Description and Requirements
è·åæŠèŠ
æ±äº¬ã«æ ç¹ã眮ã倧æçåœä¿éºäŒç€Ÿã«ãããŠãã°ããŒãã«ãªååãšé£æºããªããåœç€Ÿã®ã»ãã¥ãªãã£äœå¶ã匷åããŠããã ãæ
å ±ã»ãã¥ãªãã£å°éå®¶ãåéããŸããæ¬ããžã·ã§ã³ã¯ãã¢ã€ãã³ãã£ãã£ã»ã¢ã¯ã»ã¹ç®¡çïŒIAMïŒããã³ã»ãã¥ãªãã£ã¢ããã€ã¶ãŒãšããŠãäŒç€Ÿã®æ©å¯æ
å ±ãšãå®¢æ§æ
å ±ã®ãæ©å¯æ§ã»å®å
šæ§ã»å¯çšæ§ïŒCIAïŒããç©æ¥µçã«ç¢ºä¿ããæ¥µããŠéèŠãªåœ¹å²ãæ
ããŸãã
äž»èŠãªè²¬å**:**
ã¢ã€ãã³ãã£ãã£ã»ã¢ã¯ã»ã¹ç®¡ç:
- æ©å¯æ
å ±ã®äžæ£ã¢ã¯ã»ã¹ããã³é瀺ã鲿¢ãããããããŒã¿ä¿è·å¯Ÿçãå°å
¥ããéçšãç¶æããã
- IAMïŒIdentity Access ManagementïŒã³ã³ãããŒã«ã®æå¹æ§ãç¶ç¶çã«ç£èŠã»è©äŸ¡ããæ¹åçãææ¡ã»å®è¡ããã
- åœå
å€ã®é£æºæ
åœè
ãšååããCyberArkãSailPointãªã©ã®IAMé¢é£ã·ã¹ãã ã®åŒ·åãããžã§ã¯ããäž»å°ããã
- ã»ãã¥ãªãã£ã·ã¹ãã ãšããªã·ãŒã管çããèŠå¶èŠä»¶ïŒPCIãFSAãSOXãªã©ïŒãšã®æŽåæ§ã確ä¿ããã
ã»ãã¥ãªãã£ã¢ããã€ã¶ãªãŒ:
- ã¡ããã©ã€ãçåœã«ITãµãŒãã¹ãæäŸããã¢ããªã±ãŒã·ã§ã³éçºããŒã ããã³ITã€ã³ãã©ã¹ãã©ã¯ãã£ããŒã ã«å¯Ÿããã»ãã¥ãªãã£ããŒã¹ã©ã€ã³ãšæéãæäŸãããæ
å ±ã»ãã¥ãªãã£ã¢ããã€ã¶ãŒãšããŠãå
ç¢ãªã»ãã¥ãªãã£ã¢ãŒããã¯ãã£ã確ä¿ããããããµãŒãã¹æäŸãããžã§ã¯ãã®åææ®µéããåç»ããã
- æ
å ±ã»ãã¥ãªãã£ããªã·ãŒã®é å®ã培åºããã·ã¹ãã ããã³éçšã«ããããªã¹ã¯ãé©åã«ç®¡çããã
- ã¢ããªã±ãŒã·ã§ã³ããã³ITã€ã³ãã©ã¹ãã©ã¯ãã£ãµãŒãã¹ã®ç¯å²ã«ãããæ
å ±ã»ãã¥ãªãã£äºé
ã®äžå¿ççªå£ïŒGo-to-personïŒãæ
åœããã
- ã·ã¹ãã ã®ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãã宿œããè©äŸ¡ã¬ããŒããæéå
ã«æåºããã
- åœå
å€ã®é£æºæ
åœè
ãšååããã»ãã¥ãªãã£ã®ç¶æããã³æ¹åããã°ã©ã ãäž»å°ã»å®è¡ããã
- æ
å ±ã»ãã¥ãªãã£ã«é¢ããæèåäžãå³ããITã·ã¹ãã 管çãšéçšã®ã©ã€ããµã€ã¯ã«å
šäœã«ã»ãã¥ãªãã£ãçµã¿èŸŒãã
- èŠå¶èŠä»¶ãæ¥çæšæºããã¬ã³ãã®å€åã«å¯Ÿå¿ãããã®åœ±é¿ãåæã®äžãå¿
èŠãªå¯Ÿçãè¬ããã
- åçš®ããã°ã©ã ã®é²æç¶æ³ããã³çŸåšã®ã»ãã¥ãªãã£æ
å¢ã«é¢ããå ±åãè¡ãã
å¿åæ¡ä»¶**:**
åŠæŽ**:**
- ã³ã³ãã¥ãŒã¿ãŒãµã€ãšã³ã¹ãæ
å ±ã·ã¹ãã ãæ
å ±ã»ãã¥ãªãã£ããŸãã¯é¢é£åéã«ãããåŠå£«å·ãæããããšãæãŸããã
å¿
é æ¡ä»¶**:**
- æ
å ±ã»ãã¥ãªãã£é¢é£åéã«ãããæäœ5幎以äžã®å®åçµéšã
- ITã€ã³ãã©ã¹ãã©ã¯ãã£ããµã€ããŒã»ãã¥ãªãã£ãæè¡ãã¬ã³ããããã³é¢é£èŠå¶ã«é¢ããç¥èã
- å
šéå±€ã®åŸæ¥å¡ã«å¯Ÿããæç¢ºãã€é©åãªè¡šçŸãçšããŠæ£ç¢ºãªã¬ããŒãäœæããã³å£é ã§ã®ãã¬ãŒã³ããŒã·ã§ã³ãè¡ãèœåã
- æ°ããæè¡ãæ
å ±ã»ãã¥ãªãã£ã®å®åæ
£è¡ãç©æ¥µçã«åŠã¶ææ¬²ã
æè¿æ¡ä»¶**:**
- ããžãã¹ã¢ããªã±ãŒã·ã§ã³éçºã®çµéšããŸãã¯ITã€ã³ãã©ã¹ãã©ã¯ãã£ã®åŒ·åïŒHardeningïŒã«é¢ããçµéšã
- ãµã€ããŒã»ãã¥ãªãã£ãITãªã¹ã¯ã¬ããã³ã¹ããµãŒãããŒãã£ãªã¹ã¯ç®¡çãªã©ãããåºç¯ãªæ
å ±ã»ãã¥ãªãã£ããã³ãªã¹ã¯ç®¡çåéãžã®é¢å¿ã
- ã¯ã©ãŠãã»ãã¥ãªãã£ãããŒã¿ä¿è·ãã€ã³ã·ãã³ã察å¿ã®çµéšã
- èŠå¶ãæ¥çæšæºïŒäŸïŒNIST CSFãPCI DSSãFISCïŒã«é¢ããç¥èã
- CISSPãCISMãCISAãŸãã¯é¡äŒŒã®æ
å ±ã»ãã¥ãªãã£é¢é£èªå®è³æ Œãä¿æããŠããå Žåã¯å°å¯ïŒåªéïŒã
èšèª**:**
- æ¥æ¬èªïŒãã€ãã£ãã¬ãã«ããŸãã¯ããã«çžåœããé«ãèªåŠåã
- è±èªïŒäžçŽã¬ãã«ãè±èªïŒèªã¿æžããäŒè©±ïŒã®ã¹ãã«åäžãšå®åã§ã®æŽ»çšã«ç©æ¥µçã«åãçµãææ¬²ã¯å¿
é ã
æ±ããã¹ãã«ã»äººæå**:**
- ã³ãã¥ãã±ãŒã·ã§ã³èœå: 匷åãªã³ãã¥ãã±ãŒã·ã§ã³ã¹ãã«ãšå¯Ÿäººé¢ä¿æ§ç¯èœåãæã¡ãéšé暪æçãªããŒã ãšå¹æçã«ååã§ããããšã
- çµæå¿å: ã€ãããŒã·ã§ã³ãšç¶ç¶çãªæ¹åãéããŠã枬å®å¯èœãªææãåµåºããããšã
- åé¡è§£æ±ºèœå: åªããåæåãšãæ¬è³ªçãªèª²é¡ã解決ã«å°ãèœåã
- å€é©ã®ãªãŒããŒã·ãã: åªå
é äœãå€åãããã€ãããã¯ãªç°å¢ã«ãããŠãçå
ããŠå€é©ãäž»å°ã§ããããšã
- ãããžã§ã¯ã管çèœå: ã¹ããŒãæã®ããç°å¢ã«ãããŠãè€æ°ã®ãããžã§ã¯ããšåªå
é äœãé©åã«ç®¡çã§ããèœåã
Role Value Proposition
We are seeking an Information Security Professional for a leading life insurance company based in Tokyo, with the opportunity to collaborate remotely with global counterparts. Â In this critical role as an Identity Access Management and Security Advisor, you will proactively protect the confidentiality, integrity, and availability of the companyâs and customersâ information. Â
Key Responsibilities:
Identity Access Management:
- Implement and maintain data protection measures to safeguard sensitive information from unauthorized access or disclosure.
- Monitor and report on the effectiveness of IAM controls and provide recommendations for continuous improvement.
- Lead projects to enhance IAM-related systems, such as CyberArk and SailPoint, in collaboration with local and global counterparts. Â Â Â
- Manage the security systems and policies, ensuring alignment with regulatory requirements (e.g., PCI, FSA, SOX)
- Participate in industry events or working groups such as Financials ISAC Japan as required.
Security Advisory:
- Provide security baseline and guidance to Application Development team and IT Infrastructure team delivering IT services to MetLife. As an Information Security Advisor, engage with service delivery projects from the initial stages to ensure robust security architecture.
- Ensure adherence to Information Security policies to manage systems and operational risks.
- Serve as the go-to person for information security matters within the scope of Application and IT Infrastructure Services.
- Conduct system risk assessments and deliver assessment reports in a timely manner.Â
- Lead and execute security maintenance and improvement programs in collaboration with local and global counterparts.
- Raise awareness of information security to embed it into the lifecycle of IT system management and operations.
- Respond to changes in regulatory requirements, industry standards, and trends, analyze their implications, and take necessary measures.
- Provide progress reports on various programs and the current security posture.
Candidate Qualifications:
Education:
- A Bachelorâs degree in Computer Science, Information Systems, Information Security, or a related field is highly desirable.
Required Experience:
-
Minimum of 5 years of hands-on experience in information security related field.
-
Knowledge of IT infrastructure, cybersecurity, technology trends, and regulations.
-
Ability to prepare accurate reports for all levels of staff in clear and appropriate language, and to provide oral presentations.
-
Willingness to learn new technologies and information security practices.
Preferred Experience:
- Experience in business application development experience or IT Infrastructures hardening.
- Interest in broader information security and risk management areas such as cybersecurity, IT risk governance and third-party risk management.
- Experience with cloud security, data protection, and incident response.
- Familiarity with regulatory / industry standards (e.g., NIST CSF, PCI DSS, FISC)
- CISSP, CISM, CISA or similar information security-related certifications are a plus.
Language:
- Native or equivalent level of Japanese and intermediate level of English proficiency. Intention to improve and practice English (read, write, verbal) is a must.
Skills and Competencies:
- Communication: Strong communication and interpersonal skills, with the ability to work effectively with cross-functional teams.Â
- Results-Oriented: Delivers measurable outcomes through innovation and continuous improvement.
- Problem-Solver: Â Â Excellent analytical and problem-solving skills. Â
- Change Leadership: Comfortable leading in dynamic environments with evolving priorities.
- Project Management: Ability to manage multiple projects and priorities in a fast-paced environment.