4 hours ago
Tokyo, JapanSenior
Responsibilities
- Own Japan financial-services and payments compliance across JFSA supervisory expectations, APPI, and local banking and payments technology controls.
- Build and maintain policy-as-code, automated control validation, continuous evidence collection, and compliance monitoring integrated into engineering workflows.
- Operate and extend GRC platforms such as Vanta and integrate them with cloud, identity, logging, and engineering systems.
- Partner with architects and engineering leads to embed JFSA and APPI requirements into system designs and technical implementations.
- Design, implement, and validate controls for access, logging and monitoring, encryption, change management, vulnerability management, business continuity, disaster recovery, and secure SDLC.
- Operate the cybersecurity and compliance risk register and lead risk assessments for products, payment flows, vendors, and architectural changes.
- Coordinate with Legal and Data Privacy on APPI, personal-data security, and incident reporting.
- Manage relationships with auditors, assessors, and applicable JFSA supervisory contacts.
- Maintain policies, standards, procedures, and shared control libraries across Japan and US fintech operations.
- Champion risk-based governance focused on meaningful security and business outcomes.
Requirements
- Bachelor’s degree in computer science, information security, cybersecurity, risk management, or an engineering/STEM field, or equivalent practical experience.
- 8+ years of experience owning or materially operating a GRC, information-security compliance, or ISMS program in fintech, banking, payments, SaaS, or another regulated technology environment, with primary Japan exposure.
- Experience operating an ISMS and control library and supporting client security assurance, external audits, or regulatory evidence processes.
- Hands-on experience with JFSA supervisory expectations and Japanese banking and payments technology controls.
- Strong knowledge of information-security risk management, control assessment, risk treatment, and governance reporting.
- Experience with security incident-response governance and supplier or third-party security assurance.
- Working knowledge of APPI and ability to partner on personal-data security and incident support.
- Technical fluency with AWS, GCP, or Azure, identity, logging, and secure SDLC controls.
- Preferred: 10+ years of information-security compliance, GRC engineering, or technology audit experience in fintech or financial services with Japan focus.
- Preferred: experience with IAM, logging and monitoring, encryption, hardening, CI/CD or DevSecOps compliance checks, threat modeling, SAST/DAST, dependency scanning, secrets management, penetration testing, vulnerability remediation, and BC/DR evidence.
- Preferred: experience with enterprise trust centers, vendor questionnaires, client audits, contractual security schedules, shared control libraries, and RTO/RPO validation.
- Certifications such as CISSP, CISM, CISA, or CRISC are preferred.
- Based in Japan; English fluency required and Japanese proficiency preferred.
Benefits
- The position may require occasional travel.
- The company operates with a flat organizational structure and expects employees to contribute hands-on to the mission.
Tech Stack
Categories
About xAI
Understand the Universe. We are a team of AI technologists and business leaders on a mission to build AI systems that can help humanity understand the world better. https://x.ai/careers