# Senior Security Analyst

> KOMOJU · Musashino, Japan (Hybrid) · Full-time · Posted 2026-09-08

**Workplace:** hybrid

**Department:** Engineering

## Description

### **About KOMOJU**

KOMOJU is the leading cross-border payment gateway for Japan. We power payments for companies like video game distribution platform Steam and the popular mobile app TikTok. Today we help thousands of merchants by providing them with the payment infrastructure they need through developer-friendly API’s to integrations on popular platforms like Shopify and Wix; we help our merchants grow in all markets they are expanding.

### **About the position**

We are a payment processor that handles very sensitive data for both our merchants and their customers. As we grow we need to make sure that our security is excellent and that our customer’s data is secure.

We are seeking a skilled and motivated Senior Security Analyst to serve as a technical anchor of our security operations team. You'll lead investigations into complex threats, build the detections that catch them earlier next time, and raise the bar for how the whole team responds to incidents.

This is a hands-on role for someone who has outgrown pure alert triage and wants ownership: of detection quality, of incident outcomes, and of mentoring the analysts around you.

### **What you'll do**

-   Lead investigation and response for high-severity security incidents, from initial detection through containment, eradication, recovery, and post-incident review.
-   Design, tune, and maintain detection logic across our SIEM, EDR, and cloud security tooling, and retire the rules that generate noise instead of signal.
-   Conduct proactive threat hunts based on threat intelligence, adversary TTPs, and anomalies in telemetry.
-   Perform forensic analysis of endpoints, network traffic, and cloud environments to determine scope and root cause.
-   Write and maintain runbooks, playbooks, and post-incident reports that make the next response faster.
-   Partner with engineering and IT teams to close gaps surfaced by incidents and hunts, and to improve logging and telemetry coverage.
-   Automate repetitive response steps through SOAR (Security Orchestration, Automation, and Response) workflows or scripting.
-   Mentor junior analysts on investigation methodology, tooling, and escalation judgment.
-   Contribute to tabletop exercises, purple team engagements, and control validation.
-   Support audit and compliance evidence requests as they relate to security monitoring and incident response.

## Requirements

### **What we're looking for**

-   5+ years of experience in security operations, incident response, threat hunting, or a closely related cybersecurity function.
-   Experience managing outsourced SOC providers, including setting expectations, overseeing performance, and ensuring effective monitoring and incident response.
-   Proven ability to build and scale security operations teams, including defining processes, roles, workflows, and operating procedures.
-   Deep hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel, or Elastic, including developing, tuning, and maintaining detection content.
-   Strong expertise with EDR solutions and endpoint forensics, with the ability to investigate and respond to sophisticated endpoint threats.
-   Strong understanding of attacker techniques and tradecraft, including practical application of frameworks such as MITRE ATT&CK.
-   Solid technical foundation in networking, Windows and Linux operating systems, authentication, and identity management.
-   Scripting and automation skills using Python, PowerShell, or similar languages to support security analysis, investigation, and operational efficiency.
-   Excellent written and verbal communication skills, with the ability to clearly explain security incidents and technical risks to both engineering teams and executive stakeholders.
-   Strong judgment and decision-making skills, particularly when operating under pressure, during active incidents, and with incomplete or ambiguous information.

### Nice to Haves

-   Experience securing cloud environments (AWS, GCP or Azure), including cloud-native logging and detection.
-   Familiarity with containers and Kubernetes security.
-   Experience with SOAR (Security Orchestration, Automation, and Response) platforms and detection-as-code workflows.
-   Malware analysis or reverse engineering experience.
-   Certifications such as GCIA, GCIH, GCFA, OSCP, CISSP, or equivalent practical experience
-   Exposure to compliance frameworks relevant to our business (SOC 2, ISO 27001, PCI DSS, HIPAA).

### **Who You Are**

-   **Challenge the Status Quo:** Builds KOMOJU’s security operations capability from the ground up, continuously improving detection, response, and automation.
-   **Impact Driven:** Prioritizes measurable risk reduction by improving detection coverage, reducing false positives, accelerating incident response, and building an audit-ready security operations model that protects customers and supports KOMOJU’s growth.
-   **Frontline Decision-Making & Ownership:** Takes end-to-end ownership of security incidents, making timely, proportionate decisions under pressure and following through to resolution.
-   **Obsession with Customer Value:** Protects the sensitive payment and personal data entrusted to KOMOJU, strengthening merchant confidence and service reliability.
-   **Multiplier:** Partners with Engineering, SRE, IT, Compliance, and external SOC providers while sharing knowledge that improves security capability across the organization.

## Benefits

-   10 days regular vacation, additional 5 days summer, and year-end holidays.

-   Paid birthday holiday.
-   Budget for self-learning allowance, to ensure our employees’ skills remain current.
-   Access to the O’Reilly Learning Platform.
-   Language training for Japanese/ English
-   Twice a week office lunch.
-   Learning allowance.

_By submitting your application, you agree that your personal data will be processed in accordance with our Privacy Policy solely for recruitment and evaluation purposes._

## Apply

[Apply at KOMOJU](https://apply.workable.com/komoju/j/87F33CD063/apply)

---
Powered by [Workable](https://www.workable.com)
