Cybersecurity SOC/CSIRT Lead

Mizuho Financial Group

Security

Cybersec

Fintech

About this role

This role leads the development and operation of cyber incident response capabilities centered on the SOC and CSIRT across the group, including domestic and overseas locations. Responsibilities cover daily monitoring, detection, analysis, initial response, major incident command, reporting to management, and coordination of measures to prevent recurrence.

The role includes planning, designing, and improving SOC and CSIRT monitoring and response processes; defining monitoring coverage, detection logic, and response workflows; and setting usage policies for log management platforms, SIEM, EDR, and SOAR. It also involves planning and promoting rule updates, detection scenario design, and threat-hunting activities using cyber threat intelligence.

The successful candidate will help plan and implement stronger global SOC monitoring by coordinating with regional SOCs overseas. During cyber incidents, the role provides both technical and management leadership, including involvement in determining the content, timing, and messaging of reports to executives, relevant authorities, and business partners. The position also plans and directs responses to cybercrime such as phishing and unauthorized fund transfers.

Required qualifications include advanced expertise and practical experience in cybersecurity technology and incident response. Examples include experience in security, technical assessment, or intelligence at an IT vendor or major financial institution; management experience in infrastructure projects such as network or server construction or in security-tool implementation projects; and strong familiarity with security technologies and attack methods. Experience responding to major cyber incidents at a financial institution or critical-infrastructure operator, including overall incident management and recurrence-prevention planning, is preferred. Experience planning or operating anti-phishing, unauthorized-transfer, or unauthorized-access measures is also preferred.

Preferred certifications include CISSP, CISM, CISA, Registered Information Security Specialist, GIAC certifications such as GCIA, GCFA, or GCIH, and OSCP. Business-level English for collaboration with overseas offices and vendors is preferred.

The position is based in Tokyo. Telework may be included among company-designated work locations. It is a permanent employee position with no fixed contract period, a six-month probationary period, and standard working hours of 8:40 to 17:10 with 7.5 scheduled working hours and a 60-minute break. Flextime may apply depending on the department. Benefits and conditions include social insurance, commuting allowance, meal assistance, employee stock ownership, childcare support, housing-related programs, asset-building support, and leisure support. Salary is determined under company rules and is not numerically specified.

This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.