Oversee the overall security of Money Forward Kessai, collaborating with developers and information system staff to maintain and enhance security.
About this role
This full-time role manages the security and user experience of a global hardware fleet in the Global IT Division. The specialist designs, configures, and maintains endpoint management environments using Jamf Pro for macOS and Microsoft Intune for Windows 10/11 and iOS devices. The scope includes devices managed across Japan, Vietnam, and India.
Responsibilities include building and optimizing zero-touch provisioning workflows with Apple Business Manager (ABM/DEP) and Windows Autopilot. The role packages, tests, and deploys applications, updates, and operating-system patches through Jamf Self Service and Intune Company Portal. It also enforces CIS and NIST security baselines, manages FileVault and BitLocker full-disk encryption, configures conditional access policies, and uses remote wipe capabilities for lost or compromised devices.
The specialist writes and maintains operational scripts in Bash, Zsh, and PowerShell to automate configurations, remediate issues, and collect custom extension attributes. The role serves as the final escalation point for complex endpoint problems that the IT Helpdesk cannot resolve. It also works with the asset manager to update asset records through existing API scripting.
Applicants should have at least three years of dedicated experience in IT engineering, systems administration, or endpoint management. Required experience includes managing macOS and iOS devices at scale and knowledge of Microsoft Intune, Windows Autopilot, Azure AD (Entra ID), and Windows 11 management. PowerShell scripting for Windows and Bash or Zsh scripting for macOS are required. The role also requires an understanding of endpoint security, identity management, and the balance between strict security policies and end-user friction, together with the ability to write clear documentation for IT staff and non-technical users.
Preferred qualifications include Jamf Certified Admin (Jamf 300) or higher, Microsoft Certified: Endpoint Administrator Associate, integrations between MDM platforms and identity providers such as Okta, Google Workspace, or Azure AD, HRIS integrations, API automation between tools such as Jira, Slack, Jamf, and Intune, and experience in AI development or using AI tools to improve development processes. The organization is also developing AI-focused products and digital-worker capabilities.
Business-level English is required, equivalent to a TOEIC score of 700 or above, along with basic Japanese. The position is based at 21F Tamachi Station Tower S, msb Tamachi, 3-1-21 Shibaura, Minato-ku, Tokyo. The work style is hybrid; employees generally work from the office at least two days per week, with team office days varying by team. The basic working hours are 9:30 to 18:30 with a 60-minute break, under a discretionary labor system for professional work. Employees may choose working hours at their discretion, and overtime outside the determined hours may occur. The probationary period is three months from the joining date.
The annual salary range is JPY 5,808,000 to JPY 11,004,000, with fixed allowances included for up to 45 hours of legal overtime, legal holiday work, and 40 hours of late-night work. A high-performance bonus may be paid based on semi-annual evaluations and company performance. Benefits include social insurance, neighborhood housing and moving allowances, a salary-based rent deduction benefit, health and gynecological checkups, an influenza vaccine, book-purchase support, a defined-contribution corporate pension, an employee stock ownership plan, and contracted-service discounts. The company also provides current-CPU Mac or Windows PCs, work peripherals under its office-supplies policy, a book library, recruitment-meal support for referrals, and partial support for domestic and international conference participation.
The selection process may include a casual interview or document screening, a first interview, several additional interviews, a final interview, and an offer meeting. A technical assignment may precede an interview, and a reference check may be requested before or after the final interview.
This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.