Why Mizuho
At Mizuho, we provide the stability of an international industry leader with the career trajectory of a growing business. Our steady, strategic growth gives our people at all levels rewarding degrees of responsibility and richer work experience than a boutique firm or an established giant could offer alone
It's the local expertise of our employees that makes our global network so powerful. By collaborating with colleagues and clients who have the same ambition and drive, you can amplify your sphere of influence and base of knowledge as part of one of the largest and growing banks in the world.
Role Overview:
Mizuho EMEA is building a strategic cybersecurity capability hub in Pune and expanding its Vulnerability Management and Threat Exposure Management capabilities to proactively identify, prioritize, and reduce cyber risk across infrastructure, cloud platforms, applications, containers, and third-party technologies.
The successful candidate will work closely with Infrastructure, Cloud, Network, Application Development, DevSecOps, Security Operations, and Risk teams to improve security posture through risk-based vulnerability management, exposure assessments, security testing, and continuous improvement initiatives.
Key Responsibilities:
Vulnerability & Threat Exposure Management
- Perform vulnerability and exposure assessments across infrastructure, cloud, applications, containers, and enterprise technology platforms.
- Prioritize and validate vulnerabilities using threat intelligence, exploitability, business criticality, exposure, and overall cyber risk.
- Drive vulnerability remediation, validation testing, exception management, and risk acceptance processes to improve security posture.
- Monitor emerging threats, known exploited vulnerabilities, and security advisories to assess organizational impact and remediation priorities.
- Support attack surface management initiatives by identifying externally exposed assets, security weaknesses, and opportunities for risk reduction
Cloud, Application & Container Security
- Support vulnerability assessments across cloud platforms and cloud-native services.
- Assess container environments and cloud workloads for security weaknesses and misconfigurations.
- Review findings from application security testing, software composition analysis, and penetration testing activities.
- Partner with application and DevSecOps teams to remediate software, API, and supply chain security risks.
Security Testing & Remediation Governance
- Coordinate internal and external penetration testing activities across infrastructure, applications, APIs, and cloud environments.
- Review testing results, validate remediation ownership, and support risk-based prioritization.
- Track remediation activities through closure and coordinate validation or retesting activities.
- Work with technology teams to ensure timely remediation of identified security weaknesses.
Governance, Metrics & Continuous Improvement
- Produce vulnerability metrics, remediation reporting, and risk insights supporting operational governance and executive reporting.
- Maintain vulnerability records, audit evidence, and support risk documentation.
- Support regulatory, audit, compliance, and control testing activities.
- Help develop common vulnerability management processes, reporting standards, and governance practices that support consistency across global regions.
Required Qualifications:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline.
- 3-7 years of experience in Vulnerability Management, Threat Exposure Management, Security Operations, Application Security, Cloud Security, or related cybersecurity functions.
- Robust understanding of vulnerability management lifecycles, threat intelligence,
risk assessment, and remediation governance.
- Experience working with cloud security, application security, container security, and security testing practices.
- Understanding of CIS Benchmarks, secure configuration standards, and security best practices.
- Strong analytical, troubleshooting, and stakeholder management skills.
- Ability to communicate technical risks clearly to both technical and non-technical audiences.
Technologies & Tools:
Experience with Vulnerability Management Platforms, Exposure Management Solutions, Cloud Security Tooling, Container Security Solutions, Application Security Testing Tools, Security Monitoring Platforms, Threat Intelligence Solutions, Security Automation, ITSM Platforms, and related cybersecurity technologies
Organization Overview:
Mizuho Global Services (MGS), Pune is an integral part of Mizuho Financial Group, one of the world's leading financial institutions with a strong global presence across the Americas, EMEA, and Asia. Based in India, MGS Pune supports Mizuho's international businesses by delivering high-quality, scalable, and resilient services across multiple functions.
MGS Pune plays a critical role in driving operational excellence, standardization, and innovation for Mizuho Americas. By combining deep domain expertise with strong process, technology, and analytical capabilities, it partners closely with regional and global teams to support corporate and investment banking, capital markets, and corporate services functions, while adhering to the highest standards of risk management, regulatory compliance, and control.
MGS Pune offers competitive compensation and benefits package aligned with industry standards and local market practices. MGS Pune is an equal opportunity employer and is committed to fostering an inclusive and diverse workplace. Employment is subject to applicable background verification checks in accordance with Indian laws and company policies.
https://www.mizuhogroup.com/asia-pacific/mizuho-global-services/careers
📌 Vulnerability Management and Threat Exposure Management - Analyst (Pune)
🏢 Mizuho
📍 Pune