- Location
- Tokyo
- Employment
- Full-time
- English
- English OK
- Visa
- Visa likely
- Posted
- 2026-08-11
- Category
- Software & IT
About this role
This position is based in Tokyo, Japan, within Mandiant Consulting’s offensive security team in Google Cloud. The team performs Red Team and Purple Team assessments of customer environments, including end-to-end emulation of cyber attacks. Consultants test customer defenses by identifying weaknesses and exercising defensive teams and capabilities.
Day-to-day work covers the attack lifecycle, from initial compromise and privilege escalation through lateral movement and achievement of the engagement’s objectives. Assessments may involve external penetration testing, web application security, mobile security, wireless security, network environments, cloud architectures, zero-trust environments, and identity-centric environments. The work may also emulate ransomware, financial, espionage, and other threat actors using current threat intelligence and offensive techniques.
The consultant develops tools, researches offensive methods, incorporates threat actor intelligence, and contributes to internal presentations and knowledge sharing. The role also includes preparing comprehensive and accurate reports and presentations for technical and executive audiences, advising C-level stakeholders, security leaders, and other customer representatives, and helping scope prospective engagements.
Responsibilities include leading engagement teams from kickoff through the remediation phase and mentoring other staff. The work requires adapting assessments to different customer technologies and environments while delivering realistic adversarial scenarios.
Required qualifications include a bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related technical field, or equivalent practical experience. Candidates must have at least three years of experience in offensive security or red teaming, including experience in areas such as network, web application, mobile, cloud, social engineering, scripting, or security tool development.
Preferred qualifications include offensive security certifications such as OSCE, OSEP, OSEE, OSCP, CISSP, or CISA, or relevant SANS courses. Experience creating security tools and understanding the underlying programming languages is preferred, including Python, C#, C, C++, Rust, Nim, or similar languages. Excellent communication skills are required to explain technical details through reports and presentations to both technical and executive audiences.
Google states that English proficiency is required for all roles unless a posting says otherwise.
This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.