Why Mizuho
At Mizuho, we provide the stability of an international industry leader with the career trajectory of a growing business. Our steady, strategic growth gives our people at all levels rewarding degrees of responsibility and richer work experience than a boutique firm or an established giant could offer alone
It’s the local expertise of our employees that makes our global network so powerful. By collaborating with colleagues and clients who have the same ambition and drive, you can amplify your sphere of influence and base of knowledge as part of one of the largest and growing banks in the world.
Role Overview:
Mizuho EMEA is building a strategic cybersecurity capability hub in Pune and expanding its Threat & Exposure Management capability to proactively identify, assess, prioritize, and reduce cyber risk across infrastructure, cloud platforms, applications, containers, APIs, and third-party technologies.
The Threat & Exposure Management Lead will be responsible for leading the enterprise vulnerability management program, driving threat-informed risk prioritization, attack surface visibility, remediation governance, and cyber risk reporting. The role will partner closely with Infrastructure, Cloud, Application Development, DevSecOps, Security Operations, Architecture, and Risk teams to strengthen the organization's overall security posture and reduce enterprise cyber risk.
Key Responsibilities:
Threat & Exposure Management
- Lead the enterprise Threat & Exposure Management program across infrastructure, cloud platforms, applications, containers, APIs, and third-party technologies.
- Establish and mature vulnerability management standards, governance processes, remediation workflows, reporting, and operating procedures.
- Drive risk-based prioritization using exploitability, threat intelligence, exposure, business criticality, and cyber risk.
- Oversee External Attack Surface Management activities to identify exposed assets, security weaknesses, and emerging threats.
- Govern remediation activities, SLA adherence, validation testing, exception management, and risk acceptance processes.
- Deliver meaningful cyber risk reporting, executive metrics, and vulnerability reduction outcomes.
- Establish common vulnerability management processes, reporting standards, and governance frameworks that support consistency across global regions.
Threat Intelligence & Risk Prioritization
- Integrate threat intelligence, active exploitation trends,
ransomware activity, and known exploited vulnerabilities into remediation priorities.
- Lead rapid risk assessments for critical vulnerabilities, zero-day threats, and major security advisories.
- Translate technical findings into actionable business risk insights that support leadership decision-making.
Security Testing & Exposure Reduction
- Oversee application security testing, API security assessments, software composition analysis, and software supply chain security risk management.
- Partner with engineering and DevSecOps teams to identify and reduce cloud, container, and application security exposures.
- Coordinate penetration testing, Breach & Attack Simulation (BAS), Red Team, and Purple Team engagements to validate control effectiveness and remediation outcomes.
- Ensure security findings are prioritized, tracked, validated, and remediated through established governance processes.
- Support secure configuration and hardening initiatives aligned with CIS Benchmarks and industry security standards.
Leadership & Governance
- Lead and develop a high-performing Threat & Exposure Management team.
- Partner with Infrastructure, Cloud, Security Operations, Architecture, DevSecOps, and Risk teams to reduce cyber risk.
- Support audit, regulatory, compliance, and control assurance activities.
- Present cyber risk, vulnerability posture, exposure trends, and remediation performance to senior management and governance forums.
Required Skills & Technical Expertise
- Threat & Exposure Management
- Vulnerability Management
- Attack Surface Management
- Threat Intelligence Integration
- Risk-Based Prioritization & Remediation Governance
- Security Metrics, Reporting & Executive Communication
- Application Security & API Security
- Cloud & Container Security
- Software Supply Chain Security
- Security Validation, BAS & Penetration Testing
- Secure Configuration & CIS Benchmark Practices
- Leadership, Stakeholder Management & Team Development
Essential Experience & Qualifications:
- 12+ years of cybersecurity experience within enterprise or regulated environments.
- 5+ years leading Vulnerability Management, Threat Management, Exposure Management, Security Operations, Cyber Risk, DevSecOps, or related security functions.
- Proven experience managing enterprise-scale vulnerability, exposure management, and remediation programs.
- Strong understanding of infrastructure, cloud, application, container, and software supply chain risk.
- Experience developing governance frameworks, executive reporting, and cyber risk metrics.
- Ability to translate technical findings into business risk and influence senior stakeholders.
- Experience presenting to executive leadership, governance forums, and audit or risk committees.
- Demonstrated people leadership and team development experience.
Technologies & Tools Experience with Vulnerability Management Platforms, Exposure Management Solutions, Threat Intelligence Platforms, Application Security Testing Tools (SAST, DAST, SCA), Cloud Security Tooling, Container Security Solutions, Security Validation & BAS Platforms, Security Monitoring Platforms, Security Automation, and related cybersecurity technologies
Organization Overview:
Mizuho Global Services (MGS), Pune is an integral part of Mizuho Financial Group, one of the world’s leading financial institutions with a solid global presence across the Americas, EMEA, and Asia. Based in India, MGS Pune supports Mizuho’s international businesses by delivering high-quality, scalable, and resilient services across multiple functions.
MGS Pune plays a critical role in driving operational excellence, standardization, and innovation for Mizuho Americas. By combining deep domain expertise with strong process, technology, and analytical capabilities, it partners closely with regional and global teams to support corporate and investment banking, capital markets, and corporate services functions, while adhering to the highest standards of risk management, regulatory compliance, and control.
MGS Pune offers competitive compensation and benefits package aligned with industry standards and local market practices. MGS Pune is an equal opportunity employer and is committed to fostering an inclusive and diverse workplace. Employment is subject to applicable background verification checks in accordance with Indian laws and company policies.
https://www.mizuhogroup.com/asia-pacific/mizuho-global-serv ices/careers
📌 Threat & Exposure Management Lead (Pune)
🏢 Mizuho
📍 Pune