スキルハウスの採用情報

Cybersecurity Lead (DFIR)

役職:

Cybersecurity Lead (DFIR)

雇用形態:

Permanent

給与:

勤務時間:

English Level - Advanced (TOEIC 860), Japanese Level - Advanced (JLPT Level 1)

職務内容

 

 


One of the world’s largest financial services companies is seeking a Cybersecurity Lead t o join its Cyber Defense & Response organization.
In this role, you will lead the Digital Forensics and Incident Response (DFIR) function, managing a highly skilled technical team and continuously strengthening the organization’s enterprise-wide cyber incident response capabilities.
As a senior decision-maker during incident response, you will assess and direct the handling of escalated incidents while, over the medium to long term, leading initiatives to mature the overall Incident Response program across processes, organizational capabilities, and technology.
A key part of this role is developing the technical capabilities and careers of team members. Through internal training, knowledge sharing, mentoring, and other development initiatives, you will help build and maintain a highly skilled and specialized team.
Success in this role requires not only deep technical expertise, but also the ability to assess and organize complex situations from a broader perspective, build consensus across stakeholders, demonstrate inclusive leadership, and continuously learn and adapt to evolving threats and technologies.

Responsibilities:
- Partner with group life insurance companies, the Information Security Office (ISO), and global technology teams to oversee and coordinate cyber incident response, ensuring timely and business-impact-aware handling of incidents
- Serve as the final decision-maker for critical incidents escalated from the Cyber Security Operations Center (CSOC), business functions, and external partners
- Establish and enhance organizational capabilities and maturity initiatives to embed effective incident response capabilities into new business processes and technology implementations
- Manage the full lifecycle of investigations, ensuring that documentation, reporting, evidence management, and chain of custody are properly maintained in accordance with regulatory and audit requirements
- Lead cross-functional risk management in collaboration with Technology, Legal, Privacy, Communications, and other relevant functions, covering both cyber and business risks
- Continuously drive process improvements and resilience initiatives through post-incident analysis, KPI measurement, and threat intelligence
- Leverage expertise in emerging technologies and evolving threat landscapes to guide investigation strategies and support the technical development and growth of the team
- Maintain and promote knowledge of cybersecurity principles, frameworks, and industry trends to ensure the organization maintains a leading level of incident response capability

Required Skills:
- 10+ years of hands-on experience in cyber incident response and digital forensics within a large enterprise or government organization, including experience with complex and distributed IT infrastructure environments
- 5+ years of experience as a technical team lead or manager, with a proven track record of developing team members, strengthening organizational capabilities, and improving operational quality
- Strong experience with identity platforms, including Entra ID (Azure AD) and Active Directory
- Strong experience with cloud platforms, including Azure and AWS
- Experience with Microsoft 365 environments
- Strong knowledge of Windows, Linux, and macOS operating systems
- Advanced query and detection engineering skills across SIEM, EDR, and detection platforms, including hands-on experience designing and operating detection logic and investigation queries using SPL, KQL, or similar technologies
- Practical experience developing scripts and automation using Python, PowerShell, Bash, or similar languages for investigation, incident response, and operational improvement
- Extensive hands-on experience with major digital forensics tools, including X-Ways, EnCase, KAPE, The Sleuth Kit, Volatility, or equivalent commercial/open-source tools
- Ability to clearly communicate investigation findings, technical risks, and business implications in both Japanese and English to technical professionals as well as senior executives
- Proven experience developing practical detection, investigation, and response strategies based on adversary tactics and techniques, using frameworks such as MITRE ATT&CK and the Cyber Kill Chain

Why should you apply:
- Join a team where every individual's perspective is valued and where your work can contribute to improving people's experiences and everyday lives
- Leverage your existing expertise while gaining opportunities to further develop both your technical capabilities and leadership skills, enabling you to create an even greater impact
- Build your career within a stable and established organization


Company Details:
Founded in 2008 and headquartered in the United States, the company is one of the world’s largest financial services institutions. As a global organization, it actively collaborates with international partners while providing IT infrastructure services to group companies across Japan.
Guided by the strong commitment of the Group to protect customers’ financial security and peace of mind, the company serves as a trusted partner supporting both technology and business. Its mission is to continue delivering stable, reliable, and trusted system infrastructure services.

Working Hours: 9:00 – 18:00
Work Style: Hybrid (1–2 days per week in the office; 0–2 weekend workdays per month)
Holidays: Saturdays, Sundays, public holidays, year-end and New Year holidays, paid leave, and special leave
Benefits: Full social insurance coverage, DC pension plan, transportation allowance, Skill House University, test payback system, and more


スキルハウスで共に成長し、学び、成功を目指しませんか。

スキルハウスのこのポジションにご興味のある方は、ご連絡先をご記入の上、履歴書を添付してください。

 ※右記個人情報は、採用選考のみに利用されます

東京都港区虎ノ門3-8-27巴町アネックス2号館

internalcareers@skillhouse.co.jp

Internal Vacancy Form