【オープン】Senior Cloud Security Engineer

Salary: 900 - 1404 百万円

AWSKubernetes
English & Japanese
English: FluentJapanese: Fluent

Minimum year of experience: 2

ExaWizards

【オープン】Senior Cloud Security Engineer

職務内容

Mission / 役割

As a Senior Application Security Engineer at ExaWizards, your mission will be to ensure secure development practices being followed and support active shift-left paradigm when it comes to creation of software applications of all types (Web, Mobile, etc.). Internal Penetration testing procedures and support for automated finding of vulnerabilities would be the key tools to help proactively catch and fix the issues. You will play a critical role in strengthening our overall security posture, guiding and mentoring team members, and ensuring our security frameworks align with industry standards and regulatory requirements. Preferable expertise in both English and Japanese will allow you to bridge security efforts across teams and stakeholders, driving company-wide security initiatives effectively.

ExaWizardsのシニア アプリケーション セキュリティ エンジニアとしてのミッションは、安全な開発プラクティスの実践を徹底し、あらゆる種類のソフトウェアアプリケーション(Web、モバイルなど)の開発において「シフトレフト(開発のより早い段階でセキュリティ対策を組み込むアプローチ)」を積極的に支援・推進することです。 プロアクティブ(先回り)に課題を発見・解決するための強力な手段として、社内ペネトレーションテスト(侵入テスト)の実施や、脆弱性の自動検出ツールの導入・運用を主導していただきます。 当社のセキュリティ体制全体の強化において極めて重要な役割を担い、チームメンバーの指導・メンタリングを行い、セキュリティフレームワークが業界基準や規制要件に確実に準拠するように導いていただきます。英語と日本語の双方における優れた専門性を活かし、各チームやステークホルダー間でセキュリティの取り組みの架け橋となり、会社全体のセキュリティイニシアチブを強力に牽引していただくことを期待しています。

Expected Day-to-Day Tasks / 日々の業務内容

  • Penetration testing:

    • Performing internal penetration tests utilizing AI capabilities and dedicated tools for evaluation of findings and PoCs creation.
  • Vulnerability management:

    • Supporting triage and analysis for detected emerging threats, monitoring SLAs for product teams, and visualizing remediation progress.
  • Secure development standards:

    • Designing and executing modern operational processes and guardrails.
  • Threat modeling & design reviews:

    • Reviewing high-priority/critical projects.
  • Incident response:

    • Providing technical support and expertise during investigations (including root-cause finding, malware analysis, etc.).
  • Innovation improvements:

    • Working on frontier AI technology to improve existing security posture, ability to bring in own ideas and projects.
  • ペネトレーションテスト:

    • AI技術や専用ツールを活用した社内ペネトレーションテストの実施
    • 検出された脆弱性の評価、およびPoC(概念実証コード・環境)の作成
  • 脆弱性管理:

    • 新たに検知された脅威(エマージングスレット)のトリアージと分析の支援
    • プロダクトチームに対するSLAのモニタリング
    • 脆弱性の修正状況の可視化
  • セキュア開発標準:

    • モダンな運用プロセスおよびガードレール(開発者が安全に開発するための仕組み)の設計と実行
  • 脅威モデリング・設計レビュー:

    • 重要案件・極めて重要なプロジェクトに対するレビューの実施
  • インシデント対応:

    • インシデント調査時における技術支援および専門知識の提供(根本原因の究明、マルウェア解析などを含む)
  • イノベーションの推進:

    • 最先端AI技術を活用した既存のセキュリティ体制の改善
    • 自身のアイデアやプロジェクトを自ら提案・推進する取り組み

Tech Stack / 技術スタック

  • Cloud: AWS (Primary), Azure, GCP
  • Orchestration: Kubernetes, ECS
  • Security Tools: Standard Cloud Provider Tools, SonarQube, BurpSuite, Wiz, Datadog SIEM, and others.
  • Infrastructure as Code: Terraform

Key Attractions of This Position / 本ポジションの魅力的なポイント

  • Work with a multi-cloud environment hosting an extremely diverse variety of applications and architectures.
  • Team of passionate security professionals with a wide range of backgrounds and areas of expertise.
  • Drive company-wide security initiatives, contributing to the development of a security-first mindset within the company.
  • Solve real-world security challenges in a fast-paced, dynamic tech environment.
  • 極めて多様なアプリケーションやアーキテクチャをホストする、マルチクラウド環境での業務
  • 幅広い経歴と専門分野を持つ、情熱に溢れたセキュリティプロフェッショナルたちが集うチーム
  • 会社全体のセキュリティイニシアチブ推進、「セキュリティ・ファースト」マインドセットの醸成
  • スピード感と変化の激しい環境での、現実世界のセキュリティ課題解決

応募資格(必須)

  • 2+ years of experience in penetration testing/red teaming

  • Well-versed in application security, including activities such as white box testing/source code review

  • Deep understanding of systems' weaknesses and vulnerability logic, knowledge of PoC creation and detailed reporting

  • Experience with AWS cloud, SAST, DAST, SCA tools, understanding of vulnerability management approaches and practical skills in it

  • Ideally has some experience (or at least interest) in digital forensics and analysis

  • ペネトレーションテスト(侵入テスト)またはレッドチームでの2年以上の実務経験

  • ホワイトボックステストやソースコードレビューなど、アプリケーションセキュリティに関する深い知見

  • システムの脆弱性やそのロジックに対する深い理解、およびPoC(概念実証)の作成や詳細なレポート作成の知識

  • AWSクラウド、SAST、DAST、SCAツールの利用経験、および脆弱性管理(Vulnerability Management)へのアプローチに対する理解と実践的なスキル

  • デジタルフォレンジックおよび解析の実務経験(または、少なくとも同分野への強い興味・関心)


応募資格(歓迎)

  • Security certifications such as AWS Certified Security - Specialty, CEH, OSCP, etc

  • Previous experience working in a company with a focus on AI-powered product

  • Knowledge of zero-trust architectures and cloud-native security solutions

  • Good understanding of Kubernetes and/or container orchestration

  • Hands-on experience with security automation and Infrastructure as Code

  • Strong communication skills, experience mentoring junior engineers

  • A firm grasp on English and Japanese (Business level or higher for both, or deep interest to learn and improve)

  • セキュリティ関連の資格(AWS Certified Security - Specialty、CEH、OSCPなど)

  • AI駆動型プロダクトに注力している企業での実務経験

  • ゼロトラストアーキテクチャおよびクラウドネイティブなセキュリティソリューションに関する知識

  • Kubernetesおよびコンテナオーケストレーションに関する優れた理解

  • セキュリティの自動化、およびIaC(Infrastructure as Code)の実務経験

  • 高いコミュニケーションスキル、およびジュニアエンジニアのメンタリング(指導・育成)経験

  • 英語および日本語の確かな語学力(双方ビジネスレベル以上、または今後学習し向上させる強い意欲があること)


求める人物像

  • Proactive and solutions-oriented, with a strong sense of ownership

  • Passionate about security and continuous self-improvement

  • Excellent communicator, able to work effectively across diverse teams

  • Adaptable to new challenges in a rapidly evolving technical landscape

  • 主体性(オーナーシップ)を持ち、プロアクティブかつソリューション指向で行動できる方

  • セキュリティに対して情熱があり、常に自己研鑽を続けられる方

  • 優れたコミュニケーション能力を持ち、多様なチームと効果的に協働できる方

  • 急速に進化する技術環境において、新たな挑戦に柔軟に適応できる方


賃金

  • 年収 900万円 〜 1404万円
    • 月収:年収の12分割分を支給
      • 月収下限75万円(基本給554,910円、みなし残業代45時間分として195,090円)
      • 月収上限117万円(基本給865,660円、みなし残業代45時間分として304,340円)
      • 45時間を超える時間外労働分の割増賃金は追加で支給
    • 経験・能力、希望を考慮の上、当社規定により決定
    • 業務の内容に応じて、フレックス/裁量労働制または管理監督者としての勤務形態を適応

募集要項

  • 勤務時間: 標準労働時間 9:00-18:00(休憩1時間含む)
  • 勤務形態: 業務の内容に応じて、フレックス/裁量労働制または管理監督者としての勤務形態を適用
    • 2026年時点では原則週3出社を基本ルール(特定の部署、職種で例外あり)
  • 昇給・賞与:
    • 昇給:年2回(4月・10月)※ 規定に基づく
    • 賞与:年2回(5月・11月) ※会社業績・個人業績による
  • 諸手当: 通勤交通費(支給条件あり)
  • 休日・休暇: 完全週休二日(毎週土日曜日)、祝日、年末年始休暇(会社指定による)
  • 福利厚生:
    • 雇用保険
    • 健康保険
    • 厚生年金
    • 労災保険
    • 従業員持株会(加入は任意)
    • 確定拠出年金(加入は任意)

社内のAI利活用状況

  • 自社サービス「exaBase 生成AI」を自由に利用可能
  • コーディングエージェント「Claude Code」利用可(エンジニア職種全員、他職種は希望に応じて)
  • その他のAIツールも社内承認の上利用可能