company logo

Mercari

Enterprise Security Engineer

コヌポレヌトセキュリティ゚ンゞニア

Tags: Full-time, 4~5 YOE, Business Japanese

Minato City, Tokyo, Japan・Fetched 30+ days ago

Job Description

Employment Type: Full-time
Team: Information Technology

JD in English follows. 和文の埌に英文JDをご芧いただけたす。


Enterprise Security Engineer(コヌポレヌトセキュリティ゚ンゞニア) – Mercari

  • 雇甚圢態正瀟員
  • 働き方フレックスタむム制コアタむムなし・フレキシブルタむムなし 
  • 勀務地六本朚
    詳现はキャリアサむトの募集芁項よりご確認ください
    https://careers.mercari.com/recruitment-selection/#section3  

メルカリグルヌプに぀いお
あらゆる䟡倀を埪環させ、あらゆる人の可胜性を広げる

「地球資源が限られおいるなか、より豊かな瀟䌚を぀くるために䜕ができるか」。2013幎、創業者の山田進倪郎が䞖界䞀呚の旅で抱いた課題意識から、フリマアプリ「メルカリ」は生たれたした。私たちは、物理的なモノやお金に限らずあらゆる䟡倀を埪環させるこずで、誰もがやりたいこずを実珟し、人や瀟䌚に貢献するための遞択肢を増やすこずができるず信じおいたす。

テクノロゞヌの力で䞖界䞭の人々を぀なぎ、あらゆる人の可胜性が発揮される䞖界を実珟しおいきたす。メルカリグルヌプの目指すべき方針に぀いおは Mercari Culture Doc をご芧ください。

組織・チヌムのミッション

  •  Mercari Engineering Principles
    Mercari Engineering Principles は、メルカリの゚ンゞニアリング組織における信念や行動の基盀ずなる共通認識を明文化したもので、メルカリのメンバヌ党員が共有するMission、Value、Cultureを゚ンゞニアリングの芖点から補完するものずなりたす。これらのPrinciplesは、私たちが長期的に実珟しようずする理想的な姿を定矩するこずで、最終的にメルカリのミッションを達成するために掻甚しおいきたす。
  • Passion For The Product
  • Grow Together
  • Solve Through Mechanisms
  • Collaborate Openly

詳现に぀いおぱンゞニアリングカルチャヌ  をご芧ください
https://engineering.mercari.com/culture/  


コヌポレヌトセキュリティ゚ンゞニアずしお、コヌポレヌト゚ンゞニアチヌムやプロダクト開発チヌムず綿密に連携し、メルカリグルヌプをリヌドしおいただきたす。具䜓的には、コヌポレヌトIT環境に察するリスク評䟡、セキュリティ察策の芁件定矩などの䞊流工皋から、゜リュヌション導入、運甚などの䞋流工皋たで倚岐にわたりたす。幅広い業務に携わりながら、IT環境党䜓のセキュリティ匷化を掚進し、れロトラストアヌキテクチャヌの実珟に貢献しおいただきたす。
メルカリのミッション・バリュヌに぀いおの詳现はこちらをご芧ください
https://careers.mercari.com/culture/

業務内容

  • IT環境に関するリスク評䟡ずセキュリティ戊略の策定
    • 脅嚁モデリングを通しおIT環境のセキュリティに関するリスク評䟡
    • IT環境に必芁なセキュリティ察策の芁件定矩
    • セキュリティに関するポリシヌずの敎合性調敎
  • IT環境のセキュリティ察策デザむン
  • 導入゜リュヌションの遞定ず比范怜蚎
  • 導入゜リュヌションの運甚蚭蚈
  • 運甚䞊の課題敎理ず解決策の怜蚎
  • 経営局ぞの提案ず合意圢成
  • セキュリティ゜リュヌションの実装および運甚
  • セキュリティ察策の運甚蚭定や問い合わせ察応をコヌド化し、できるだけ自動化を行う
  • セキュリティベンダずの連携
  • セキュリティ察策のモニタリングや評䟡
  • 䌁業資産に関わるむンシデント察応力の向䞊
  • セキュリティ察策管理の培底
  • 脅嚁怜知゚ンゞニアリングチヌムによる察応プレむブック䜜成のサポヌト
  • 緊急察応チヌムず連携し、瀟内むンフラ関連ドメむンのプロゞェクトメンバヌずしお業務遂

ナニヌクなチャレンゞ

  • クラりドネむティブ環境においお、前䟋のない瀟員の自由な働き方を支揎するこずができる
  • 自由な働き方ぞの積極的なサポヌトを通じお、最先端のコヌポレヌトITセキュリティを実珟するこずができる
  • セキュリティ芁件定矩などの䞊流工皋から䌚瀟のIT環境をデザむンし、実際の゜リュヌション導入、運甚などの䞋流工皋たで、広い業務に裁量暩を持っお取り組める
  • グロヌバルなスケヌルか぀急成長する組織や環境のなかで、ダむナミズムに富んだセキュリティ実装にチャレンゞできる


応募芁件

  • 求める経隓・スキル
    • ITに関連するサむバヌセキュリティの専門領域における孊士号たたは同等の実務経隓。
    • クラりド環境におけるITシステムのリスク評䟡、セキュリティ芁件策定、蚭蚈の経隓
    • ゚ンドポむントセキュリティの怜蚎,構築,運営及び改善の経隓
    • ID管理、認蚌システムの導入、運甚経隓
    • セキュリティむンシデント察応経隓(圱響分析、調査、察応、再発防止策の怜蚎ず実行支揎)
    • ITむンフラに関する深い知識TCP/IP, ネットワヌク, サヌバ, 認蚌、ディレクトリサヌビス,゚ンドポむントマネヌゞメント
    • 倚様性のある環境で他者ずの匷いチヌムワヌクを発揮できる方
    • セキュリティ䞊の脅嚁やリスクを効果的に提瀺、䌝達し、緩和策や戊略を違和感なく萜ずし蟌む胜力
    • プロゞェクトマネゞメント経隓
    • メルカリのミッションずバリュヌに共感しおいただける方
  • 歓迎する経隓・スキル
    • セキュリティアヌキテクト/ITアヌキテクトの業務経隓
    • クラりドネむティブやれロトラストベヌスのコヌポレヌトITのシステムアヌキテクチャの蚭蚈、セキュリティ補品評䟡やPoC、構築、運甚の経隓
    • クラりドベヌス環境、Infrastructure as Code、およびデプロむメントパむプラむンに関する知識ず実務経隓
    • Go、Python、Javascriptなどの開発蚀語の知識、およびリビゞョン管理ツヌルGithubなどによるコヌドの管理経隓
    • 情報システムやアプリケヌションの開発および運甚管理やシステムセキュリティに関する党般的な知識
    • セキュリティ機噚や監芖基盀CASB、EDR、DLPなどの構築・運甚経隓
    • チヌムマネゞメントの経隓
    • 情報セキュリティ関連の資栌保有(CISSP, CEH, SANS GIAC等)
    • システムや情報セキュリティ関する監査の実斜経隓
    • 金融事業における業務経隓・知識
    • PCI DSS、GDPR等のコンプラむアンス芁件の理解
  • 語孊力
    • 英語日垞䌚話レベル必須,ビゞネスレベル歓迎CEFR-B2
    • 日本語流暢レベル必須CEFR-C1
      ※CEFRの詳现に぀いおは、こちらをご芧ください
      https://careers.mercari.com/language/#page-1

 

メルカリグルヌプに぀いお知る 


遞考に぀いお

メルカリグルヌプではメルカリグルヌプおよび各カンパニヌのミッションずバリュヌぞの共感・䜓珟を倧切にしおいたす。メンバヌが発揮する䟡倀の総量が最倧化されるような組織づくりを掚進するために、候補者のみなさんの経隓やスキルをより正しく理解したいず考えおいたす。

遞考の流れ

  • 曞類遞考
  • 技術課題゚ンゞニアポゞションではHackerRankたたはGithubでの技術課題を、゚ンゞニア以倖のポゞションでは採甚ポゞションによりたす面接タむミングず前埌するこずがありたす
  • 面接ポゞションにより、耇数回の面接をお願いしたす
  • リファレンスオンラむン回答圢匏のもので、最終遞考の前埌でお願いしたす
  • オファヌ最終遞考ずリファレンスの内容より決定されたす

 ※詳しくは  こちらのペヌゞをご芧ください
 https://careers.mercari.com/recruitment-selection/#section2

遞考における機䌚の平等  

メルカリでは、バックグラりンドによっお個人の可胜性が決め぀けられるこずなく、自由に䟡倀を生みだす機䌚を手にできる瀟䌚の実珟を目指しおいたす。そしおメルカリがミッションを実珟するために「Inclusion & Diversity」ずいう考え方は䞍可欠な存圚だず考えおいたす。
採甚掻動においおも、メルカリのミッション・バリュヌに共感する、様々なバックグラりンドの方にゞョむンしおいただけるよう、幎霢、性別、性的指向、人皮、宗教、身䜓胜力、その他蚘号に基づくあらゆる差別をなくすこずを玄束したす。
詳しくは、I&D statementをご芧ください。
https://about.mercari.com/inclusion-diversity/


なお、ご応募の際にはプラむバシヌポリシヌをご確認ください。
https://careers.mercari.com/privacy/


Enterprise Security Engineer(コヌポレヌトセキュリティ゚ンゞニア) – Mercari

About Mercari

Circulate all forms of value to unleash the potential in all people

"What can I do to help society thrive with the finite resources we have?" The Mercari marketplace app was born in 2013 out of this thought by our founder Shintaro Yamada as he traveled the world. We believe that by circulating all forms of value, not just physical things and money, we can create opportunities for anyone to realize their dreams and contribute to society and the people around them. Mercari aims to use technology to connect people all over the world and create a world where anyone can unleash their potential. For more information about Mercari Group’s mission, see Mercari’s Culture Doc.
https://careers.mercari.com/en/culture/

Organization/Team Mission

Mercari Engineering Principles  

Mercari Engineering Principles are a shared understanding that serves as the foundation of engineering beliefs and behavior at Mercari. The Engineering Principles are designed to complement the organizational identity (Mercari’s mission, values, and culture) from an engineering viewpoint. 

These principles ultimately help us achieve Mercari’s mission by defining the ideal state we seek to realize in the long term. 

  • Passion For The Product
  • Grow Together
  • Solve Through Mechanisms
  • Collaborate Openly

For more details, please see the following link:

As an Enterprise Security Engineer, you will work closely with the Corporate Engineering team and production teams to lead security initiatives within the Mercari Group. This position handles a wide range of tasks, from upstream processes like assessing risks facing the corporate IT environment and defining requirements for security measures, to implementing solutions and other downstream processes. You will also work to strengthen security for the IT environment as a whole and contribute to implementing zero-trust architecture.

  • Secure our infrastructure, corporate environment and services
  • Identify risks and resolves issues through scalable solutions
  • Maintain and update a secure enterprise platform vision and roadmap

See here for more information about our mission and values.
https://careers.mercari.com/en/culture/

Work Responsibilities 

  • Formulating risk assessments and security strategies relating to the IT environment
    • Assessing risks relating to the security of the IT environment through threat modeling and regular reviews.
    • Defining requirements for security measures necessary for the IT environment
    • Ensuring consistency with security policies
    • Maintenance and ownership of the corporate IT security roadmap
    • Document and be able to report about the state of maturity of our infra against a defined standard.
  • Designing security measures for the IT environment
    • Selecting and comparing solutions to be implemented
    • Planning operations for solutions to be implemented
    • Identifying problems in operations and considering solutions
    • Proposing solutions and building consensus with senior management
  • Implementing and running security solutions
    • Running security measures (setting configurations, answering questions, etc.) as code and through automation.
    • Liaising with the IT team and security vendors
    • Monitoring and evaluating security measures
    • Coordinate with the IT team for the review and release of security configurations and countermeasures.
  • Improve incident handling capabilities related to Enterprise assets.
    • Master the management of our security countermeasures
    • Support the Threat Detection Engineering team in creating response playbooks
    • Act as subject matter expert for enterprise infrastructure related domains, in collaboration with the emergency response team.


Unique Challenges 

  • Support the freedom of employees to choose whatever work style is best for them through a cloud-native environment
  • Provide active support for diverse work styles within and outside of Japan and the US.
  • Work on a wide range of tasks, from upstream processes like defining security requirements to designing the company’s IT environment and actually implementing solutions
  • Take on the challenge of implementing dynamic security in a rapidly-growing global organization and environment


Qualifications 

  • Required Experience/Skills
    • Bachelor's degree or equivalent practical experience in core cybersecurity domains related to IT.
    • Experience assessing risks and formulating/designing security requirements for cloud based IT systems
    • Experience analyzing, building, administrating, and improving endpoint security
    • Experience implementing and operating identity and role management, as well as authentication systems
    • Experience handling security incidents (impact analysis, investigation, response, consideration of and support for implementing preventative measures)
    • Extensive knowledge of IT infrastructure (TCP/IP, networks, servers, authentication, directory services, endpoint management)
    • Strong teamwork skills and the ability to collaborate with others in a diverse environment.
    • Ability to effectively present and communicate security threats and risks to any audience and impress upon them the mitigation techniques and strategies
    • Experience managing projects
    • Shared belief in Mercari’s mission and values
  • Preferred Experience/Skills
    • Experience working as a security architect or IT architect
    • Experience leading or managing teams
    • Certifications related to information security (CISSP, CEH, SANS GIAC, etc.)
    • Understanding of compliance requirements such as PCI DSS and GDPR
    • Knowledge of and experience working in a cloud-based environment, infrastructure as code, as well as deployment pipelines
    • Knowledge of development languages like Go, Python or Javascript and management of code through revision control tools (like Github)
    • Knowledge of and experience working in financial or crypto asset businesses
    • General knowledge of information system/application development/management and system security
    • Experience carrying out audits regarding systems and/or information security
    • Experience building and operating security devices and monitoring infrastructure (CASB, EDR, DLP, etc.)
  • Language 

Learn More About Mercari Group

Recruiting at Mercari

At Mercari Group, we value empathizing with and embodying the mission and values ​​of the Group and each company. To promote the creation of an organization that maximizes the total amount of value exhibited by all members, we would like to understand the experience and skills of each candidate as accurately as possible.

Recruiting cycle at Mercari Group

  • Application screening
  • Skill assessment: For engineering positions, you will be asked to complete a skill assessment on HackerRank or GitHub. For non-engineering positions, you may be asked to complete an assessment depending on the position. (The timing of the assessment may coincide with the interview process.)
  • Interview: The number of interviews may vary depending on the position.
  • Reference check: We will ask for online references around the timing of the final interview.
  • Offer: Offers will be determined carefully in consideration of the final interview and the reference check.

 Learn more about our recruiting process here.

 https://careers.mercari.com/en/recruitment-selection/


Equal Opportunity Hiring 

Here at Mercari, we work to realize a world in which no one’s potential is limited by their background and everyone has the opportunity to freely create value. We also firmly believe that a mindset of Inclusion & Diversity is essential for us to achieve our mission.

This, of course, extends to our hiring practices as well. Mercari is committed to eliminating discrimination based on age, gender, sexual orientation, race, religion, physical disability, and other such factors so that anyone who shares our mission and values can join us, regardless of their background.
For more details, please read our I&D statement.
https://about.mercari.com/en/inclusion-diversity/ 

Please read and acknowledge our Privacy Policy prior to submitting your application.
https://careers.mercari.com/en/privacy/