Lead enterprise-wide digital transformation strategy and execution across Mizuho Securities and the financial group. Manage AI, data, and business reform projects, coordinate stakeholders, report to executives, and mentor DX personnel.
About this role
The security engineer will evaluate AI and generative AI products and projects, design and continuously improve security assessment standards and processes, organize security requirements with planning and development teams, conduct reviews, and propose improvements. The role includes coordinating review policies with the group-wide cyber security function, managing external partners for vulnerability assessments and security evaluations, reviewing deliverables, selecting and introducing security diagnostic tools and other security solutions, and planning measures to address AI-specific risks and emerging threats.
The position will help establish a new security function for AI-related work. It supports products and projects such as an iOS and web application for drafting meeting records, an AI slide-generation service, an AI interviewer that turns sales expertise into knowledge for RAG databases and proprietary language-model training data, and an internal-procedure search service that generates answers from company information. The role is intended to enable the safe expansion of AI use while supporting implementation and operational improvement in a financial-services environment.
Required qualifications include at least three years of practical experience in security, including designing, establishing, or improving security assessment or operational processes. Candidates must have practical experience with vulnerability assessments, security reviews, security assessments, or security architecture design; a basic understanding of applications, cloud, APIs, and authentication and authorization; experience organizing security issues, proposing improvements, and driving responses with stakeholders; and the ability to read code such as Python and TypeScript and create simple scripts. Experience assessing security or risks for AI, generative AI, or AI-agent projects; product security, security architecture, or security consulting experience; product-focused security work in a financial institution, operating company, or SaaS company; external-partner management, customer discussions, cross-functional consensus building, leadership, management, or organizational launch experience are welcomed.
Named technologies include Next.js, React, Vue.js, FastAPI, Streamlit, Assistants API, Agents SDK, Strands Agents SDK, LangChain, LangGraph, Vertex AI, AWS, S3, ECS, ElastiCache, Terraform, CDK, Bedrock, Bedrock Agentcore, Jest, Pytest, Playwright, GitHub, Teams, Slack, Jira, Confluence, ClaudeCode, AWS Kiro, OpenAI Codex, Amazon Q Developer, Devin, Dify, and v0. The posting states that the role is full-time and permanent, with a six-month probationary period. Work is based in Tokyo with hybrid office and remote work. Standard hours are 8:40 to 17:10, including a 60-minute break and 7.5 scheduled working hours; flextime may apply depending on the department. Weekends, public holidays, and specified year-end holidays are off, with 21 days of annual paid leave subject to the hiring month and other special leave. Salary is determined under company rules. Benefits include commuting-cost reimbursement, lunch assistance, social insurance, a stock ownership plan, childcare support, housing-related programs, asset-building support, and leisure support.
This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.