Join a market-leading FinTech and digital payments company in Tokyo as an IT Security Engineer, helping protect high-volume payment platforms and electronic money services used by tens of millions of customers.
This role combines cybersecurity risk management, CSIRT incident response, security governance, and financial regulatory compliance. You will assess security risks across payment systems and technology infrastructure, strengthen cybersecurity policies, support incident response, and identify gaps against Japanese financial regulatory requirements, including FSA guidelines.
Working across security, engineering, operations, and compliance teams, you will play an important role in strengthening the organisation's cyber resilience while gaining exposure to areas such as cloud security, Zero Trust, DevSecOps, and Secure-by-Design.
Key Responsibilities
- Manage CSIRT operations and cybersecurity incident response, coordinating investigation, escalation, remediation, and follow-up activities.
- Develop, maintain, and continuously improve cybersecurity governance policies, security guidelines, standards, and internal documentation.
- Conduct cybersecurity risk assessments across digital payment systems, electronic money services, applications, and supporting infrastructure.
- Identify security and compliance gaps against Japanese financial regulatory requirements, including relevant Financial Services Agency (FSA) guidelines.
- Coordinate with engineering, operations, compliance, and other stakeholders to implement appropriate security controls and remediation measures.
- Evaluate and support the implementation of new cybersecurity products and technologies to strengthen security and regulatory compliance.
- Create and deliver cybersecurity training, awareness materials, and educational content for internal teams.
- Analyse security risks across network, server, cloud, and application environments and recommend practical mitigation strategies.
- Support continuous improvements to the organisation's cybersecurity governance and incident response capabilities.
Required Skills and Qualifications
Experience:
- 3+ years of hands-on professional experience in information security, cybersecurity, or a closely related security role.
- Practical knowledge of system development and IT operations across network, server, or cloud environments.
- Experience conducting cybersecurity risk assessments, security governance, regulatory gap analysis, or compliance reviews.
- Understanding of cybersecurity incident response and CSIRT-related processes.
- Ability to develop or maintain security policies, guidelines, standards, and governance documentation.
- Experience working with technical and business teams to identify security risks and implement appropriate controls.
- Bachelor's degree or equivalent qualification.
Soft Skills:
- Strong stakeholder management, negotiation, and cross-functional coordination skills.
- Excellent analytical and problem-solving abilities, with the ability to translate security risks into practical actions.
- Strong communication skills for working effectively with engineering, operations, compliance, and business teams.
- Collaborative mindset combined with a strong sense of ownership and accountability.
- Proactive approach to identifying security weaknesses and driving improvements across complex technology environments.
Language Requirements:
- Japanese: Business-level proficiency required for cross-departmental coordination, documentation, and stakeholder negotiations.
- English: Conversational proficiency; business-level communication skills would be advantageous for working in an international technology environment.
Preferred Skills & Qualifications
- Experience working in financial services, FinTech, payments, electronic money, or critical infrastructure security.
- Hands-on experience with CSIRT, incident response, threat monitoring, logging, or SIEM analysis.
- Experience with DevSecOps practices and integrating security into software development and operational processes.
- Knowledge of AWS, Azure, or GCP cloud security.
- Understanding of Zero Trust architecture and Secure-by-Design principles.
- Knowledge of Japanese financial cybersecurity regulations or FSA security guidelines.
- Industry-recognised cybersecurity certifications such as CISSP, CISM, CEH, or CompTIA Security+.
- Business-level English communication skills.
About the Company
Our client is a market-leading FinTech and digital finance company operating large-scale cashless payment and electronic money services used by tens of millions of customers.
As the organisation continues to expand its digital financial ecosystem, cybersecurity is critical to protecting payment infrastructure, customer data, and high-volume financial transactions.
The dedicated cybersecurity function works across CSIRT, security governance, risk management, regulatory compliance, cloud security, and security architecture, providing an opportunity to build broad expertise while protecting some of Japan's most heavily used digital financial services.
Why You'll Love Working Here
- Protect large-scale payment and electronic money platforms used by tens of millions of customers.
- Build valuable expertise in FSA regulatory compliance, cybersecurity governance, risk assessment, and CSIRT.
- Gain exposure to modern security approaches including Zero Trust, DevSecOps, cloud security, and Secure-by-Design.
- Work closely with product engineering, IT operations, cybersecurity, and compliance teams on high-priority initiatives.
- Take ownership of meaningful cybersecurity projects within a fast-moving FinTech environment.
- Strong potential to transition into a permanent position based on performance, impact, and business requirements.
- Benefit from remote work/WFH options, flex time, minimal overtime, and casual clothing.
- Develop your cybersecurity career within a business where security directly supports nationwide digital financial services.
Don't Miss Out - Apply Now!
