Назад
Company hidden
20 дней назад

Corporate IT & Security Specialist (GRC)

6 500 000 - 9 500 000JPY
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
c1
Страна
Japan
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Corporate IT & Security Specialist (GRC) (ISO 27001/27017/27018): Coordinating the maintenance of information security controls, audits, documentation, and evidence collection for an internal IT organization with an accent on GRC operations, risk management, and compliance processes. Focus on managing control ownership across teams, preparing for external audits, improving security procedures, and supporting incident response documentation.

Location: Tokyo, Japan — Shibuya Headquarters

Salary: 6.5M–9.5M JPY per year, negotiable. The range includes a duty allowance covering approximately 20 hours of overtime per month.

Company

hirify.global operates an internal IT organization supporting approximately 350 full-time employees and maintains information security standards including ISO 27001, ISO 27017, and ISO 27018.

What you will do

  • Coordinate the day-to-day execution and continuous improvement of ISMS controls across departments.
  • Coordinate internal security audits, collect and review evidence, and support preparation for external audits.
  • Assign control-related tasks to owners, track progress, and follow up on completion.
  • Maintain ISMS documentation, including the Statement of Applicability and security policies.
  • Coordinate risk-assessment and incident-response documentation, security awareness training logistics, and process manuals.
  • Evaluate IT systems and workflows, analyze policies, and recommend efficiency and compliance improvements.

Requirements

  • Must currently reside in Japan.
  • At least 3 years of experience in information technology, compliance, IT audit, or project coordination.
  • Practical working knowledge of ISO/IEC 27001 or a similar framework such as SOC 2 or NIST.
  • Experience coordinating complex, long-term administrative tasks across multiple teams and stakeholders.
  • Proficiency with Google Docs/Sheets or Word/Excel and familiarity with cloud services and SaaS environments.
  • Business-level Japanese and English proficiency required.

Nice to have

  • CISA or ISO 27001 Lead Implementer certification.
  • Experience with GRC platforms such as Vanta, Drata, or Secureframe.
  • Experience documenting and supporting external compliance audits.
  • Project management experience.

Culture & Benefits

  • Flexible working hours with core time from 10:00 to 15:00; a typical workday is 8 hours with a 1-hour break.
  • Permanent employment with a 3-month probation period.
  • Annual performance-based salary review and an annual bonus worth 2 months of basic monthly salary.
  • Weekends, national holidays, and the year-end and New Year holiday period are days off.
  • Health, employment, industrial injury, and welfare pension insurance, plus transportation allowance of up to JPY 35,000 per month.
  • English and advanced language allowances, stock ownership plan, conference opportunities, and financial support for certifications and technical learning.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →