Propose banking-app and internet-banking systems to regional financial institutions, identify client needs, coordinate with internal and partner teams, and improve digital services and user experience.
About this role
This position is assigned to SBI Neo Banking System and belongs to the Risk and Quality Management Office. It manages system risk for systems and services provided to financial institutions, working with development, operations and management to maintain reliability and security.
Responsibilities include identifying, analyzing and assessing system risks from availability, confidentiality and integrity perspectives. The role conducts risk assessments, maintains the risk register, and creates and maintains system-risk policies, standards and procedures.
The position handles responses to Financial Services Agency and supervisory-authority guidelines, including standards for system outages, outsourcing management and cybersecurity. It responds to system-risk requirements and reporting requests from financial-institution clients and supports internal and external audits by preparing and explaining audit materials.
When a major system outage occurs, the role evaluates risk, analyzes the scope of impact and reports to management. It verifies the effectiveness of recurrence-prevention measures, manages permanent countermeasures, and develops, exercises and reviews business continuity plans. Security duties include assessing security risks, managing response priorities, planning vulnerability assessments and penetration tests, managing their results, preparing and training the cyber-incident response structure, and assessing and regularly monitoring outsourced providers.
Required experience includes at least three years of practical experience in IT system risk management or information-security management, experience in a financial institution or in financial-system development or operations, and experience with system outage management, BCP development and internal-control responses. Knowledge and practical experience with Financial Services Agency guidelines, ISMS including ISO/IEC 27001, PCI DSS or FISC safety standards are welcomed. Relevant security certifications such as Information Technology Engineers Examination Registered Information Security Specialist, CISM or CISSP, experience at a bank, securities or insurance institution or financial-system SIer, and risk-management support experience at an audit corporation or consulting firm are also welcomed. No education requirement is stated.
The position is full-time with an indefinite contract and a six-month probationary period. The workplace is in Roppongi, Minato-ku, Tokyo, with no transfer or workplace relocation. Remote work is available by consultation. Basic hours are 9:00 to 17:45 with a 60-minute break; there is no flextime system. This is a managerial position, so overtime pay is not provided. Estimated annual compensation is JPY 7.0 million to JPY 11.0 million, with performance-linked bonuses, one bonus payment per year and one salary review per year.
Benefits include reduced-hours work, casual dress, a defined-contribution pension, group life insurance, an employee stock ownership plan, childbirth and childcare support, certification and training support, and meal assistance. Additional benefits include Netflix access, discounted accommodation, corporate sports-club membership, health and mental-health consultations, childcare and nursing-care assistance, e-learning and a communication program. Social insurance covers health, employees' pension, employment and workers' accident compensation. Annual holidays total 120 days, including weekends, public holidays and the year-end period from December 31 to January 3; annual paid leave is 13 to 23 days. The premises are entirely smoke-free. The role may lead discussions with financial institutions and supervisory authorities, with possible progression to risk-management leadership or support for the CISO.
This is an AI-generated summary of the employer's original posting — details can be incomplete, out of date or simply wrong. Always confirm everything on the official posting before applying.