Develop and improve Loglass Management through customer-informed design, server-side features, performance optimization, refactoring, testing, and development-process automation.
About this role
The first product security engineer will establish a security foundation for Loglass’s cloud-based management platform, which combines data warehouse and business-system characteristics and is used by enterprise companies. The role focuses on improving security across the product and development organization.
Responsibilities include creating security policies and strategies, defining security requirements, developing a security improvement culture, and supporting security-related development and operations. The engineer will also conduct and improve product security checks, strengthen DevSecOps, select and introduce tools, and design environments and processes for appropriate product incident response. Enabling the product organization with security knowledge is also part of the role.
The position initially belongs to the Cloud Infrastructure team, also described as the SRE team, and is expected to later become part of a dedicated product security team. The initial management and reporting line is to the Cloud Infrastructure team’s Engineering Manager. The engineer will work with development members with substantial autonomy. Depending on the person’s interests, the role may later include leading team formation as the product security team’s Engineering Manager.
Required experience includes practical application-security work such as vulnerability scanning, security testing, secure-development support, and risk-analysis support, together with theoretical knowledge of web-application security and cloud security. Desired experience includes building a security-focused internal culture, launching a PSIRT, web-application vulnerability assessments, penetration testing, targeted-attack resilience assessments, and understanding ISO/IEC 27001, ISO/IEC 27017, and CIS Controls. Experience with vulnerability management and operational processes using SCA or SBOM, threat-intelligence collection and analysis, DevSecOps operations, web-application development, and architecture is also valued.
The listed technology environment includes Kotlin, Spring Boot, Rust, Go, React, Next.js, TypeScript, AWS, Terraform, Fargate, ECR, Aurora PostgreSQL, Datadog Synthetics, Playwright, and Sysdig. Other listed tools include Slack, Gather, Figma, Findy team+, Notion, Miro, and diagrams.net.
This is a full-time permanent position with a three-month probationary period, extendable to six months. Annual compensation is JPY 8,000,000–15,000,000, determined according to experience and skills, with stock options available and salary reviews twice a year in April and October. The work location is the Tokyo office in Minato City, with remote work available. Working hours are 10:00–19:00 with a one-hour break, under a flextime system with core hours from 10:00–15:00. Benefits include company-leased housing, support for computer equipment, and a corporate defined-contribution pension plan. Insurance includes health, employees’ pension, employment, and workers’ compensation coverage. Holidays include weekends, public holidays, and the year-end and New Year period; leave includes annual paid leave, condolence leave, childcare nursing leave, nursing-care leave, and menstrual leave.
This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.