Enterprise AI Security Engineer - Mercari
Salary not provided
GCPAWSAzureGoPythonJavaScriptGitShell
English: Intermediate
MercariEnterprise AI Security Engineer
- Employment Status: Full-time
- Work Hours: Full Flextime (no core time)
- Office: Roppongi
Organization/Team Mission
Engineering Principles:
- Passion For The Product
- Grow Together
- Solve Through Mechanisms
- Collaborate Openly
See more about Engineering Culture and mission and values.
Work Responsibilities
As an Enterprise AI Security Engineer, you will:
- Build core controls to secure a dynamic and AI-centric work environment.
- Focus on securing internal AI agent platforms and solutions.
- Collaborate with AI Taskforce, engineering, and IT teams to design and deploy secure foundations.
- Implement zero-trust architecture to enhance security posture.
- Embrace a "security as code" philosophy—automate and optimize security solutions for a secure-by-default enterprise IT infrastructure.
Unique Challenges
Security Frameworks and Assessments
- Develop and implement security frameworks for enterprise IT solutions and AI agents.
- Conduct risk assessments and threat modeling for IT and AI systems.
- Design and implement technical security solutions and mitigation strategies for IT infrastructure and internal AI agent platforms.
Automation and Optimization
- Automate manual processes and operational tasks across security systems.
- Optimize configurations for IAM, Endpoint Security, AI agent platforms, and DLP systems.
Standards and Partnership
- Establish and maintain security standards and guidelines for AI solutions and infrastructure.
- Collaborate with engineering and IT teams to secure enterprise IT systems and protect against evolving threats.
Qualifications
Required Experience/Skills
- Bachelor’s degree or equivalent practical experience in core cybersecurity domains related to IT.
- Knowledge of computer security concepts (CIA triad, principle of least privilege, authentication vs. authorization, etc).
- Experience in programming with at least one language (e.g., Go, Python, JavaScript).
- Knowledge of software development tools: Git, CI/CD, IaC, shell scripting.
- Basic understanding of AI security principles (OWASP AI/LLM Top Ten).
- Proficiency using AI tools for productivity, dashboarding, and reporting.
- Experience with modern IAM systems (e.g., Okta, Microsoft Entra ID).
- Strong teamwork and collaboration skills.
Preferred Experience/Skills
- Experience as a security architect or IT architect.
- Deep understanding of AI agent mechanisms, vulnerabilities, and attack methodologies.
- Experience in securing AI agent frameworks.
- Experience managing Non-Human Identity (NHI) tools.
- Expertise in security of cloud platforms (GCP, AWS, Azure); knowledge of multi-cloud and cloud-agnostic systems.
- Experience building/administering IT security solutions (IAM, MDM, EDR, DLP, etc.).
- Familiarity with frameworks such as NIST AI RMF, Google's Secure AI Framework, OWASP Top 10 for Agentic Applications.
- Strong analytical, problem-solving, and critical thinking skills.
- Ability to effectively communicate security threats and mitigation strategies to various audiences.
Language
- Japanese: Bonus
- English: Independent (CEFR-B2)
CEFR information
Learn More
- Careers Site
- Mercan blog
- Social: X / LinkedIn
Related Articles:
- How Mercari’s AI Security Team is Securing AI Native
- Removing GitHub PATs from Google Cloud
- When Caching Hides the Truth
- How to Bypass GitHub’s Branch Protection
- Streamlining Security Incident Response
- An Introduction to Reverse Engineering for eBPF Bytecode
- Who Watches the Watchmen?
- Detection Engineering and SOAR
- Security | Mercari Engineering blog
- Security/Privacy | Mercan
Recruiting Process
- Application screening
- Skill assessment (HackerRank/GitHub for engineering positions)
- Interview(s)
- Reference check
- Offer
Learn more about the process here.
Equal Opportunity Hiring
We are committed to diversity and inclusion, eliminating discrimination based on age, gender, sexual orientation, race, religion, physical disability, and other factors.
Read our I&D statement for details.
Please read and acknowledge our Privacy Policy.