20 дней назад
Corporate IT & Security Specialist (GRC)
6 500 000 - 9 500 000JPY
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Corporate IT & Security Specialist (GRC) (ISO 27001/27017/27018): Coordinating the maintenance of information security controls, audits, documentation, and evidence collection for an internal IT organization with an accent on GRC operations, risk management, and compliance processes. Focus on managing control ownership across teams, preparing for external audits, improving security procedures, and supporting incident response documentation.
Location: Tokyo, Japan — Shibuya Headquarters
Salary: 6.5M–9.5M JPY per year, negotiable. The range includes a duty allowance covering approximately 20 hours of overtime per month.
Company
operates an internal IT organization supporting approximately 350 full-time employees and maintains information security standards including ISO 27001, ISO 27017, and ISO 27018.
What you will do
- Coordinate the day-to-day execution and continuous improvement of ISMS controls across departments.
- Coordinate internal security audits, collect and review evidence, and support preparation for external audits.
- Assign control-related tasks to owners, track progress, and follow up on completion.
- Maintain ISMS documentation, including the Statement of Applicability and security policies.
- Coordinate risk-assessment and incident-response documentation, security awareness training logistics, and process manuals.
- Evaluate IT systems and workflows, analyze policies, and recommend efficiency and compliance improvements.
Requirements
- Must currently reside in Japan.
- At least 3 years of experience in information technology, compliance, IT audit, or project coordination.
- Practical working knowledge of ISO/IEC 27001 or a similar framework such as SOC 2 or NIST.
- Experience coordinating complex, long-term administrative tasks across multiple teams and stakeholders.
- Proficiency with Google Docs/Sheets or Word/Excel and familiarity with cloud services and SaaS environments.
- Business-level Japanese and English proficiency required.
Nice to have
- CISA or ISO 27001 Lead Implementer certification.
- Experience with GRC platforms such as Vanta, Drata, or Secureframe.
- Experience documenting and supporting external compliance audits.
- Project management experience.
Culture & Benefits
- Flexible working hours with core time from 10:00 to 15:00; a typical workday is 8 hours with a 1-hour break.
- Permanent employment with a 3-month probation period.
- Annual performance-based salary review and an annual bonus worth 2 months of basic monthly salary.
- Weekends, national holidays, and the year-end and New Year holiday period are days off.
- Health, employment, industrial injury, and welfare pension insurance, plus transportation allowance of up to JPY 35,000 per month.
- English and advanced language allowances, stock ownership plan, conference opportunities, and financial support for certifications and technical learning.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
13 дней назад
Senior Professional Services Engineer (Cybersecurity)
14 дней назад
Associate Director - Security Consulting (Cybersecurity)
12 дней назад
Information Security Analyst (Fintech)
CrowdStrike
12 дней назад
Regional Sales Engineer, Cloud Security
13 дней назад
Cloud Security Engineer (AWS)
110 000 - 150 000$
13 дней назад