マネーツリーは、「金融分野のデジタル・トランスフォーメーションを加速する包括的ソリューションを提供することにより、日本全体に永続的なポジティブな変化をもたらす」というミッションを掲げ、データとテクノロジーによって人々がよりよい金融サービスを活用できる社会を目指しています。
2025年8月には、三菱UFJ銀行(MUFG)グループの参画を受け、メガバンクの信頼性とフィンテックスタートアップの機動力を融合させた新たな成長フェーズに入り、国内唯一無二のポジションを確立。
金融データの所有者が自ら共有先を選択・管理できる「オープンバンキング」の先駆者として、私たちは今、第二の創業期を迎えています。
Role Description
Because of who our clients are, our security posture is examined continuously — by our parent group, by our enterprise clients' recurring security assessments, by our ISO 27001 certification body, and by internal risk review.
You will be responsible for that examination surface.
You are the person who reads a security requirement in Japanese, works out what it actually asks of us, finds the person inside the company who holds the answer, consults with them, and returns a defensible response on time. This is a translation role in both senses: Japanese ↔ English, and regulatory language ↔ engineering reality.
This is not a form-filling job. We use AI to handle the first draft and to search our own documentation, so the value you add is judgement, not typing. Enterprise security questions increasingly turn on real judgement calls about scope, applicability and interpretation. You will be expected to form a view and defend it, in Japanese, to sophisticated counterparties.
You will work alongside a Senior Security Engineer who is responsible for technical controls, remediation and incident response.
What you'll be responsible for
Parent group and regulatory liaison
- Acting as our primary working contact for group-level cybersecurity governance, attending recurring syncs and periodic liaison meetings.
- Interpreting and triaging incoming requirements — questionnaires, standards updates, control
catalogues, policy briefings — most of which arrive in Japanese under short deadlines. - Translating each requirement into concrete internal action, identifying the accountable stakeholder, and driving it to a submitted answer.
- Recurring group-level reporting and annual risk reporting cycles.
Client security assessments
- End-to-end completion of client security checklists and questionnaires — annual, biannual and ad hoc — for our banking and fintech clients.
- Managing the queue: intake, scoping, evidence gathering, internal review, submission and follow-up questions.
- Coordinating client-driven security obligations including penetration testing, threat-led testing, vulnerability assessments and threat modelling.
- Operating and continually improving our AI-assisted response workflow — drafting from curated source material and prior answers, then carefully reviewing and correcting every output before it is submitted. Keeping the underlying source material current so answer quality improves over time.
Risk management
- Running the operational risk management process: assessment, treatment planning, approval routing and monitoring.
- Determining impact and likelihood, identifying treatments, and tracking them to completion with risk owners.
- Facilitating periodic risk register reviews.
ISMS and audit
- Supporting ISO 27001 surveillance, re-certification and internal system audits: evidence preparation, control checklists, audit minutes and findings closure.
- Maintaining core ISMS documentation including the Statement of Applicability, risk register, asset register and incident register.
- Keeping information security policies current and internally consistent.
Third-party and software governance
- Running the vendor evaluation and software approval processes, including a growing volume of AI tooling requests.
- Partnering with Legal on data handling and privacy alignment, including "Privacy by Design" documentation.
Required Experience
- 5+ years in GRC, information security compliance, IT audit or third-party risk, with meaningful time in or serving Japanese financial services.
- Japanese: JLPT N1 or native level. You will read formal Japanese regulatory and banking documents and draft formal Japanese responses daily.
- English: business level, TOEIC 800+ or demonstrated equivalent. You will write English summaries for executives and work in English-language frameworks daily. A test score is not required from native speakers or from candidates with an English-medium degree or sustained English-language work history.
- Demonstrable experience being responsible for a client security assessment or vendor due-diligence process, end to end.
- Working command of ISO 27001, plus at least one major control framework (for example NIST CSF or NIST SP 800-53).
- A track record of extracting information from busy engineers and executives who did not ask to be interrupted.
- Comfort using Jira and Confluence as a system of record.
- Legally able to work in Japan.
Preferred Experience
- Comfort using AI-assisted tools (LLM-based document search and drafting) in a compliance workflow, with the judgement to review and correct their output rather than trust it blindly.
- Experience with a Japanese megabank's vendor security or group governance program.
- Familiarity with FISC guidelines or other Japanese banking security standards.
- Certification: CISA, CRISC, CISM, CISSP, ISO 27001 Lead Auditor, or 情報処理安全確保支援士 (RISS).
- Experience in a startup or small team.
- Familiarity with AWS.
| 職種 / 募集ポジション | Senior IT Security and Compliance Specialist / シニアITセキュリティ・コンプライアンス専門職 |
|---|---|
| 雇用形態 | 正社員 |
| 給与 |
|
| 勤務地 | |
| 勤務時間 | 10時〜19時 休憩1時間 |
| 休日 | 土、日、祝日 |
| 福利厚生 | ・Work remotely in Japan・20 annual PTO ・10 annual sick leave・Referral bonus 250,000JPY per hire・Remote & Communication allowance (13,000 JPY/month)・Work from overseas for short periods・Learning support |
| 加入保険 | 健康保険、厚生年金、雇用保険、労災保険 |
| 会社名 | マネーツリー株式会社 |
|---|---|
| 所在地 | 〒106-0031 東京都港区西麻布3-13-3 カスタリア広尾2階 |
| 代表者 | 代表取締役 ポール チャップマン |
| 設立日 | 2012年4月23日 |
| 事業内容 | 資産管理サービス「Moneytree®︎」、財務管理サービス「Moneytree Business®︎」および金融データプラットフォーム「Moneytree LINK®︎」、融資DX「Moneytree Verify®︎」の開発・運営 |
| 従業員数 | 76名(2026年3月末時点) |