Vulnerability Management Analyst

Remote

PayPay

PayPayは、スマホひとつでカンタン・おトクにお支払いができるアプリです。最短1分で登録完了!街のお店をはじめ、ネットサービスや請求書のお支払いなどにもご使用いただけます。

View company page

About PayPay

PayPay, a fintech company, that achieved more than 47M users within around 3.5 years since its launch in 2018 has hugely diversified employees who are from 40 different countries. To build "PayPay", we allied with Paytm, the biggest payment service company in India. Based on their customer-first technologies , we created and expanded the smartphone payment service in Japan.

Our biggest competitor is "cash". We are seeking for people who can accept this challenge positively, brush up the product at a tremendous speed that other companies could never achieve, and who are passionate about promoting and spreading such a financial life platform in a short time along with professionalism.

Job Description

PayPay DevSecOps is seeking a vulnerability management analyst  to direct our development and operations teams on maintenance and improvement of our services security.

PayPay DevSecOps focuses on supporting our teams through discovery, knowledge sharing and the automation of security configuration, testing, verification and monitoring. A strong candidate for Vulnerability Management Analyst will have a good understanding of software and infrastructure vulnerability detection, management and remediation. 

Primary Responsibilities

  • Working closely with CSIRT and Security Champions to track current security risks and mitigations

Main Responsibilities

  • Maintaining an up-to-date view of known vulnerabilities and their remediation status
  • Maintaining automated systems to assist teams with tracking current security status
  • Provide guidance to team members on methods of identifying mitigating vulnerabilities
  • Working with CSIRT and senior management to track progress on incident response
  • Working in a fast-paced environment where projects and prioritization may change frequently but maintaining a secure product is a requirement for all team members

Qualifications

  • Minimum of five years of demonstrated, security focused experience
  • Experience leading projects tasked with cross team vulnerability assessment and management
  • Minimum of three years experience with: 
    • DefectDojo or other vulnerability management tools
    • Crowdstrike
  • Demonstrated proficiency in python
  • Native or business level English proficiency

Preferred Qualifications

  • Experience with AWS SecurityHub and SSM
  • ArgoCD, Github Actions, Jenkins, Snyk, CodeQL
  • Neo4J
  • Native or business level Japanese proficiency

PayPay 5 senses

Working Conditions 

Employment Status

  • Full Time

Office Location

Work Hours

  • Super Flex Time (No Core Time)
  • In principle, 10:00am-6:45pm (actual working hours: 7h45m + 1h break)

Holidays

  • Two days off per week (as well as national holidays, New Year's break(December 29th to January 4th))
  • Paid leave, congratulatory and bereavement leave, maternity/paternity leave, family care leave etc

Salary

  • Annual salary paid in 12 installments (monthly)
  • Based on skills, experience, and abilities
  • Reviewed once a year
  • Special Incentive once a year *Based on company performance and individual contribution and evaluation
  • Late overtime allowance, Work from anywhere allowance (JPY100,000)

Benefits

  • Social Insurance (health insurance, employee pension, employment insurance and compensation insurance)
  • 401K
  • Language Learning support
  • Translation/Interpretation support
  • VISA sponsor + Relocation support

Other Information:

        ・Tech Talks Series

    ・ PayPay Professionals Series

    ・ WFA (work from anywhere, at anytime) series

Tags: Automation AWS CodeQL CSIRT DevSecOps FinTech GitHub Incident response Monitoring Neo4j Python Vulnerabilities Vulnerability management

Perks/benefits: 401(k) matching Career development Health care Parental leave Relocation support

Region: Remote/Anywhere
Job stats:  31  5  1
Category: Analyst Jobs

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.