Skip to content

Open nowPosted 9 hours ago

Sr. Security Engineer - GRC APAC Fintech & Financial Services

xAI305 open roles

Where
Tokyo, Japan
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr. Security Engineer - GRC APAC Fintech & Financial ServicesxAI · Tokyo, Japan
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on xAI's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. xAI postings stay open a median of 39 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: posted 9 hours ago

xAI median: 39 days open

The posting

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE:

We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on Japanese information security and financial services regulation to help scale compliance for SpaceXAI and X Money. As we expand deeper into the regulated Japanese market, maintaining a robust, transparent, and technically sound information security GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on experience with JFSA supervisory expectations, APPI, and local Japanese banking and payments technology controls, plus GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. This position may require occasional travel.

RESPONSIBILITIES:

  • Own and evolve Japan financial services and payments compliance posture across JFSA supervisory expectations (including technology risk management, incident reporting, and third-party technology risk), APPI, and local Japanese banking and payments technology controls supporting X Money.
  • Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit and supervisory readiness scales with the business rather than depending on manual, point-in-time checks.
  • Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.
  • Partner with Architects and Engineering Leads to bake JFSA and APPI requirements into design early; translate complex Japanese regulatory obligations into concrete technical implementations and auditor- or supervisor-ready narratives without slowing development.
  • Design, implement, and validate technical controls relevant to Japanese banking and payments environments (access control, logging and monitoring, encryption, change management, vulnerability management, business continuity and disaster recovery, and secure SDLC) — not just document them.
  • Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk under JFSA supervisory expectations.
  • Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the Japan regulated attack surface, including third-party technology risk and subcontractor/sub-processor oversight.
  • Liaise with Legal and the Data Privacy team on security-relevant intersections with APPI, including security measures for personal data and breach/incident reporting aligned to applicable JFSA expectations.
  • Own and cultivate relationships with external auditors, assessors, and (where applicable) JFSA supervisory contacts; serve as the bridge between external parties and internal teams so requests are reasonable, clear, and relevant to our stack.
  • Develop, maintain, and continuously improve policies, standards, and procedures aligned to JFSA, APPI, and local banking and payments technology requirements, mapped to the control library shared with US Fintech to avoid duplicate control sets.
  • Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.

BASIC QUALIFICATIONS:

  • Bachelor's degree in computer science, Information Security, Cybersecurity, risk management, or an engineering/STEM field — or equivalent practical experience.
  • 8+ years of experience owning or materially operating a GRC, information security compliance, or ISMS program in fintech, banking, payments, SaaS, or other regulated technology environments — with primary Japan exposure.
  • Demonstrable experience owning or materially operating an ISMS and control library, and experience supporting client security assurance, external audits, or regulatory evidence processes.
  • Hands-on experience with JFSA supervisory expectations and local Japanese banking and payments technology controls — including implementing or operating controls, not only reading the requirements.
  • Strong understanding of information security risk management, control assessment, risk treatment, and governance reporting to senior stakeholders.
  • Experience coordinating security incident response governance (escalation, communications, remediation tracking) and operating or improving supplier/third-party security assurance.
  • Working knowledge of APPI sufficient to partner with Privacy counterparts on security of personal data and incident support.
  • Technical fluency to partner with Engineering on cloud (AWS/GCP/Azure), identity, logging, and secure SDLC — and to evaluate control objectives against real configurations.

PREFERRED SKILLS AND EXPERIENCE:

  • 10+ years of information security compliance, GRC engineering, or technology audit experience in fintech or financial services with a primary Japan focus.
  • Experience in a SaaS, fintech, financial services, regulated technology, or B2B enterprise software environment.
  • Hands-on experience implementing technical controls (IAM, logging/monitoring, encryption, hardening) and integrating compliance checks into CI/CD / DevSecOps pipelines.
  • Familiarity with secure SDLC practices: threat modeling, SAST/DAST, dependency scanning, secrets management, application/API penetration testing, and vulnerability remediation tracking.
  • Deep familiarity with JFSA expectations for technology risk management, third-party technology risk, and incident reporting at banking and payments providers.
  • Experience enabling enterprise sales through trust centers, vendor questionnaires, client audits, and contractual security schedules for clients in Japan.
  • Experience mapping a single control library shared across jurisdictions (e.g., US Fintech and Japan) so JFSA, APPI, and local banking and payments technology requirements are met without duplicate control sets.
  • Experience supporting BC/DR and resilience evidence (dependency mapping, backup/restore testing, RTO/RPO validation).
  • Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics.
  • Excellent communication and stakeholder management — able to explain risk and tradeoffs to engineers, legal, privacy, sales, and executives in plain language.
  • Certifications such as CISSP, CISM, CISA, CRISC, or equivalent preferred.
  • Prior experience working with or within JFSA-supervised financial institutions, banking or payments providers, or supervised fintechs in Japan is a plus.
  • Based in Japan; fluency in English required; Japanese language proficiency a plus.

SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against xAI's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on xAI's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    xAI's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.