Sobre este puesto de シニア セキュリティエクスポージャー&アーキテクチャ エンジニア/Senior Security Exposure & Architecture Engineer en Sony Interactive Entertainment Inc.
Why PlayStation?
PlayStation isn’t just the Best Place to Play — it’s also the Best Place to Work. Today, we’re recognized as a global leader in entertainment producing The PlayStation family of products and services including PlayStation®5, PlayStation®4, PlayStation®VR, PlayStation®Plus, acclaimed PlayStation software titles from PlayStation Studios, and more.
PlayStation also strives to create an inclusive environment that empowers employees and embraces diversity. We welcome and encourage everyone who has a passion and curiosity for innovation, technology, and play to explore our open positions and join our growing global team.
The PlayStation brand falls under Sony Interactive Entertainment, a wholly-owned subsidiary of Sony Group Corporation.
【職務内容】
SIEの情報セキュリティ組織において、Global Vulnerability Management(GVM)およびGlobal Security Architecture(GSA)の双方と連携し、脆弱性・セキュリティエクスポージャー管理とセキュリティアーキテクチャの両面から、SIE全体のセキュリティリスク低減を推進するポジションです。
実際に確認された脆弱性やセキュリティ上のエクスポージャーを単に個別対応するだけではなく、その背景にある根本原因を分析し、セキュアな設計、再発防止策、標準化されたアーキテクチャやセキュリティコントロールへとつなげていくことが、本ポジションの重要な役割です。クラウドネイティブ環境、次世代テクノロジー、クラウドゲーミング、AIを活用したシステム、プラットフォームサービス、エンタープライズIT環境など、SIEが展開する幅広い技術領域を対象とします。
日本および米国を中心としたSIE・Sony Group各社のセキュリティ、インフラ、クラウド、エンジニアリング、IT、ビジネス部門と密接に連携しながら、セキュリティリスクの特定、優先順位付け、検証、対応、および将来的な予防までを一貫して支援します。また、複数の組織・チームを横断するグローバル環境において、関係者と連携しながら業務を推進します。
【このポジションの役割】
セキュリティアーキテクチャとセキュリティエクスポージャー管理は、相互に補完する領域です。セキュリティアーキテクチャでは、安全な設計パターンや予防的なセキュリティコントロールを整備し、セキュリティエクスポージャー管理では、実際に確認された脆弱性やリスクに関するデータや技術的根拠を活用し、優先順位付け、改善対応、将来の設計に反映します。
・GVM領域:
実際の脆弱性・セキュリティエクスポージャーを特定・分析し、脅威情報、悪用可能性、事業・資産の重要度などを踏まえて優先順位付け・検証を行い、重要なリスクの低減を推進します。
・GSA領域:
新規・既存システムに対するセキュリティアーキテクチャレビューを実施し、セキュアな設計パターン、リファレンスアーキテクチャ、適切なセキュリティコントロールを策定します。
・共通するゴール:
繰り返し発生するセキュリティ課題を構造的なアーキテクチャ改善につなげるとともに、新しいシステム・サービスについても早期段階からセキュリティを組み込みます。リスク、事業上の重要性、根拠となる情報の確度、実現可能性、長期的な運用・サポート性を考慮したセキュリティ判断を行います。
【主な業務内容】
・GVMおよびGSAの共同施策に参画し、セキュリティエクスポージャー管理とセキュリティアーキテクチャを統合した運用モデルの構築・改善を推進
・新規および既存のサービス、プラットフォーム、インフラ設計、技術提案をレビューし、セキュリティ上の弱点、攻撃経路、セキュリティコントロールの不足を早期に特定し、実践的な改善策を提案
・脆弱性やセキュリティエクスポージャーについて、悪用可能性、事業・資産の重要度、技術的根拠、既存のセキュリティコントロール、対応難易度などを分析し、適切な優先順位および対応方針を提案
・セキュリティエクスポージャーの発見、情報付加、トリアージ、検証、対応判断、対応推進、効果確認、振り返りまでのライフサイクル全体を支援
・アーキテクチャ、インフラ、クラウド、エンジニアリングチームと連携し、繰り返し発生する脆弱性や根本原因を、スケーラブルな設計パターン、リファレンスアーキテクチャ、ハードニング基準、予防的コントロールへ反映
・AWS、Google Cloudを含むクラウドネイティブ、ハイブリッドクラウド、コンテナ、SaaS、PaaS、オンプレミス環境に加え、外部セキュリティ製品や独自開発のセキュリティコントロールを含む環境における、セキュアなアーキテクチャ設計および技術的アドバイス
・クラウド、ネットワーク、エンドポイント、サーバー、コンテナ、ID・認証、アプリケーション、プラットフォーム、AIを活用したシステムに対する、アーキテクチャ観点での改善・修正方針の策定
・正式な承認のもとで実施されるPoC検証、攻撃経路分析、アドバーサリアルテストの支援、セキュリティコントロールの有効性評価などのセキュリティ検証活動への参画
・再利用可能な技術ガイドラインや標準を策定し、セキュリティツール、データ、AI、自動化を適切に活用することで、可視性、優先順位付け、一貫性、チーム全体の業務品質・効率を向上
・セキュリティ上の課題、設計上のトレードオフ、推奨事項を明確に説明し、担当する施策を完遂するとともに、GVM、GSA、日本およびグローバルの各ステークホルダーとの連携を推進
【組織・職場紹介】
本ポジションは、Global Vulnerability Management(GVM)およびGlobal Security Architecture(GSA)の双方と連携して業務を行います。
日本および米国を中心としたグローバルチームと日常的に協働し、実際に確認されたセキュリティエクスポージャーや脆弱性に関する知見を、アーキテクチャ上の意思決定や長期的なリスク低減につなげていきます。
特定のシステムや製品のみを担当するのではなく、クラウド、ゲーム・プラットフォーム、エンタープライズIT、AIを活用したシステムなど、SIEの幅広い技術環境に関与できるポジションです。
【必須スキル・経験(MUST)】
・情報セキュリティ、セキュリティエンジニアリング、システムエンジニアリング、クラウドセキュリティ、インフラセキュリティ、プロダクトセキュリティ、セキュリティアーキテクチャ、または関連領域における実務経験
・アーキテクチャレビュー、セキュア設計、リファレンスパターン、セキュリティコントロールの選定、複雑な本番環境へのセキュリティ要件適用など、セキュリティアーキテクチャに関する十分な知識・経験
・脆弱性管理およびセキュリティエクスポージャー管理に関する知識
- 脅威情報を踏まえた優先順位付け
- 脆弱性・リスクの検証
- 改善・修正プロセス
- リスク判断を支える技術的根拠・データの活用
・クラウド、コンテナ、ネットワーク、プラットフォーム、アプリケーション、ID・認証、またはエンタープライズインフラ環境の評価、設計、セキュリティ強化、もしくは運用に関する実務経験
・セキュリティアセスメント、セキュリティエクスポージャー分析、脆弱性スキャン、検証、アーキテクチャレビュー、またはセキュア実装基準の策定・適用経験
・以下を含むセキュリティ技術に関する知識
- OS
- ネットワーク
- ID・認証
- 暗号化
- 鍵管理
- ネットワークセグメンテーション
- ファイアウォール
- WAF(Web Application Firewall)
- DDoS対策
- その他一般的なエンタープライズセキュリティコントロール
・日本語・英語ともにビジネスレベルのコミュニケーション能力
- 英語で技術的なディスカッションやアーキテクチャレビューを実施できること
- 技術的なリスクをビジネス観点で分かりやすく説明できること
- 直接的な指揮権限を持たないステークホルダーに対しても、合意形成・影響力を発揮できること
・コンピューターサイエンス、情報セキュリティ、数学、工学、その他関連分野の学士号、または同等の実務経験
【歓迎スキル・経験(WANT)】
・脆弱性管理またはThreat Exposure Managementを含むセキュリティエクスポージャー領域と、セキュリティアーキテクチャ、設計レビュー、またはセキュリティエンジニアリングの双方にまたがる実務経験
・以下のいずれかに関する実務経験
- AWS
- Google Cloud
- ハイブリッドクラウド
- Kubernetes
- CI/CDセキュリティ
- Infrastructure as Code(IaC)
- SaaS/PaaS
- マルチテナントシステム
- AIシステムセキュリティ
- モダンアプリケーションアーキテクチャ
・テスト、PoC開発、攻撃経路分析、アドバーサリアルテスト、セキュリティコントロールの有効性評価などを通じた、脆弱性の悪用可能性を検証した経験
・セキュリティレポーティング、分析、オートメーション、データを活用した優先順位付け、リファレンスアーキテクチャ、クラウドガバナンスなどのセキュリティ機能を構築・改善した経験
・複数の国・タイムゾーンにまたがるグローバルチームでの業務経験、特に日本および米国のステークホルダーとの協働経験
・日本におけるビジネス文化・業務環境への理解
・コンピューターサイエンス、情報セキュリティ、数学、工学、その他関連分野の修士号・博士号、または同等の高度な専門経験
【想定する人物】
・脆弱性やセキュリティエクスポージャーを単純なスキャン結果として扱うのではなく、脅威情報、悪用可能性、技術的根拠、事業上の重要度を踏まえて分析・優先順位付けし、実際のリスク低減につなげられる方
・セキュリティ上の課題や脆弱性から得られた知見を、リファレンスパターン、設計ガイドライン、セキュリティコントロール、クラウド・アプリケーション・ネットワーク・ID・インフラのセキュアなアーキテクチャに反映できる方
・個別の問題対応だけではなく、再発防止や仕組み化までを考え、システム全体を俯瞰して課題を捉えられる方
・技術的な判断や設計上のトレードオフを明確に文書化・説明し、関係者を巻き込みながら担当領域の施策を主体的に推進できる方
・スピード、リスク低減、ビジネス要件、長期的な設計品質のバランスを考慮しながら、実践的なセキュリティ判断ができる方
【このポジションの特徴】
・Global Vulnerability Management(GVM)とGlobal Security Architecture(GSA)の両領域に関わり、「発見された脆弱性への対応」と「将来の脆弱性を生みにくい設計」の双方を推進できるポジション
・クラウド、プラットフォーム、AI、クラウドゲーミング、エンタープライズITなど、SIEの幅広い技術領域に関与
・日本国内だけではなく、米国を中心としたグローバルセキュリティ・エンジニアリング組織との協働が日常的に発生する環境
・個別の脆弱性対応だけではなく、根本原因の特定、標準化、アーキテクチャ改善、予防的なセキュリティ設計まで影響を与えられる役割
PlayStation is not just the Best Place to Play - it is also the Best Place to Work. Since 1994, Sony Interactive Entertainment (SIE), a wholly owned subsidiary of Sony Group Corporation, has delivered industry-leading interactive entertainment experiences through the PlayStation brand.
We are seeking a highly technical security professional in Japan to work across Global Vulnerability Management (GVM) and Global Security Architecture (GSA). This role will help advance SIE’s approach to Threat Exposure Management by connecting real-world exposure evidence with practical security architecture, durable remediation, and preventative design guidance.
The successful candidate will work across cloud-native infrastructure, future technology initiatives, cloud gaming, artificial intelligence (AI)-enabled systems, platform services, and enterprise environments. They will apply architecture and exposure-management concepts to improve how security exposures are identified, prioritized, validated, treated, and prevented over time.
This position requires close collaboration with security, infrastructure, cloud, engineering, information technology, and business teams across SIE and Sony Group companies, including Japan- and United States-based stakeholders. Success depends on technical judgment, clear communication, practical delivery, and the ability to operate effectively in a matrixed global environment.
About the Role
Security architecture and exposure management are complementary disciplines: architecture establishes secure patterns and preventative controls, while exposure management uses evidence from real security exposures to improve decisions, remediation, and future designs.
· GVM focus: apply exposure-management practices to identify, enrich, prioritize, validate, and reduce the security exposures that matter most while improving evidence, remediation guidance, and continuous learning.
· GSA focus: conduct secure architecture reviews, develop reference patterns, select appropriate controls, and partner with engineering and infrastructure teams to reduce systemic risk.
· Shared outcome: recurring findings drive durable architecture improvements, new designs are reviewed early, and treatment decisions balance risk, business importance, evidence strength, feasibility, and long-term supportability.
Key Responsibilities
· Contribute across joint GVM and GSA initiatives, helping advance an integrated exposure-management operating model while delivering secure architecture reviews and architecture-informed remediation.
· Review new and existing services, platforms, infrastructure designs, and technical proposals to identify security weaknesses, attack paths, and control gaps early and recommend practical improvements.
· Analyze security exposures and findings using exploitability, business and asset criticality, supporting evidence, existing controls, and remediation complexity to recommend appropriate priorities and treatment options.
· Contribute across the exposure-management lifecycle by supporting discovery, enrichment, triage, validation, decisions, mobilization, verification, and learning for security exposures and findings.
· Partner with architecture, infrastructure, cloud, and engineering teams to translate recurring exposures and root causes into scalable design patterns, reference architectures, hardening standards, and preventative controls.
· Design and advise on secure cloud-native, hybrid, containerized, software-as-a-service (SaaS), platform-as-a-service (PaaS), and on-premises environments, including Amazon Web Services (AWS), Google Cloud, third-party security products, and custom-developed controls.
· Provide architecture-informed remediation guidance for cloud, network, endpoint, server, container, identity, application, platform, and AI-enabled systems.
· Contribute to authorized security validation activities such as proof-of-concept testing, attack path analysis, adversarial testing support, and control effectiveness reviews.
· Develop reusable technical guidance and use security tooling, data, AI, and automation responsibly to improve visibility, prioritization, consistency, and team effectiveness.
· Communicate security issues, design tradeoffs, and recommendations clearly; lead scoped work through completion; and align delivery across GVM, GSA, Japan, and global stakeholders.
Organization and Team
This position is jointly supported by GVM and GSA. The successful candidate will collaborate across Japan- and United States-based teams, connecting exposure insights with architecture decisions and durable risk reduction.
Required Qualifications (MUST)
· Demonstrated experience in information security, security engineering, systems engineering, cloud security, infrastructure security, product security, security architecture, or a related field.
· Strong foundation in security architecture principles, including architecture review, secure design, reference patterns, control selection, and the application of security requirements in complex production environments.
· Working knowledge of vulnerability and exposure management concepts, including threat-informed prioritization, validation, remediation workflows, and the use of evidence to support risk decisions.
· Hands-on experience assessing, securing, designing, or operating cloud-based, containerized, network, platform, application, identity, or enterprise infrastructure environments.
· Experience with security assessment, exposure analysis, vulnerability scanning, validation, architecture review, or secure implementation standards.
· Knowledge of operating systems, networking, identity, authentication, encryption, key management, segmentation, firewalls, web application firewalls (WAFs), distributed denial-of-service (DDoS) mitigation, and common enterprise security controls.
· Strong written and verbal communication skills, with business-level proficiency in Japanese and English, including the ability to conduct technical discussions and architecture reviews in English, explain technical risk in business terms, and influence without direct authority.
· Bachelor’s degree in Computer Science, Information Security, Mathematics, Engineering, a related field, or equivalent practical experience.
Preferred Qualifications (WANT)
· Experience spanning both vulnerability or threat exposure work and security architecture, design review, or security engineering work.
· Experience with AWS, Google Cloud, hybrid cloud, Kubernetes, continuous integration and continuous delivery (CI/CD) security, infrastructure as code, SaaS, PaaS, multi-tenant systems, AI system security, or modern application architectures.
· Experience validating exploitability through testing, proof-of-concept development, attack path analysis, adversarial testing, or control effectiveness reviews.
· Experience building or improving security reporting, analytics, automation, data-driven prioritization, reference architectures, cloud governance, or related security capabilities.
· Experience working across global teams and time zones, particularly with Japan- and United States-based stakeholders, and familiarity with business culture in Japan.
· Master’s degree or Ph.D. in Computer Science, Information Security, Mathematics, Engineering, a related field, or equivalent advanced experience.
What We’re Looking For
· A practitioner who can connect exposure analysis, threat research, exploitability assessment, evidence-based prioritization, validation, remediation guidance, workflow coordination, and security tooling interpretation.
· A security architect who can translate those insights into reference patterns, design guidance, control selection, and secure cloud, application, network, identity, and infrastructure architecture.
· A collaborative systems thinker who can lead scoped work, document technical decisions clearly, and balance speed, risk reduction, business needs, and long-term design quality.
Equal Opportunity Statement:
Sony is an Equal Opportunity Employer. All persons will receive consideration for employment without regard to gender (including gender identity, gender expression and gender reassignment), race (including colour, nationality, ethnic or national origin), religion or belief, marital or civil partnership status, disability, age, sexual orientation, pregnancy or maternity, trade union membership or membership in any other legally protected category.
We strive to create an inclusive environment, empower employees and embrace diversity. We encourage everyone to respond.
PlayStation is a Fair Chance employer and qualified applicants with arrest and conviction records will be considered for employment.