Information Security Operations Leader

ArkEdge Space

Security

Cybersec

Linux

About this role

The Information Security Operations Leader will lead company-wide information security governance from the Information Systems Department. The initial priority is to establish policies and frameworks, strengthen ISMS operations, and create security processes that function in daily work. The role will collaborate with information systems members, development engineers, management, and business departments rather than handling every area alone.

Responsibilities include reviewing the existing ISMS documentation, identifying ineffective areas, developing internal regulations with reference to Japan’s Cybersecurity Management Guidelines Version 3.0, and designing and embedding access and privilege management processes. The role will also build agreement with management and departments and establish practical rules.

For ISMS operations, the position will plan and execute annual activities, conduct internal audits, respond to external assessments, perform risk assessments, design and promote corrective actions, and prepare inputs and reports for management reviews. The role will plan and deliver company-wide and department-specific security training for onboarding, annual programs, and ad hoc needs.

Working with existing members and development engineers, the leader will design CSIRT processes covering initial response, root-cause analysis, recovery, and recurrence prevention, and plan incident response exercises. The role will systematize threat intelligence collection, evaluation, and response, including existing monitoring of OSS supply-chain threats and sharing through GitHub Issues. It will also lead requirements definition, selection, and implementation of security tools, with budget securing and technical validation handled by the team.

Longer-term work includes planning and promoting a roadmap toward NIST SP 800-171 compliance, expanding security measures to OT environments in development and manufacturing, and systematizing supply-chain risk management, including SBOM management and continuous dependency monitoring. A future path is to become a CISO-equivalent security executive and lead an expanded team.

The position supports a small-space technology company that designs, manufactures, and operates small satellites and provides related components, software, and satellite ground-station services. The company has ISMS certification, while company-wide security policies and frameworks are still being developed. Space-industry experience is not required; security governance experience in manufacturing, finance, SaaS, or other industries is accepted.

The work location is the Ariake office in Koto-ku, Tokyo. The standard arrangement is office-based, with limited remote work permitted. The listed operating environment includes Windows, macOS, Linux, Google Workspace, GitHub, Slack, Zoom, GitHub Projects V2, GitHub Issues, Redmine, Ubiquiti UniFi, and CrowdStrike EDR. The selection process consists of document screening, a 60-minute first interview, a second interview with an aptitude test, and a final interview.

This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.