Lead enterprise-wide digital transformation strategy and execution across Mizuho Securities and the financial group. Manage AI, data, and business reform projects, coordinate stakeholders, report to executives, and mentor DX personnel.
About this role
This role leads group-wide cybersecurity governance and planning for domestic and overseas locations. Responsibilities include designing and maintaining security policies, standards, architecture principles, and operating rules based on global frameworks, guidelines, and current threat trends. The role also develops security reference architectures and standard configurations for IaaS, PaaS, and SaaS use.
The position plans and designs vulnerability assessment, patch management, and configuration management processes aligned with global standards. It also develops a company-wide cybersecurity risk assessment framework using approaches such as CRI Profile, conducts risk assessments for important systems and business operations with business divisions, IT divisions, and overseas locations, and monitors the results.
Additional work involves planning cybersecurity strategies and roadmaps aligned with management strategy, including investment plans, personnel plans, and organizational design in coordination with management, business companies, and group functions. The role also plans and promotes explanations and disclosures to regulatory authorities, supervisory authorities, industry associations, and other internal and external stakeholders. The scope and level of responsibility, including leadership, planning, and practical execution, are determined according to the candidate’s experience and skills.
Required qualifications are advanced cybersecurity expertise and practical experience, experience in cybersecurity governance at a global financial institution or large global company, or equivalent experience in an organization of comparable scale, and the ability to build consensus and facilitate discussions with diverse stakeholders. Examples listed include management experience in the IT division of a major financial institution or at an IT vendor, experience in crisis management, business continuity planning, or system risk management at a large company, and headquarters planning or audit experience at a consulting firm, audit corporation, or major company.
Preferred qualifications include internationally recognized security certifications such as CISSP, CISM, CISA, GIAC, or Japan’s Registered Information Security Specialist certification; deep document-level knowledge of NIST, CIS, CRI, and similar security guidelines with experience applying them in organizations and performing gap analysis; experience developing design policies and standardization for cloud security, including AWS or GCP; and business-level English ability.
The role is part of the Cybersecurity Coordination Department, which combines first-line defense, detection, and response against cyberattacks with second-line group-wide rule-making and governance. The department covers important infrastructure systems, large-scale cloud environments, overseas locations, and overseas subsidiaries.
The position is a full-time, indefinite-term employee role in Tokyo. The probationary period is six months, with the same salary during probation. Standard hours are 8:40 to 17:10, with 7 hours 30 minutes of scheduled work and a 60-minute break; flextime may apply depending on the department. The company may require overtime and holiday work. Holidays include Saturdays, Sundays, public holidays, and year-end and New Year holidays. Annual paid leave is 21 days, adjusted for the hiring month in the first year, with other special leave available.
Salary is determined under company rules based on ability and suitability. Commuting expenses are fully covered under company rules, and a lunch subsidy and overtime allowance may apply; managers and supervisors do not receive overtime or holiday-work allowances. Social insurance includes employment, workers’ accident, health, and employees’ pension insurance. Benefits include an employee stock ownership plan, babysitter childcare discounts, housing-related programs, asset-building support, and leisure support. The workplace is smoke-free indoors, and designated work locations may include telework locations.
This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.