English summary for screening — check the original posting before applying.
We are seeking a Security Engineer to strengthen our security posture for both our products and internal systems. This role will lead initiatives in product security, incident response, and governance, acting as the first dedicated security specialist in the company.
Must-haves
- Experience in web application development or operations.
- Understanding of OWASP Top 10 vulnerabilities and experience implementing or identifying countermeasures.
- Ability to calmly make initial judgments and escalation decisions during security incidents.
- Communication skills to advance security measures by involving stakeholders.
Nice-to-haves
- Experience with vulnerability assessments or penetration testing, or vendor management.
- Experience operating supply chain security tools (Renovate, Dependabot, SCA tools, etc.).
- Experience with ISMS, SOC2, or PCI-DSS certifications.
- Experience with security measures for financial industry products.
- Security-related certifications (CISSP, Information Security Engineer, etc.).
Tech stack
RenovateDependabotContainer scanning
Work style
Hybrid or remote work possible in Tokyo (Shinjuku). Full remote is possible, but may depend on the position. Full flex time with no core hours (05:00-22:00 available).
Other notes
Annual salary range: JPY 5,000,000 - 8,000,000. Probationary period: 1 to 6 months (no change in conditions).