Senior Security Engineer

GO Inc.

Security

Cybersec

Python

About this role

This role leads company-wide security initiatives in the IT Strategy Division. Responsibilities include advancing a zero-trust architecture, designing, improving, operating, and standardizing security platforms, and leading incident response. The security platforms named in the posting include Entra ID, Intune, Jamf, Microsoft Defender for Endpoint, and Netskope.

The role may focus on corporate security, security governance, or related cross-functional work. Corporate security responsibilities include developing monitoring strategies, implementing and tuning detection logic for large-scale logs, threat hunting, log analysis, endpoint forensics, malware analysis, and overall incident command. The position also develops automation tools using Python and GAS for investigation, response operations, and SaaS integrations.

Governance responsibilities include creating and revising company-wide security policies and rules, automating and improving internal inquiry handling with AI, and managing projects for obtaining and maintaining certifications such as ISMS, including internal audit coordination. In collaboration with the product security team, the role plans vulnerability assessments and penetration tests for company products and manages external vendors and project progress.

The security group has approximately five members, with projects generally handled by teams of one or two people. The role is expected to rebuild and standardize operating foundations, address risks related to emerging technologies such as AI, and establish a more advanced zero-trust environment for diverse devices and network access conditions. Relevant experience includes infrastructure or security product operations; SOC or CSIRT work involving log analysis, forensics, or detection-rule creation; troubleshooting and tool development; process systemization and automation; and information security management, including policy development, certification operations, or audits.

Preferred experience includes designing, building, or operating zero-trust architectures; malware analysis; digital forensics; large-scale log analysis platforms; vulnerability assessment and penetration-test vendor management; web application development; infrastructure as code; DevOps or platform engineering; security certifications or frameworks such as ISMAP, SOC 2, ISO 27001, CIS Controls, or NIST; and certifications such as CISSP, CISM, CISA, or Registered Information Security Specialist. English document reading and technical research on overseas products are also listed as preferred skills.

The position is full-time and based in Minato, Tokyo, with remote work available. It uses a super-flextime system with no core hours. Annual compensation is determined according to skills and experience and includes a fixed overtime allowance for 45 hours per month, except where the hire is classified as a manager or supervisor. Compensation is reviewed twice yearly, with an annual performance-linked payment. Benefits include social insurance, transportation reimbursement up to 50,000 yen per month, a monthly New Normal allowance of 10,000 yen, childcare allowance, paid leave, holidays, and other stated leave programs.

This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.