Security Engineer

Money Forward

Security

About this role

This Security Engineer designs, implements, and operates security controls for the software development lifecycle. The role works with software engineers and SREs on code security reviews, automates security checks and integrations with scripts and tools, and helps identify risks in systems and development processes. Responsibilities also include incident response, vulnerability management, and improving security processes, guidelines, reusable patterns, and components.

The engineer will evaluate, introduce, and operate AI development support tools such as Claude, Cursor, and Codex, while creating mechanisms for their safe use. The position is expected to provide practical security solutions rather than only policy guidance, propose and implement mitigations, and help development teams adopt secure practices without obstructing productivity.

Required qualifications include practical experience as a security engineer, infrastructure engineer, SRE, or software engineer with significant security involvement. Candidates need hands-on experience designing, deploying, and operating secure environments on AWS or another major cloud platform; the ability to script or code using Python, shell, or similar languages; and experience with threat modeling, vulnerability analysis, or secure code review in a development or DevOps context. Familiarity with CI/CD, Infrastructure as Code, containerization, and embedding security into development workflows is required, along with the ability to explain risks and solutions to technical and non-technical stakeholders.

Preferred experience includes securing large-scale or highly available AWS systems, applying AI tools to security automation or development processes, application security, secure coding, API security, OWASP Top 10, incident response, log analysis, and security monitoring in a cloud-native environment. Information-security or cloud-security certifications and formal training are welcome but not mandatory. Experience in AI development or using AI tools to improve development processes is also preferred.

The role supports products and infrastructure in a large-scale cloud-native environment and contributes to security strategy, standards, and AI-assisted development workflows. Japanese is not required. English proficiency equivalent to a TOEIC score of 700 or above is requested; candidates without an equivalent score may take a designated test during the interview process.

This is a full-time regular position in Tokyo. Annual compensation is 6,408,000 to 11,004,000 JPY, with monthly salary of 534,000 to 917,000 JPY including fixed allowances for up to 45 hours of legal overtime, legal holiday work, and 40 hours of late-night work. A high-performance bonus may be paid based on semi-annual evaluations and may change according to company performance. The probationary period is three months from the join date.

The working system is discretionary labor for professional work, subject to conditions and possible change to a flextime system. Basic hours are 9:30 to 18:30 with a 60-minute break, although employees may choose their working hours at their discretion and overtime may occur. The work style is hybrid; employees generally work from the office at least two days per week, with three or more days encouraged. Team office days may vary.

Holidays include Saturdays, Sundays, Japanese national holidays, paid leave, three summer holidays, two winter holidays, and year-end and New Year holidays from December 31 to January 3. Benefits include social insurance, neighborhood housing and moving allowances, salary-based rent deduction, health checks, influenza vaccination, book-purchase support, a defined-contribution corporate pension, an employee stock ownership plan, and preferential rates for certain contracted services. The company also provides recent-CPU Mac or Windows PCs, work peripherals, a library and book purchasing, recruitment-meal support, referral rewards, and partial support for domestic and international conference participation.

The selection process may include a casual interview or document screening, a first interview with a possible technical assignment, several interviews, a final interview, a possible reference check, and an offer meeting. The process may change depending on the case.

This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.