About this Senior Security Engineer / Architect role at SmartNews
About SmartNews
SmartNews is a leading global information and news discovery company dedicated to delivering quality information to the people who need it. Thanks to our unique machine-learning technology and relationships with more than 3,000 global publisher partners, we provide news that matters to millions of users.
Founded in 2012 in Tokyo, SmartNews also has offices in Osaka (Kansai Office), Palo Alto, New York and Singapore.
If you share our vision and are passionate about our mission, we encourage you to apply!

The Security team at SmartNews protects and strengthens the company's overall security posture, working proactively rather than reactively across both our product and our corporate environment. On the Security Operations side, the team monitors systems continuously, detects and investigates threats, and manages security incidents and vulnerabilities through to resolution. On the Governance, Risk, and Compliance side, the team sets the standards and policies that guide how
SmartNews handles security, and ensures we meet our obligations under applicable legal and industry requirements. Rather than operating as a separate gatekeeping function, the team embeds security practices directly into product development and day-to-day business operations, so that protecting our users, our data, and our platform is a shared discipline across the organization.
SmartNewsのセキュリティチームは、受動的な対応ではなく能動的な取り組みを通じて、プロダクトとコーポレート環境の双方にわたり、全社的なセキュリティ体制の保護と強化を担っています。セキュリティオペレーションの領域では、システムを常時モニタリングし、脅威の検知と調査を行い、セキュリティインシデントや脆弱性を解決に至るまで一貫して管理します。ガバナンス・リスク・コンプライアンス(GRC)の領域では、SmartNewsにおけるセキュリティ対応の指針となる基準やポリシーを策定し、適用される法令および業界標準上の要件を確実に満たせるようにしています。また、当チームは独立したゲートキーパーとして機能するのではなく、プロダクト開発や日々の事業運営そのものにセキュリティのプラクティスを組み込むことで、ユーザー・データ・プラットフォームの保護を組織全体で共有される規律として根付かせています。
- Define security blueprints, threat models, and reference architectures
- Develop technical solutions to prevent or mitigate security vulnerabilities and strengthen overall system security
- Develop automated security solutions to seamlessly integrate security checks directly into developer and agent workflows and eliminate manual friction
- Build custom integrations between various security tools (e.g., network scanners, ASM, EDR) to provide real-time security observability for engineering teams
- Own the technical controls that make safe AI adoption possible
- 全社のセキュリティ設計方針と脅威モデルを定義し、開発チームがそのまま使えるリファレンスアーキテクチャに落とし込む
- セキュリティの脆弱性を防止または軽減し、システム全体のセキュリティを強化するための技術的ソリューションを開発する
- 開発者およびAIエージェントのワークフローにセキュリティチェックを自然な形で組み込み、手作業のレビューに依存しない状態をつくる
- 各種セキュリティツール(例:CSPM、SAST/SCA、ASM、EDR)をAPIで連携させ、各チームが自分のサービスのセキュリティ状態を自ら把握できる状態をつくる
- AIを安全に導入するための技術的なガードレールの整備を主導する
Requirements
Minimum requirements
- Proficient in English and Japanese to support a multinational engineering community
- Hands-on experience securing enterprise AI adoption at pace (third-party LLM integrations, MCP server onboarding, agentic tools acting on internal systems). We want to hear from your lived experiences and learn from them.
- A strict "Security as Code" mindset, viewing manual tasks as an automation failure and striving to build self-service security capabilities
- Detailed knowledge of system security vulnerabilities and remediation techniques, including penetration testing, and mitigation technique
- A solid understanding of the intersection between DevOps and SecOps, with a track record of building high-velocity, secure engineering cultures
- 多国籍のエンジニアリング組織を支援するため、英語と日本語の両方で業務を遂行できること
- 事業会社においてAI活用を短期間で推進した実務経験(外部LLMの組み込み、MCPサーバーの導入、社内システムを実際に操作するエージェント型ツールの開発など)。
- 「Security as Code」を徹底して志向し、手作業が残っている状態を自動化の不足と捉えて、開発者が自分で使えるセキュリティ機能を構築できること
- 脆弱性とその修正・緩和方法について深い知識を有すること(ペネトレーションテストの実施経験を含む)
- DevOpsとSecOpsが交わる領域を深く理解し、開発スピードと安全性を両立するエンジニアリング文化を築いた実績があること
Nice to have experiences/skills
- Capabilities in supply chain protection/SBOM scanning
- Able to design technical guardrails for agentic system
- Passionate resonance with fast-moving AI protocol standards (MCP and A2A) and actively involved in the community
- サプライチェーンセキュリティやSBOMを用いた脆弱性管理の導入・運用経験があること
- AIエージェントを用いたシステム向けに、技術的なガードレールを設計できること
- 急速に発展しているAI関連のプロトコル標準(MCPやA2Aなど)に強い関心を持ち、コミュニティでの活動にも積極的に関わっていること
Related Links
Working condition
- Office Location: Tokyo
Click here or visit our careers site for more info.
Benefits
Benefits available at the SmartNews Tokyo Office
- All healthcare and social insurance required by the Japanese labor law, plus annual health check
- Visa sponsorship and overseas relocation support available for eligible candidates
Click here or visit our careers site for more info about our benefits.
