Lead customer projects for major Japanese companies from scope and architecture through data pipelines, implementation, rollout and operations, coordinating departments. Remote work is available.
About this role
This full-time internal IT security architect role is responsible for planning and advancing company-wide security architecture and CSIRT capabilities. The work covers security strategy and tactics, system planning, implementation, operations, and responses to cyber threats and vulnerabilities. The role participates broadly from design through implementation and subsequent improvement, with responsibilities adjusted according to experience and strengths.
Architecture responsibilities include creating the company-wide security architecture grand design, establishing strategies, tactics, and roadmaps, and planning, selecting, validating, and introducing security products. The role also designs post-implementation operations and improvements, defines security requirements for IT systems, conducts design reviews, analyzes usage, proposes improvements, and coordinates external vendors and agencies.
CSIRT responsibilities include designing the CSIRT strategy and operating structure, monitoring and responding to threats and vulnerabilities, handling incidents, designing and operating incident-response training, coordinating with external SOC and MSS partners, and collecting, analyzing, and applying threat intelligence.
The security function is being strengthened in preparation for business expansion and potential mergers and acquisitions. The position is expected to contribute to standardization and advancement based on an overall design rather than isolated countermeasures. It reports directly to the CISO, and the role covers the company-wide security environment supporting services including the economic information platform Speeda and the NewsPicks economic media platform. The company also operates in North America, China, and Southeast Asia. IT-domain offline events are held twice a year to support cross-team coordination.
Applicants must have at least three years of specialized experience in either security architecture or CSIRT and security operations. Relevant experience includes designing company-wide security architecture; selecting, introducing, operating, and improving security products based on company-wide policies; building or operating a SOC or CSIRT; vulnerability management, log monitoring, and practical incident response; and leading improvements to security structures or operations. Experience taking ownership of security design and implementation in an operating company, making decisions from the policy or design stage, and building consensus with varied internal stakeholders is emphasized.
Experience collecting and analyzing threat intelligence, practical forensics, in-depth cloud security knowledge, knowledge of zero trust or SASE, security integration after an acquisition, and using generative AI to improve system efficiency are listed as welcome qualifications.
The position is based in Marunouchi, Chiyoda-ku, Tokyo, postal code 100-0005, with full remote work permitted. Working hours use a full-flex system with no core time, and side work is permitted. The team determines attendance frequency and working hours according to its operating needs. Annual compensation is JPY 8.2–10.0 million and is determined through the selection process based on experience and skills. Holidays include Saturdays, Sundays, and public holidays, with at least 10 days of paid leave and a long-vacation program providing seven consecutive days off, including weekends, twice per year. Benefits include a company-provided PC selected from a catalog and a reduced-hours system. The work location may change to the employee’s home, the headquarters, or another company-approved location, and duties may change to any work designated by the company. Smoking is prohibited in workspaces; smoking is limited to a designated smoking room, and there is no work in smoking-permitted areas.
This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.