As a senior security engineer at MeetsMore, you’ll join the SRE team and cover four areas: penetration testing of our own products, application security in the development process, AI security-covering both our LLM-powered features and our AI-assisted development process-and the technical side of security compliance: implementing controls, automating evidence collection, and answering the engineering questions in audits and customer security checks.
You will be building the security team and leading the security effort across the company. You’ll work alongside an SRE / DevOps team that automates as much as possible. Communication is mostly in English and occasionally in Japanese, with support from translation tools.
Our Tech Stack
Not exhaustive, but the most important are:
- TypeScript everywhere.
- NodeJS.
- React.
- MongoDB.
- AWS (Specifically ECS, CloudFront, S3, SQS, Lambda)
- Vercel.
- Redis.
Requirements
- Have built or improved security in a development process: threat modeling, design reviews, and security tools in CI/CD (SAST, DAST, dependency scanning).
- Experience with cloud infrastructure security: finding and fixing issues in AWS IAM and network configuration, Kubernetes (RBAC, network policies, workload permissions), and CI/CD pipelines (secrets handling, supply chain).
- Experience implementing and operating automated attack detection and protection using technologies such as WAF, IDS/IPS, runtime application security, or SIEM-including rule tuning, monitoring, alerting, and response to attacks such as SQL injection and XSS.
- Experience in securing Node.js based application (Python or Go for tooling is fine too, but TypeScript is prefered.)
- Either be conversational in Japanese or have a desire to do so (we will help).
- Be located in, or be willing to relocate to, Japan (we will relocate).
Nice to haves
While not specifically required, tell us if you have any of the following.
- Experience testing or securing LLM-based features: prompt injection, jailbreaks, data leakage, or agent tool permissions.
- Have led at least one full penetration test from start to finish - scoping, testing, reporting, and confirming fixes - against web applications, mobile apps, and APIs.
- Have led a full certification audit (e.g., ISO 27001 / ISMS), ideally at a Japanese company: getting the controls in place, collecting evidence, and working directly with auditors.
- Offensive security certifications (OSCP, OSWE) or bug bounty / CTF experience.

