About SmartNews SmartNews is a leading global information and news discovery company dedicated to delivering quality information to the people who need it. Thanks to our unique machine-learning technology and relationships with more than 3,000 global publisher partners, we provide news that matters to millions of users. Founded in 2012 in Tokyo, SmartNews also has offices in Osaka (Kansai Office), Palo Alto, New York and Singapore.
If you share our vision and are passionate about our mission, we encourage you to apply! The Security team at SmartNews protects and strengthens the company's overall security posture, working proactively rather than reactively across both our product and our corporate environment. On the Security Operations side, the team monitors systems continuously, detects and investigates threats, and manages security incidents and vulnerabilities through to resolution.
On the Governance, Risk, and Compliance side, the team sets the standards and policies that guide how SmartNews handles security, and ensures we meet our obligations under applicable legal and industry requirements. Rather than operating as a separate gatekeeping function, the team embeds security practices directly into product development and day-to-day business operations, so that protecting our users, our data, and our platform is a shared discipline across the organization.
SmartNewsのセキュリティチームは、受動的な対応ではなく能動的な取り組みを通じて、プロダクトとコーポレート環境の双方にわたり、全社的なセキュリティ体制の保護と強化を担っています。セキュリティオペレーションの領域では、システムを常時モニタリングし、脅威の検知と調査を行い、セキュリティインシデントや脆弱性を解決に至るまで一貫して管理します。ガバナンス・リスク・コンプライアンス(GRC)の領域では、SmartNewsにおけるセキュリティ対応の指針となる基準やポリシーを策定し、適用される法令および業界標準上の要件を確実に満たせるようにしています。また、当チームは独立したゲートキーパーとして機能するのではなく、プロダクト開発や日々の事業運営そのものにセキュリティのプラクティスを組み込むことで、ユーザー・データ・プラットフォームの保護を組織全体で共有される規律として根付かせています。 Build and evolve Detection & Response capabilities across SmartNews infrastructure and products with a focus on detection and operational response.
Automate response and investigations by building workflows that reduce toil (triage, enrichment, containment, evidence capture) and improve time-to-understand/time-to-contain. Evaluate and respond to emergent security concerns in a lab environment, such as detection and response strategies for agents operating across infrastructure at scale. Identify gaps in security controls, develop remediation strategies, and coordinate vulnerability management and patching across IT, and cloud systems.
Perform comprehensive security and risk assessments across infrastructure, AI implementations, and global governance frameworks. Overhaul and streamline our ISMS policies, converting rigid legacy frameworks into clear, workable workflows for modern engineering and business operations. Manage security inquiries, partner audits, and compliance obligations (including JSOX and enterprise deal requirements) in collaboration with key business stakeholders.
SmartNewsのインフラおよびプロダクト全体を対象に、脅威の検知と対応(Detection & Response)の体制を構築し、継続的に高度化する。 トリアージ、情報の付加、封じ込め、証拠収集といった手作業を自動化し、状況の把握から封じ込めまでにかかる時間を短縮するワークフローを構築する。 ラボ環境において、インフラ全体で大規模に動作するエージェントに対する検知・対応戦略など、突発的なセキュリティ課題を評価し、対策を講じる。 セキュリティ対策のギャップを特定し、是正戦略を策定するとともに、ITおよびクラウド環境全体の脆弱性管理とパッチ適用を推進する。 インフラ、AI導入、およびグローバルなガバナンスフレーム要件を対象に、包括的なセキュリティおよびリスク評価を実施する。 ISMSポリシーを全面的に見直し、合理化することで、硬直した従来のフレームワークを、現代のエンジニアリングおよび事業運営に即した、明確で実用的なワークフローに置き換える。 主要な事業ステークホルダーと連携し、セキュリティに関する問い合わせ、パートナーによる監査、およびコンプライアンス要件(J-SOXやBtoB取引先からの要求事項を含む)への対応を取りまとめる。。 Requirements Minimum requirements Japanese - Primary / English - Intermediate+ Familiar with the enterprise AI attack surface Have hands-on threat detection and/or incident response experience, including building detections, running investigations, and improving operational playbooks.
Understanding of regulatory requirements, personal data protection laws, and compliance standards Substantial experience in turning compliance controls into policy and scalable, auditable, operations Experience partnering with internal Business Process Owners to define clear sec