Key Responsibilities :
Security Assessment
- Conduct cybersecurity assessments for multinational clients across various industries.
- Review client security policies, procedures, standards, and related documentation.
- Assess client environments against recognized cybersecurity frameworks and standards, including:
- NIST Cybersecurity Framework (NIST CSF)
- CIS Controls
- ISO/IEC 27001
- Identify security gaps, risks, and improvement opportunities.
- Develop practical and actionable recommendations to address identified risks.
Assessment Planning & Execution
- Prepare assessment plans, interview questionnaires, and evidence request lists.
- Conduct interviews and workshops with client stakeholders.
- Perform onsite and remote security assessments as required.
- Gather, validate, and analyze assessment evidence.
- Coordinate assessment activities with client teams and project stakeholders.
Reporting & Communication
- Prepare assessment reports, executive summaries, and presentation materials.
- Present findings, risk observations, and recommendations to client stakeholders.
- Communicate effectively with both technical and non-technical audiences.
Project Support
- Support cybersecurity consulting engagements related to governance, risk management, and compliance.
- Contribute to the development and enhancement of assessment methodologies, templates, and knowledge assets.
- Collaborate with regional and global project teams.
Requirements :
Experience & Knowledge
- 2–5 years of experience in cybersecurity, information security, IT audit, IT risk management, or related fields.
- Experience conducting or supporting security assessments, audits, compliance reviews, or security consulting engagements.
- Hands-on experience assessing organizations against at least one of the following frameworks:
- NIST Cybersecurity Framework (NIST CSF)
- CIS Controls
- ISO/IEC 27001
- Experience working with enterprise-scale organizations and corporate environments.
- Understanding of security governance, risk management, and security controls.
Skills
- Strong analytical and problem-solving skills.
- Good report writing and documentation skills.
- Strong interpersonal and communication skills.
- Ability to conduct client interviews and facilitate discussions.
- Ability to communicate effectively with stakeholders ranging from IT personnel to management-level audiences.
- Business-level English communication skills.
Additional :
Preferred Qualifications
- Japanese language proficiency and/or experience working with Japanese multinational companies.
- Experience using AI solutions (e.g., Microsoft Copilot, ChatGPT, Gemini, or other enterprise AI tools) in business or professional environments.
- Security-related certifications are an advantage but not required, such as:
- CompTIA Security+
- ISC2 Certified in Cybersecurity (CC)
- Microsoft Security, Compliance, and Identity Fundamentals (SC-900)
- ISO/IEC 27001 Foundation
- ISO/IEC 27001 Internal Auditor
- Other equivalent cybersecurity certifications
AI Governance & AI Security
- Familiarity with AI-related security, governance, or risk management concepts.
- Knowledge of frameworks such as ISO/IEC 42001, ISO/IEC 23894, or NIST AI Risk Management Framework (AI RMF) is an advantage.
Operational Technology (OT) Security
- Exposure to Operational Technology (OT), Industrial Control Systems (ICS), or manufacturing environments.
- Familiarity with frameworks such as IEC 62443 or NIST SP 800-82 is an advantage.