Start Date
Immediate
Expiry Date
08 Dec, 26
Salary
0.0
Posted On
09 Sep, 26
Experience
0 year(s) or above
Remote Job
Yes
Telecommute
Yes
Sponsor Visa
Yes
Skills
Industry
Cybersecurity & Data Protection
About the Job
*Our cybersecurity team is currently recruiting for the following four positions. Details for each role are provided below.
[Open Positions] • DFIR Lead • Digital Forensic Investigator • Insider Risk Analyst • CTI Lead (Establishing a Threat Intelligence Organization) ________________________________________________________________ [DFIR Lead] <Job Description> As a manager within the Cyber Defense & Response organization specializing in Digital Forensics and Incident Response (DFIR), you will lead a highly skilled technical team and continuously strengthen the company's overall cyber incident response capabilities. In incident response scenarios, you will act as a senior decision-maker, evaluating and directing escalated cases. Over the medium to long term, you will lead efforts to enhance the maturity of the entire incident response program—strengthening processes, organizational structures, and technologies. Fostering the technical skills and career growth of team members is also a key priority; a vital part of your mission is to cultivate highly specialized talent through internal training, knowledge sharing, and mentoring. The challenges involved are highly complex; you will be required to balance "technically correct responses" with "optimal business decisions" amidst situations characterized by incomplete information and intertwined risks and stakeholder interests. Therefore, in addition to deep technical expertise, the role demands the ability to view situations holistically, communication skills to build consensus among stakeholders, leadership that respects diversity, and a commitment to continuous learning regarding evolving threats and technologies. ● Key Responsibilities: Oversee and coordinate cyber incident response in collaboration with group life insurance companies, the Information Security Office (ISO), and global technology teams to ensure rapid responses that account for business impact. Make final judgments and decisions regarding critical incidents escalated from the Cyber Security Operations Center (CSOC), various departments, and external partners. Establish frameworks and drive initiatives to enhance maturity and integrate incident response capabilities into new business processes and technology implementations. Manage the full lifecycle of investigations, ensuring proper execution of documentation, reporting, and evidence management (chain of custody) in compliance with legal, regulatory, and audit requirements. Lead cross-functional risk management—covering cyber and operational risks—in collaboration with technology, legal, privacy, and public relations teams. Continuously implement process improvements and resilience-enhancing measures using post-incident analysis, KPIs, and threat intelligence. Leverage expertise in new technologies and threat trends to guide the direction of investigations and support/drive the technical growth of the team. Maintain and share knowledge regarding cybersecurity principles, frameworks, and industry trends to keep the organization's response capabilities at a leading-edge level. Scope of potential role changes: Duties as determined by the company (added in accordance with the April 2024 amendment to the Ordinance for Enforcement of the Employment Security Act).
<Requirements> ≪Must≫: 10+ years of practical experience in cyber incident response and digital forensics within large-scale enterprises or government agencies (including experience in complex, distributed IT infrastructure environments). 5+ years of experience as a technical team leader or manager, with a proven track record of leading team member development, strengthening organizational capabilities, and improving operational quality. Deep understanding of enterprise IT environments, including: Identity Infrastructure (Entra ID/Azure AD, Active Directory), Cloud (Azure, AWS), Business Platforms (Microsoft 365), and OS (Windows/Linux). Advanced skills in query and detection design for macOS, SIEM, EDR, and detection platforms (experience designing and managing detection logic and investigation queries using SPL, KQL, etc.); practical experience in scripting and automation using Python, PowerShell, Bash, etc. (for investigation, response, and operational improvement); extensive practical experience with major forensics tools such as X-Ways, EnCase, KAPE, The Sleuth Kit, and Volatility (commercial or open-source); business-level proficiency in Japanese and English (reading, writing, speaking), with the ability to clearly explain investigation results and risks to both technical staff and management; practical experience building detection, investigation, and response strategies based on attack methodologies using frameworks like MITRE ATT&CK and the Cyber Kill Chain. ≪Preferred Qualifications≫ Experience conducting integrated forensic analysis across multiple domains (host, log, memory, network, etc.); experience proactively leading complex, high-priority incident responses with a high degree of autonomy and responsibility; a track record of continuous learning and rapid adaptation to new technologies, threats, and organizational needs; strong analytical, problem-solving, and decision-making skills, with the ability to remain calm under pressure and collaborate with both technical and non-technical stakeholders. ________________________________【Digital Forensic Investigator】 <Job Description> As a highly specialized technical expert in Japan, the Digital Forensic Investigator is responsible for analysis and response regarding digital forensics and incident response. You will perform tasks such as investigating security incidents, supporting threat hunting operations, establishing and strengthening incident response frameworks, and handling other cybersecurity-related duties within a dynamic, global corporate environment. This role requires tackling extremely complex challenges by evaluating situations and data from multiple perspectives—including factors that cannot be quantified or judged against clear-cut criteria. Therefore, we welcome candidates who possess deep technical knowledge and practical experience, alongside excellent problem-solving, communication, and teamwork skills. Furthermore, we expect you to approach your work with an agile mindset, decision-making capabilities grounded in a business perspective, respect for diversity, and a drive for continuous learning.
● Key Responsibilities:
* Collaborate with cross-functional stakeholders—including the Group’s life insurance companies, the Information Security Office (ISO), and global technology teams—to support and coordinate global cyber incident response activities.
* Conduct complex, enterprise-scale investigations across hybrid environments encompassing both on-premises and cloud infrastructures (e.g., Active Directory/Entra ID, Microsoft 365, Azure, AWS).
* Drive efficient, data-driven investigation workflows by leveraging SIEM and detection platforms, utilizing advanced query techniques such as Splunk Search Processing Language (SPL) and Microsoft Kusto Query Language (KQL).
* Utilize EDR (Endpoint Detection & Response) technology to perform large-scale endpoint investigations, threat hunting, triage, and root cause analysis (RCA) across distributed environments.
* Support incident response by conducting comprehensive digital forensic analysis spanning multiple domains, including log analysis, host-based forensics, memory analysis, and network traffic analysis.
* Perform triage and analysis of malicious code to identify Indicators of Compromise (IOCs), behavioral patterns, and potential impacts, contributing to the formulation of containment and recovery strategies.
* Organize and share investigation findings in a clear, concise, and actionable manner; produce high-quality reports and provide verbal briefings to both technical staff and senior business leaders.
* XSOAR ...improve response efficiency, consistency, and scalability by leveraging tools to develop and maintain scripts, detection queries, and automated workflows; lead or actively contribute to strategic initiatives and continuous improvement activities aimed at strengthening enterprise-wide forensics, detection, and incident response capabilities; scope of job changes: duties as determined by the company (added in accordance with the April 2024 amendment to the Ordinance for Enforcement of the Employment Security Act).
<Requirements> ≪Must≫ - At least 5 years of practical experience in cyber incident response and digital forensics within large-scale, complex enterprise environments (including experience at global companies or in multi-region environments). - Business-level proficiency in Japanese and English (reading, writing, and speaking); ability to clearly explain complex technical details, investigation findings, and risk impacts to both technical teams and non-technical business stakeholders. - Practical experience using digital forensics tools (e.g., X-Ways, EnCase; commercial or open-source). - Basic to practical knowledge and experience in scripting and automation using languages such as Python, PowerShell, and Bash (experience in streamlining investigations, data analysis, and automating response actions). - Understanding of attacker behavior patterns and TTPs (Tactics, Techniques, and Procedures), and experience applying frameworks such as MITRE ATT&CK or the Lockheed Martin Cyber Kill Chain to actual detection, investigation, and incident response operations.
≪Want≫ - Certifications such as CCE, EnCE, GCFE, GCFA, GCIH, GREM, GNFA, or GPEN (demonstrating expertise in incident response, digital forensics, or threat analysis). - Bachelor’s degree in digital forensics, information security, computer science, information technology, or a related field (or equivalent practical experience in cybersecurity and incident response). ________________________________【Insider Risk [Analyst] <Job Description> We are seeking an Insider Risk Analyst—a specialist responsible for detecting, analyzing, and responding to insider risks (such as policy violations, data leaks, and internal misconduct). This role requires strong analytical skills, prudent judgment, and the communication skills necessary to collaborate across multiple departments. [Key Responsibilities] • Monitor and analyze user behavior to detect potential insider threats using advanced analytical methods and security tools • Monitor and analyze data security alerts generated by various security platforms and tools • Conduct initial triage (assessing severity and scope of impact) for security incidents • Escalate issues to appropriate teams or management as necessary • Coordinate with stakeholders—including Legal, Compliance, Privacy, and business units—to align on response strategies and consider measures to prevent recurrence • Create clear, concise records of incidents, response actions, and outcomes • Assist in improving and refining operational processes for incident detection and response • Stay up-to-date with the latest security trends, threats, and relevant technologies • Participate in post-incident reviews to share knowledge and identify areas for improvement • Scope of potential job changes: Duties as determined by the company (added in accordance with the April 2024 amendment to the Ordinance for Enforcement of the Employment Security Act)
<Application Requirements> <<Must>> • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience • 1–3 years of experience in security operations or a similar role • Knowledge of data security principles, incident response, and industry best practices • Experience using security tools such as SIEM, IDS/IPS, and Endpoint Protection Platforms • Excellent communication skills