5
JBE - Credit Middle - Analyst
JBE - Credit Middle - Analyst

Inter Act B.V. • Greater London

On-site
GBP 30,000 - 60,000
Competitive starting salary
Discretionary bonus
Non-contributory pension
+5