xAI

Sr. Security Engineer - GRC APAC Fintech & Financial Services

xAI
Apply
4 hours ago
Tokyo, JapanSenior

Responsibilities

  • Own Japan financial-services and payments compliance across JFSA supervisory expectations, APPI, and local banking and payments technology controls.
  • Build and maintain policy-as-code, automated control validation, continuous evidence collection, and compliance monitoring integrated into engineering workflows.
  • Operate and extend GRC platforms such as Vanta and integrate them with cloud, identity, logging, and engineering systems.
  • Partner with architects and engineering leads to embed JFSA and APPI requirements into system designs and technical implementations.
  • Design, implement, and validate controls for access, logging and monitoring, encryption, change management, vulnerability management, business continuity, disaster recovery, and secure SDLC.
  • Operate the cybersecurity and compliance risk register and lead risk assessments for products, payment flows, vendors, and architectural changes.
  • Coordinate with Legal and Data Privacy on APPI, personal-data security, and incident reporting.
  • Manage relationships with auditors, assessors, and applicable JFSA supervisory contacts.
  • Maintain policies, standards, procedures, and shared control libraries across Japan and US fintech operations.
  • Champion risk-based governance focused on meaningful security and business outcomes.

Requirements

  • Bachelor’s degree in computer science, information security, cybersecurity, risk management, or an engineering/STEM field, or equivalent practical experience.
  • 8+ years of experience owning or materially operating a GRC, information-security compliance, or ISMS program in fintech, banking, payments, SaaS, or another regulated technology environment, with primary Japan exposure.
  • Experience operating an ISMS and control library and supporting client security assurance, external audits, or regulatory evidence processes.
  • Hands-on experience with JFSA supervisory expectations and Japanese banking and payments technology controls.
  • Strong knowledge of information-security risk management, control assessment, risk treatment, and governance reporting.
  • Experience with security incident-response governance and supplier or third-party security assurance.
  • Working knowledge of APPI and ability to partner on personal-data security and incident support.
  • Technical fluency with AWS, GCP, or Azure, identity, logging, and secure SDLC controls.
  • Preferred: 10+ years of information-security compliance, GRC engineering, or technology audit experience in fintech or financial services with Japan focus.
  • Preferred: experience with IAM, logging and monitoring, encryption, hardening, CI/CD or DevSecOps compliance checks, threat modeling, SAST/DAST, dependency scanning, secrets management, penetration testing, vulnerability remediation, and BC/DR evidence.
  • Preferred: experience with enterprise trust centers, vendor questionnaires, client audits, contractual security schedules, shared control libraries, and RTO/RPO validation.
  • Certifications such as CISSP, CISM, CISA, or CRISC are preferred.
  • Based in Japan; English fluency required and Japanese proficiency preferred.

Benefits

  • The position may require occasional travel.
  • The company operates with a flat organizational structure and expects employees to contribute hands-on to the mission.
xAI

About xAI

1,001-5,000 employees

Understand the Universe. We are a team of AI technologists and business leaders on a mission to build AI systems that can help humanity understand the world better. https://x.ai/careers

Contact me