About SmartNews
SmartNews is a leading global information and news discovery company dedicated to delivering quality information to the people who need it. Thanks to our unique machine-learning technology and relationships with more than 3,000 global publisher partners, we provide news that matters to millions of users.
Founded in 2012 in Tokyo, SmartNews also has offices in Osaka (Kansai Office), Palo Alto, New York and Singapore.
If you share our vision and are passionate about our mission, we encourage you to apply!
The Security team at SmartNews protects and strengthens the company's overall security posture, working proactively rather than reactively across both our product and our corporate environment. On the Security Operations side, the team monitors systems continuously, detects and investigates threats, and manages security incidents and vulnerabilities through to resolution. On the Governance, Risk, and Compliance side, the team sets the standards and policies that guide how
SmartNews handles security, and ensures we meet our obligations under applicable legal and industry requirements. Rather than operating as a separate gatekeeping function, the team embeds security practices directly into product development and day-to-day business operations, so that protecting our users, our data, and our platform is a shared discipline across the organization.
SmartNewsのセキュリティチームは、受動的な対応ではなく能動的な取り組みを通じて、プロダクトとコーポレート環境の双方にわたり、全社的なセキュリティ体制の保護と強化を担っています。セキュリティオペレーションの領域では、システムを常時モニタリングし、脅威の検知と調査を行い、セキュリティインシデントや脆弱性を解決に至るまで一貫して管理します。ガバナンス・リスク・コンプライアンス(GRC)の領域では、SmartNewsにおけるセキュリティ対応の指針となる基準やポリシーを策定し、適用される法令および業界標準上の要件を確実に満たせるようにしています。また、当チームは独立したゲートキーパーとして機能するのではなく、プロダクト開発や日々の事業運営そのものにセキュリティのプラクティスを組み込むことで、ユーザー・データ・プラットフォームの保護を組織全体で共有される規律として根付かせています。
- Build and evolve Detection & Response capabilities across SmartNews infrastructure and products with a focus on detection and operational response.
- Automate response and investigations by building workflows that reduce toil (triage, enrichment, containment, evidence capture) and improve time-to-understand/time-to-contain.
- Evaluate and respond to emergent security concerns in a lab environment, such as detection and response strategies for agents operating across infrastructure at scale.
- Identify gaps in security controls, develop remediation strategies, and coordinate vulnerability management and patching across IT, and cloud systems.
- Perform comprehensive security and risk assessments across infrastructure, AI implementations, and global governance frameworks.
- Overhaul and streamline our ISMS policies, converting rigid legacy frameworks into clear, workable workflows for modern engineering and business operations.
- Manage security inquiries, partner audits, and compliance obligations (including JSOX and enterprise deal requirements) in collaboration with key business stakeholders.
- SmartNewsのインフラおよびプロダクト全体を対象に、脅威の検知と対応(Detection & Response)の体制を構築し、継続的に高度化する。
- トリアージ、情報の付加、封じ込め、証拠収集といった手作業を自動化し、状況の把握から封じ込めまでにかかる時間を短縮するワークフローを構築する。
- ラボ環境において、インフラ全体で大規模に動作するエージェントに対する検知・対応戦略など、突発的なセキュリティ課題を評価し、対策を講じる。
- セキュリティ対策のギャップを特定し、是正戦略を策定するとともに、ITおよびクラウド環境全体の脆弱性管理とパッチ適用を推進する。
- インフラ、AI導入、およびグローバルなガバナンスフレーム要件を対象に、包括的なセキュリティおよびリスク評価を実施する。
- ISMSポリシーを全面的に見直し、合理化することで、硬直した従来のフレームワークを、現代のエンジニアリングおよび事業運営に即した、明確で実用的なワークフローに置き換える。
- 主要な事業ステークホルダーと連携し、セキュリティに関する問い合わせ、パートナーによる監査、およびコンプライアンス要件(J-SOXやBtoB取引先からの要求事項を含む)への対応を取りまとめる。。
Requirements
Minimum requirements
- Japanese - Primary / English - Intermediate+
- Familiar with the enterprise AI attack surface
- Have hands-on threat detection and/or incident response experience, including building detections, running investigations, and improving operational playbooks.
- Understanding of regulatory requirements, personal data protection laws, and compliance standards
- Substantial experience in turning compliance controls into policy and scalable, auditable, operations
- Experience partnering with internal Business Process Owners to define clear security requirements and drive their practical implementation across business workflows.
- Fluent with the AI governance and compliance landscape (ISO 42001, NIST AI RMF) and how it maps onto existing GRC frameworks. The challenge is translating frontier guidance into workable internal policy without stalling adoption
- Hands-on experience running AI governance in a fast-adoption environment (MCP/tool review, acceptable-use policy, data-classification guardrails, AI related incident response). We want to hear what you’ve built and what you learned from it.
- 日本語 - ビジネスレベル / 英語 - 中級以上
- 企業でのAI活用に伴って生じる攻撃対象領域(アタックサーフェス)を理解していること
- 脅威検知およびインシデント対応の実務経験があること(検知ルールの作成、調査の実施、運用プレイブックの改善などを含む)。
- 規制要件、個人情報保護法、およびコンプライアンス基準に関する理解
- コンプライアンス上の統制(コントロール)をポリシーおよびスケーラブルで監査可能な運用へと転換した豊富な経験
- 社内の業務プロセス責任者と連携してセキュリティ要件を明確に定義し、実際の業務フローに無理なく組み込んだ経験があること
- AIガバナンスおよびコンプライアンスの動向(ISO/IEC 42001、NIST AI RMFなど)を把握しており、それらを既存のGRC(ガバナンス・リスク・コンプライアンス)の枠組みにどう対応づけるかを理解していること
- AI導入が急速に進む環境でAIガバナンスを実際に運用した経験があること(MCPサーバーや外部ツールの導入審査、利用規程の策定、データ分類に基づくガードレール、AI関連インシデントへの対応など)
Nice to have experiences/skills
- Comfortable working within the governance function and vision for a company already adopting AI aggressively. Providing judgment and options around which risks require hard gates and which need monitored guardrails. Able to correlate lived experience to influence direction from day one.
- Knowledge and practical experience in AI governance, AI risk management, and ISMS audit and certification processes
- AI活用を積極的に進めている企業のガバナンス部門での業務経験があり、当社のビジョンに共感いただけること
- どのリスクに対して厳格な制限を設けるべきか、どのリスクに対して監視体制を構築すべきかについて、適切な判断と選択肢を提示できること
- 実務経験に基づく知見を活かし、入社後すぐに組織の方向性に影響を与えられる方。
- AIガバナンス、AIリスク管理、およびISMS(ISO/IEC 27001)の監査・認証プロセスに関する知識と実務経験があること
Related Links
Working condition
- Office Location: Tokyo
Click here or visit our careers site for more info.
Benefits
Benefits available at the SmartNews Tokyo Office
- All healthcare and social insurance required by the Japanese labor law, plus annual health check
- Visa sponsorship and overseas relocation support available for eligible candidates
Click here or visit our careers site for more info about our benefits.

