GT

【Agentic DevSecOps Engineer(Backend × Security)】In-house Product | Full Remote | JLPT N2~

G Talent
Posted 2 hours ago
JapanRemoteEngineering & Development
Is this job info correct?

★Agentic DevSecOps Engineer(Backend×Security) | AI+Marketing

  • Japanese: Business Level Required


◆ Famous Venture Company

◆ Flextime & Fully Remote Work

◆ In-house Products/Services

◆ Global Team

◆ Annual salary: 7 million yen - 8 million yen


-------------【About the company】-------------


The company provides a communication platform that leverages LINE to bridge the gap between businesses and their customers. They offer specialized solutions across a broad range of industries, including human resources, education, and real estate.


By placing their proprietary product at the core of their strategy, the company helps clients optimize communication to drive revenue growth and reduce operational costs. Currently, they are heavily focused on accelerating feature development and further enhancing their support ecosystem.


-------------【 Job Description】-------------


【Overview】

The organization is seeking a dedicated engineer to take full responsibility—from design to implementation—for the core security agents of the Agentic Security Life Cycle (ASLC).

ASLC is a security operations cycle centered around AI agents supporting each stage of the development lifecycle. Security agents will be built for every stage: Design, Code, Build, Test, Release, and Operations, as well as for two cross-cutting layers: Data Protection and AI Security.

The median time from CVE disclosure to the emergence of a functional exploit has collapsed from 56 days in 2024 to approximately 10 hours in 2026. It is clear that manual human response cannot keep pace, necessitating the leverage of AI technology for automated defense.


【Responsibilities】

Design, Implementation, and Operations of Security Agents: Architect and build AI security agents supporting each phase of the development lifecycle using the Claude Agent SDK.

CI/CD Security Integration: Embed SAST, SCA, secret detection, and related automated security checks directly into CI pipelines.

Threat Modeling and Security Reviews: Conduct threat modeling for high-risk features and perform rigorous security reviews on implementation code and API architectures.

In-Housing Vulnerability Assessments: Internalize and execute DAST, API security testing, and penetration testing workflows.

Data Privacy & Protection Engineering: Implement data classification, masking, tokenization, fine-grained access control, and privacy protections.

Adversarial AI Testing & Safeguards: Perform adversarial red-teaming/testing on internal AI agents and construct robust guardrail systems.


【Organizational Structure】

This position represents the first dedicated security engineer hire. Rather than working in isolation, you will join a collaborative structure where the VP of Security and a Security Specialist will continuously handle strategy, implementation requirements, and customer-facing response. As a member of the Security Team responsible for both data privacy and overall service safety, the engineer will work within a global, remote-first engineering organization.


【Role Expectations & Ideal Motivations】

Leveraging strong background and core skills in software engineering to tackle complex security domain challenges.

Building and designing core security frameworks and mechanisms from the ground up, rather than simply operating third-party security software.

Driving the development and deployment of AI agents as the primary focus of daily engineering activities.

Possessing a strong interest and drive to build pioneering solutions in uncharted territories from zero to one.

Viewing security not as a cost center, but as a core driver of product quality and strategic business competitiveness.


【What You'll Gain from This Position】

High degree of autonomy and total ownership in driving key security initiatives.

Collaborative work culture within a distributed, remote-first global engineering organization.

Opportunity to place AI agent development at the absolute center of daily engineering operations.

Greenfield discretion to design security systems and workflows from scratch, unrestricted by legacy operations.

Highly competitive remuneration package and comprehensive employee benefits.

Dynamic, flexible working style built on mutual trust and individual accountability.

Ample opportunities for continuous technical learning and long-term career advancement.


【Career Path & Growth Opportunities】

As the first dedicated security engineer, this role offers hands-on experience through the design, implementation, and operation of ASLC, with opportunities to grow into a Lead DevSecOps Engineer. Starting from establishing core security infrastructure, you can aspire to lead the expansion of the security organization in the future.


-------------【 Requirements】-------------


【Required】

5+ years of practical experience as a software development engineer

Experience in backend development using TypeScript, Python, Go, etc.

Daily use of AI coding agents such as Claude Code in business operations

Business-level Japanese proficiency

Strong communication skills, debugging skills, teamwork skills, problem-solving skills, and logical thinking skills

Ability to proactively drive projects forward even in highly uncertain situations


【Preferred】

Practical experience in secure code reviews, threat modeling, and API/web vulnerability assessments

Experience addressing supply chain security issues based on the OWASP Top 10, API Top 10, CVE, and OSV

Practical experience with cloud security on AWS (IAM, GuardDuty, Security Hub, CloudTrail)

Experience integrating security into CI/CD (implementation and adoption of SAST, SCA, and secret detection)

Experience with AI/LLM security (testing for prompt injection, jailbreak, and tool abuse)

Knowledge of OWASP LLM Top 10, MITRE ATLAS, Promptfoo, Garak, PyRIT, etc.

Experience building agents and automation on LLM SDKs (tool integration, MCP integration)

Practical experience with penetration testing (at a level capable of handling chained attack vectors)

Experience handling large-scale personal data (classification, masking, tokenization, access proxies)

Understanding of the Personal Information Protection Act and GDPR

Experience with security compliance for regulated industries (checklists, customer audits, trust centers)

Experience reading technical documentation and communicating in English

Certifications such as OSCP, GWAPT, CISSP, and Information Processing Security Support Specialist


--------------------------------------------------


【Welfare】

・Transportation allowance (bicycle commuting permitted)

・Company-issued laptop provided

・Company-issued mobile phone provided ※For certain positions only

・Flexible start time system (may apply every 2 months)

・Social insurance (Health Insurance, Employees' Pension Insurance, Employment Insurance, Workers' Accident Compensation Insurance)

・Life and health support leave

・Health checkup costs covered

・Childbirth and childcare support system

・Club activities

-------------------------------------------------------------------------

Similar jobs