Cyber Proactive Security - Associate

MizuhoLondon, EnglandHybridFull-timeNew grad, 0–1 yearsListed 4 hours ago

Apply now

About this role

Profile Summary

Responsible for supporting the Proactive Security function, with an approximately equal focus on Privileged Access Management and broader security engineering. The role supports the CyberArk PAM service while helping Proactive Security design, implement, integrate and improve preventative security controls across the Bank. Working with infrastructure, application, architecture, risk and security teams, the role contributes to secure technology delivery, automation, security tool engineering, control improvement and cyber resilience. Proactive Security identifies and reduces security risk before it becomes an incident by strengthening privileged access, engineering preventative controls and improving the security technology environment.

Duties and Responsibilities

1. Privileged Access Management:

- Manage and support the multi-region CyberArk PAM platform, including Digital Vault, CPM, PSM, PSMP, CCP, AIM/AAM, PTA and supporting components.

- Onboard, maintain and decommission privileged accounts, service accounts, SSH keys, certificates and application credentials.

- Design and maintain CyberArk Safes, role-based access controls, platforms and policies aligned with least privilege, Zero Trust and applicable security standards.

- Support CyberArk upgrades, maintenance, disaster recovery testing, service improvements and future migration initiatives.

- Develop automation scripts and repeatable processes for onboarding, reconciliation, reporting, recertification and operational efficiency.

- Configure and support third-party integrations, connection components and non-standard connectors for business applications.

- Support application and DevOps teams with secrets management, credential rotation and secure application authentication.

##

2. Proactive Security Engineering:

- Support the Proactive Security function in designing, implementing and improving preventative security controls across infrastructure, applications, identity and cloud environments.

- Support evaluations, proof-of-concept exercises and pilot deployments for new security technologies.

- Assist with the onboarding, configuration, integration, tuning, testing and operational handover of cybersecurity tools.

- Work with engineering, infrastructure, application, architecture and third-party teams to deliver Proactive Security projects and control improvements.

- Contribute practical technical input to security designs, requirements, solution assessments, implementation plans and technical testing.

- Develop scripts, integrations and repeatable engineering processes that reduce manual effort and improve the reliability of security controls.

- Support certificate lifecycle management, secrets management, identity security, endpoint security, network security and cloud security initiatives where assigned.

- Identify control gaps and recommend practical engineering improvements that reduce risk before security incidents occur.

- Support security tooling upgrades, platform maintenance, service transition, resilience testing and technical lifecycle management.

3. Reporting and Documentation:

- Produce clear operational reports, dashboards, metrics and management information for Proactive Security and PAM activities.

- Maintain Proactive Security and PAM SOPs, runbooks, onboarding guides, platform diagrams, support procedures and control evidence.

- Ensure monitoring and review activities are documented with appropriate timestamps, screenshots and supporting records where required.

- Support Proactive Security standards, procedures, risk actions, control assessments and audit remediation plans.

- Deliver Proactive Security knowledge-sharing sessions and provide practical guidance to internal stakeholders.

Qualifications, Skills and Experience

Essential:

- Experience supporting enterprise cybersecurity, security engineering, infrastructure or identity security technologies.

- Good understanding of Privileged Access Management concepts and practical knowledge of CyberArk solutions.

- Understanding of identity security, least privilege, credential lifecycle management and Zero Trust principles.

- Working knowledge of Windows Server, Active Directory, Linux and enterprise networking concepts.

- Understanding of firewalls, proxies, VPNs, network segmentation and remote access technologies.

- Familiarity with security frameworks and standards such as NIST CSF, NIST 800-53, CIS Controls or ISO 27001.

- Ability to use PowerShell, Python or similar scripting technologies for automation and data handling.

- Strong analytical, troubleshooting, documentation and problem-solving skills.

- Ability to communicate clearly with technical and non-technical stakeholders and manage assigned work to agreed deadlines.

- Flexibility to provide occasional weekend or out-of-hours support in line with business requirements is expected.

##

Desirable:

- Experience with Azure, AWS or other cloud platforms and cloud security controls.

- Knowledge of DevSecOps, secrets management, CI/CD security and certificate lifecycle management.

- Experience supporting audit, regulatory, risk or compliance evidence requirements in a financial services environment.

- Relevant professional certification such as Security+, SC-200, SC-300, AZ-500, CyberArk Defender/Sentry or equivalent.

- Experience integrating and engineering preventative security controls in an enterprise environment.

- Experience with security tooling evaluation, proof-of-concept delivery, technical implementation or operational handover.

What Mizuho Can Offer You

Here at Mizuho, there are fantastic progression opportunities and clear paths to promotion. We will give you ample opportunity to affect change and to help grow our business.

In addition to the great opportunity outlined above we are also currently able to offer:

- Competitive starting salary, plus discretionary bonus

- Non-contributory pension

- 27 days’ annual leave

- Core working hours*

- Hybrid working - office and home based*

- Virtual GP

- Wellbeing benefits, including Mental Health Allies and First Aiders

*For applicable roles only

At Mizuho, we embrace flexible ways of working when the role permits. We offer different working arrangements like part-time, job-sharing and hybrid (office and home) working. Our purpose-led culture and global infrastructure help us connect, collaborate, and work together in agile ways to meet all our business needs.

We are committed to supporting equality and diversity, and seek to create a workplace that is fully inclusive. We welcome applications from all sections of the community that we operate in and from all ethnic backgrounds, sexual orientation, beliefs, gender identities and disabilities

If you require more information about our equal opportunities policy or wish to discuss any accessibility requirements or reasonable adjustments please contact the recruitment team – [email protected] and we will be happy to help.