Security Engineer (Product Security) - Mercari

Security Engineer (Product Security) - Mercari
Mercari, inc., Japan

Experience
1 Year
Salary
0 - 0
Job Type
Job Shift
Job Category
Traveling
No
Career Level
Telecommute
Qualification
As mentioned in job details
Total Vacancies
1 Job
Posted on
Oct 9, 2022
Last Date
Nov 9, 2022
Location(s)

Job Description


JD in Japanese follows. JD


Introduction
Our Mission

Mercari is a Japan-based company with the mission of create value in a global marketplace where anyone can buy amp; sell. Having continuously worked toward this goal since our founding in 2013, we are now transforming from a startup into a global player. While this transformation brings its own specific set of challenges, we believe that solving them one after another will allow us to fully achieve our mission. Are you interested in working together to take on these exciting challenges?


Our CultureMercari’s culture has been central to the company since our founding, with the three core values of Go Bold, All for One, and Be a Pro. In addition, the Trust amp; Openness value was introduced to embody our culture of mutual trust, where information remains transparent and rules are kept to a minimum. Regardless of how big Mercari gets, our culture is essential to achieving our mission and will be promoted throughout our organization.


Position Overview


Work Responsibilities
  • Mercari is looking for a security engineer to join our Product Security Team in Tokyo. The Product Security Team ensures that Mercari products meet security requirements and investigates, tracks, and assists in fixing security issues. The team strives to be a business enabler working on a variety of tasks and applying a risk-based approach to security-related decision making.
  • As a Product Security Engineer you will be responsible for eliciting and communicating security requirements to product teams, performing threat modeling, design reviews, and security testing. You will also be involved in evaluating, designing, developing, and deploying automated security assessment solutions (DAST, SAST, SCA, etc.) and take on the challenge of ensuring the safety of Mercari’s development lifecycle.


Bold Challenges
  • Work with a modern, cloud-first development and deployment environment.
  • This position will allow you to take full advantage of your skills and experience because you will work on a variety of projects ranging from an online marketplace to payments and IoT.
  • Mercari offers a multicultural environment with colleagues from over 40 different countries and various backgrounds (experiences and skills), so you will be able to discuss and address issues from different perspectives and use that for personal growth.
  • *See this page for details


Roles and Responsibilities
  • Review product designs to define necessary security requirements based on threat modeling.
  • Review proposed architecture and propose a set of security controls in order to minimize risk.
  • Review source code to find security problems and potential vulnerabilities.
  • Conduct vulnerability assessments and penetration testing on Mercari’s Web, iOS, and Android applications.
  • Automate security checks and tests so that they can be easily and transparently plugged into the CI/CD pipeline.
  • Develop technical solutions to help mitigate security vulnerabilities.
  • Maintain technical and security standards for Web and mobile application technologies.
  • Educate developers on secure coding practices with workshops, talks, and lessons.
  • Evaluate and investigate suspected security events or incidents and perform remediation in accordance with Incident Response procedures.
  • Collaborate with information security officers, the legal team, and internal auditors on technical security matters.


Required Experience

  • Bachelor's degree or equivalent practical experience.
  • Programming experience with one or more programming languages including but not limited to: Go, PHP, Java, Ruby, Python, C/C++, Objective-C, Swift, Kotlin, or JavaScript.
  • 2+ years of experience analyzing the security of systems (penetration testing, Web application security testing, vulnerability scanning, threat modeling, etc.).
  • Good understanding of modern Web application architecture, TLS, HTTP, TCP/IP, and standard network and system security technologies.
  • Experience with modern software development tools, such as distributed version control systems (git), dependency management, build systems, and CI/CD pipelines.
  • Strong teamwork skills in a diverse environment.
  • Effective interpersonal and communication skills.


Preferred Experience
  • In-depth technical knowledge of security engineering, computer and network security, Unix-based operating systems, mobile security, authentication, security protocols, and applied cryptography.
  • Strong experience in securing both backend (Go, PHP) and frontend (Web, JavaScript, iOS, Android) applications.
  • Good understanding of development methodologies such as Object-oriented Programming (OOP

Job Specification

Job Rewards and Benefits

Mercari, inc.

Information Technology and Services - Minato City, Tokyo, Japan
© Copyright 2004-2024 Mustakbil.com All Right Reserved.