Senior IT Security and Compliance Specialist

  • Tokyo
  • Remote OK - Anywhere in Japan
  • Full-time
  • September 30, 2026
Conditions
yen-icon
¥12M ~ ¥13M /yr
location-icon
Apply from Japan Only
visa-icon
No relocation to Japan
(No visa sponsorship from overseas)
Requirements
language-icon
Language Requirements
Japanese: Business Level
English: Business Level
career-icon
Minimum Experience
Senior or above

Role Description

Because of who our clients are, our security posture is examined continuously — by our parent group, by our enterprise clients' recurring security assessments, by our ISO 27001 certification body, and by internal risk review.
You will be responsible for that examination surface.
You are the person who reads a security requirement in Japanese, works out what it actually asks of us, finds the person inside the company who holds the answer, consults with them, and returns a defensible response on time. This is a translation role in both senses: Japanese ↔ English, and regulatory language ↔ engineering reality.
This is not a form-filling job. We use AI to handle the first draft and to search our own documentation, so the value you add is judgement, not typing. Enterprise security questions increasingly turn on real judgement calls about scope, applicability and interpretation. You will be expected to form a view and defend it, in Japanese, to sophisticated counterparties.
You will work alongside a Senior Security Engineer who is responsible for technical controls, remediation and incident response.

 

What you'll be responsible for

Parent group and regulatory liaison

  • Acting as our primary working contact for group-level cybersecurity governance, attending recurring syncs and periodic liaison meetings.
  • Interpreting and triaging incoming requirements — questionnaires, standards updates, control catalogues, policy briefings — most of which arrive in Japanese under short deadlines.
  • Translating each requirement into concrete internal action, identifying the accountable stakeholder, and driving it to a submitted answer.
  • Recurring group-level reporting and annual risk reporting cycles.

Client security assessments

  • End-to-end completion of client security checklists and questionnaires — annual, biannual and ad hoc — for our banking and fintech clients.
  • Managing the queue: intake, scoping, evidence gathering, internal review, submission and follow-up questions.
  • Coordinating client-driven security obligations including penetration testing, threat-led testing, vulnerability assessments and threat modelling.
  • Operating and continually improving our AI-assisted response workflow — drafting from curated source material and prior answers, then carefully reviewing and correcting every output before it is submitted. Keeping the underlying source material current so answer quality improves over time.

Risk management

  • Running the operational risk management process: assessment, treatment planning, approval routing and monitoring.
  • Determining impact and likelihood, identifying treatments, and tracking them to completion with risk owners.
  • Facilitating periodic risk register reviews.

ISMS and audit

  • Supporting ISO 27001 surveillance, re-certification and internal system audits: evidence preparation, control checklists, audit minutes and findings closure.
  • Maintaining core ISMS documentation including the Statement of Applicability, risk register, asset register and incident register.
  • Keeping information security policies current and internally consistent.

Third-party and software governance

  • Running the vendor evaluation and software approval processes, including a growing volume of AI tooling requests.
  • Partnering with Legal on data handling and privacy alignment, including "Privacy by Design" documentation.

 

Required Experience

  • 5+ years in GRC, information security compliance, IT audit or third-party risk, with meaningful time in or serving Japanese financial services.
  • Japanese: JLPT N1 or native level. You will read formal Japanese regulatory and banking documents and draft formal Japanese responses daily.
  • English: business level, TOEIC 800+ or demonstrated equivalent. You will write English summaries for executives and work in English-language frameworks daily. A test score is not required from native speakers or from candidates with an English-medium degree or sustained English-language work history.
  • Demonstrable experience being responsible for a client security assessment or vendor due-diligence process, end to end.
  • Working command of ISO 27001, plus at least one major control framework (for example NIST CSF or NIST SP 800-53).
  • A track record of extracting information from busy engineers and executives who did not ask to be interrupted.
  • Comfort using Jira and Confluence as a system of record.
  • Legally able to work in Japan.

 

Preferred Experience

  • Comfort using AI-assisted tools (LLM-based document search and drafting) in a compliance workflow, with the judgement to review and correct their output rather than trust it blindly.
  • Experience with a Japanese megabank's vendor security or group governance program.
  • Familiarity with FISC guidelines or other Japanese banking security standards.
  • Certification: CISA, CRISC, CISM, CISSP, ISO 27001 Lead Auditor, or 情報処理安全確保支援士 (RISS).
  • Experience in a startup or small team.
  • Familiarity with AWS.

Moneytree is a fin-tech start-up founded by three foreign entrepreneurs in Tokyo.

Their Moneytree Link product provides a "utility layer for connecting financial services" that serves banks and other fin-tech companies, but they also have a popular consumer app that helps people manage their finances.

They're an international company with an English-first work environment and a high technical skill level for engineers. Truly a really great place to work!

View Moneytree's company page

↑ Back to top ↑

Senior IT Security and Compliance Specialist at Moneytree
APPLY NOW  ➜🇯🇵 Residents Only