
Sophos · Japan
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organization...
About Us
Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response.
Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats.
Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.
Role Summary
ソフォスは、日本を拠点とする「Sophos Red Team」のリーダーを募集しています。このポジションでは、確立された実績を持つ、高いパフォーマンスを発揮する攻撃的セキュリティの専門家チームを率いていただくことになります。当社の文化は、謙虚でありながら情熱に満ち、高度な技術力を持ち、サイバーセキュリティへの情熱を共有するプロフェッショナルたちが融合した、ユニークなものです。このリーダーシップポジションでは、APJ北/日本担当ディレクターと緊密に連携し、グローバルなプラクティスリーダーや他の部門横断的なパートナーと協力して、卓越したサービス提供を実現していただきます。理想的な候補者は、攻撃的セキュリティチームを率いた経験を有していることが求められます。ビジネスリーダーとして、この役職は特定のプラクティス指標(収益、利益率、NPS/顧客満足度など)の達成に責任を負い、営業、マーケティング、その他の組織と緊密に連携してプラクティスの成長を支援します。これは戦略的なリーダーシップポジションであり、チームミーティング、全社ミーティング、戦略会議、その他のワークショップを通じて、現地での強力なリーダーシップを発揮し、チームの成果が顧客を満足させ、最先端であることを保証する必要があります。
Sophos is looking for a Japan based leader on the Sophos Red Team in Japan to lead a well-established, high performing team of offensive security professionals. Our culture is a unique mix of low ego – high energy, highly technical, and motivated professionals with a passion for cybersecurity. This leadership position will partner closely with the Director of APJ North/Japan and will work collaboratively with global practice leadership and other cross-functional partners to achieve service delivery excellence. The ideal candidate will have experience leading offensive security teams. As a business leader this role will be responsible for achieving select practice metrics (Revenue, Margin, NPS/customer satisfaction, etc.) and partner closely with sales, marketing and other organizations to help grow the practice. This is a strategic leadership position which requires strong local leadership presence through team meetings, all hands, strategy sessions, and other workshops to ensure the team’s delivery is customer delighting and at the bleeding edge.
About Us Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com. Role Overview ソフォスのインシデントレスポンスチームでは、アドバイザリーサービス事業を拡大するため、各チームやインシデントレスポンス/レディネスコンサルタントと連携するシニアマネージャーを募集しています。インシデントレスポンスシニアマネージャーは、アドバイザリーサービス事業内のIRマネジメントチーム、IRチームリーダー、インシデントレスポンダー、インシデントレディネスコンサルタントと協力し、コンサルティング業務全般を統括します。業務内容は、予防的な取り組み(能力構築や脅威ハンティングなど)から、事後対応としてのインシデント/侵害対応まで多岐にわたります。サービス提供の質向上やコンサルティングスキルに関するチームメンバーへの指導、および顧客と直接連携して課題や障害を解決することも、この役職の重要な役割です。候補者には、契約案件への従事(請求可能業務の割合は最低15%)が求められます。 採用候補者には、インシデント対応能力の開発、管理、運用、トレーニング、演習、ワークショップの実施経験が求められます。また、脅威アクターが一般的に使用する戦術、手法、手順に精通している必要があります。組織がインフラやデータのセキュリティを確保しようとする際に直面する要因や制約について熟知していることが不可欠です。オンコール(プライマリ/サポート)対応が求められます。 The Sophos Incident Response team is looking for a Senior Manager who will work with various Sophos teams and Incident Response\Readiness consultants to grow the Sophos Advisory Services practice. The Incident Response Senior Manager will work with the IR management team, IR team leads, incident responders, and incident readiness consultants within the Sophos Advisory Services practice to oversee all consulting matters. Deliverables may be proactive (e.g. capability building or threat hunting) or reactive incident/breach response. Mentoring team members on service delivery excellence and consulting skills, as well as working directly with customers to resolve any blockers/issues, is a key component of the role. The candidate will be expected to work on engagements with a minimum requirement of 15% billable work. The successful candidate will have experience in developing, managing, and operating incident response capabilities, conducting training, exercises, and workshops, and will be familiar with tactics, techniques, and procedures commonly employed by and used to thwart threat actors. Familiarity with the drivers and constraints that organizations are working with and against while trying to secure their infrastructure and data is a necessity. On call (primary / support) is required.
About the Team The Senior Manager of Application Security leads a global team responsible for embedding security into Miro’s Software Development Lifecycle (SDLC)—from concept to code to customer impact. This team partners closely with product and engineering to proactively mitigate risk while accelerating developer velocity and innovation.The role focuses on enabling secure-by-default development through secure design support, automated tooling, vulnerability management, offensive testing, and developer engagement. It also plays a critical role in integrating security into Miro’s Discover, Define, Deliver product lifecycle and aligning with our AMPED Ways of Working (Analytics, Marketing, Product, Engineering, Design) and AMPED Operating Model. As Miro embraces AI-supported software development and explores Agentic AI workflows that empower engineers, product teams, and security teams alike, this role will contribute to adapting and securing those evolving working methods—ensuring that innovation and trust go hand in hand. About the Role As Senior Manager of Application Security, you will define and operationalize Miro’s application security strategy in alignment with our industry-leading software development lifecycle and AMPED framework. You will lead a multidisciplinary team of application security engineers and offensive security specialists who work directly with developers, product teams, and platform engineering across multiple regions. You will embed security into all phases of the product lifecycle—from early discovery and architecture threat modeling, to design reviews and secure delivery pipelines, and ongoing monitoring and testing post-release. Your team will also support Miro’s AI-driven development tooling and guide secure adoption of Agentic AI workflows, which enable both developers and security teams to collaborate more efficiently and proactively. The role requires a pragmatic, hands-on leader who thrives in fast-moving environments and has a deep understanding of both software engineering and security, as well as a passion for empowering teams to build securely and autonomously. What you’ll do * Lead and mentor a globally distributed team of security engineers focused on application security, offensive testing, secure architecture, and vulnerability remediation. * Lead and coordinate the team's initiatives and help provide project management leadership to the team members. * Coordinate cross function and cross stream initiatives and projects. * Drive integration of security into Miro’s Discover, Define, Deliver lifecycle through the lens of the AMPED Ways of Working and Operating Model. * Collaborate with Product, Engineering, and Design to ensure security is considered at the earliest stages of ideation—via threat modeling, risk reviews, and abuse-case analysis.Shape and evolve Miro’s Secure SDLC practices, integrating security seamlessly into CI/CD pipelines, infrastructure-as-code, and developer tooling. * Oversee execution of bug bounty and third-party testing programs, ensuring vulnerabilities are triaged, communicated, and remediated effectively. * Build and scale Miro’s Security Champions program to embed security ownership within each engineering team. * Guide secure adoption of AI-augmented software development tools, including LLMs used for code generation, reviews, or architectural assistance. * Help envision and safely operationalize Agentic AI-driven developer and security workflows, including policy-driven autonomous agents supporting security automation and decision-making. * Provide structured guidance, patterns, and reference architectures that support developers in implementing secure, scalable, and privacy-respecting features. * Define and report on KPIs and success metrics for secure development adoption, vulnerability resolution, and developer engagement. * Collaborate with Privacy, Legal, and Compliance teams to ensure alignment with regulatory requirements (ISO 27001, SOC 2, GDPR, and emerging AI regulations). * Foster a strong team culture based on collaboration, learning, and continuous improvement. What you’ll need * 10+ years of experience in software, application, or product security, including significant experience in secure software development. * 3+ years of technical leadership or management experience in a security-focused role. * Extensive experience with threat modeling methodologies (e.g., STRIDE, PASTA) and risk assessment, particularly within a SaaS or product-centric organization. * Deep expertise in Secure Software Development Lifecycles (SSDLC), including integrating security into agile and custom development frameworks. * Demonstrated experience running Security Champions programs and scaling developer engagement. * Experience leading offensive security programs (penetration testing, red teaming, bug bounty). * Practical understanding of governance and assurance frameworks such as ISO 27001, SOC 2, and OWASP SAMM. * Familiarity with AI/LLM tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations) and the associated security and governance considerations. * Experience working with AWS and securing API-driven, microservice-based architectures. * Ability to manage distributed teams and communicate effectively across technical and business stakeholders. Who You Are (Skills & Attributes) * Developer-Aligned: You understand the pace and pressure of modern software development and are committed to reducing friction while improving security posture. * An Exceptional Communicator: You can articulate complex technical risks to non-technical stakeholders and translate business goals into security strategy for your team. * A Natural Collaborator: You excel at building strong relationships and influencing cross-functional teams without direct authority. * A Pragmatic Problem-Solver: You are skilled at identifying scalable, risk-based solutions and are comfortable navigating ambiguity in a fast-paced environment. * Data-Driven: You use metrics and KPIs to measure the effectiveness of your programs and drive continuous improvement. * A Passionate Mentor: You are dedicated to developing talent and empowering engineers and product managers to be security champions. Why Join Miro’s Security Team? As a member of Miro’s security leadership, you’ll help define how innovation and trust scale together. You’ll work across the AMPED operating model, empower developers through secure tooling, and support cutting-edge AI-driven and agentic workflows that redefine how software and teams are built. If you thrive on technical depth, cross-functional collaboration, and advancing the next era of secure software development, this role is for you. What's in it for you We want you to feel supported, connected, and ready to grow. Our global benefits package generally includes equity, a wellbeing benefit, a WFH equipment allowance, and an annual Learning & Development stipend. Join a diverse team where you can do your best work. Full benefits may differ per location. If you would like to learn more about location-specific benefits, please refer to our Global Miro benefits board.
PROSEC Wir bei ProSec wissen genau, was wir für #CyberSecurity erreichen wollen und was wir dafür tun müssen. Unsere Vision ist es, IT-Security viral gehen zu lassen, um Menschen und Werte nachhaltig vor Cyber-Bedrohungen zu schützen. Hierfür etablieren wir neue Standards im Penetration Testing, im IT-Security-Consulting sowie in der Ausbildung und Förderung von Nachwuchstalenten in diesen Fachbereichen. Wir bieten den Besten unserer Branche ein berufliches Zuhause, das von echtem Zusammenhalt und Rückhalt geprägt ist. Unsere Expertise und Leidenschaft teilen wir mit einer aktiven Community, um den digitalen Raum für uns alle dauerhaft sicher zu gestalten. DEINE ROLLE Fokus: Momentum, Umsetzungskraft, technische Exzellenz Als Professional bist du der Möglichmacher in unseren Teams. Du steigst genau dort ein, wo viele Kunden innerlich schon kapitulieren – weil Themen technisch komplex wirken, weil alte Baustellen sie erschlagen oder weil niemand weiß, wo man anfangen soll. Und genau da brillierst du: Mit Struktur, technischem Verständnis und echter Begeisterung schaffst du Klarheit, Ordnung und Fortschritt. Du bringst Projekte ins Rollen, nimmst Kunden an die Hand und sorgst dafür, dass aus einer unübersichtlichen To-Do-Liste ein realistisch machbarer Plan wird. Kurz: Du bist derjenige, der Dinge möglich macht, die vorher niemand für möglich hielt. WAS DU BEI UNS MACHST * Du verwandelst chaotische, technisch herausfordernde Situationen in klare, machbare Schritte * Du führst Kunden durch komplexe Security-Themen – mit Ruhe, Kompetenz und Struktur * Du schaffst echte Fortschritte: Wo andere doppelt so lange brauchen, lieferst du in kürzerer Zeit mehr Wirkung * Du arbeitest nah an der Technik: Analysen, Maßnahmen, Validierungen, technische Umsetzung * Du bringst Energie ins Projekt: Mitdenken, pro aktive Arbeitsweise, Kunden motivieren * Du arbeitest eng mit Senior & Manager zusammen, um Roadmaps und technische Wege umzusetzen WAS WIR NICHT SUCHEN * Problemzähler – wir brauchen Menschen, die Lösungen finden * Personen, die nur abarbeiten – wir wollen, dass du Projekte mitgestaltest * Sicherheits-Fans ohne Tiefgang – bei uns zählt Kompetenz, nicht Buzzword-Bingo * Menschen, die Verantwortung abgeben anstatt übernehmen WAS UNS WICHTIG IST * Technische Leidenschaft und Begeisterung * Drang, Dinge zu ordnen und effizient umzusetzen * Klarheit in der Kommunikation * Strukturiertes Vorgehen – auch wenn es brennt * Lust, den Kunden stärker zu machen, nicht abhängig WAS DU MITBRINGST * OSCP oder vergleichbare technische Zertifizierung * Erfahrung als Pentester oder als Admin/System Engineer mit Security-Fokus * Spaß an Hands-on-Umsetzung und echter Problemlösung * Den Drive, auch schwierige Themen einfach und machbar zu gestalten * Bereitschaft, dich von unseren Seniors weiterentwickeln zu lassen WAS DU ERWARTEN KANNST * Echte technische Arbeit statt Folien-Arbeit * Kunden, die deine Unterstützung wirklich brauchen – und sie wertschätzen * Eine Kultur, die deinen Einsatz sieht und fördert * Klare Entwicklung: Professional → Senior Consultant * Verantwortung, Sichtbarkeit, Wirkung Wenn du Lust hast, Projekte ins Rollen zu bringen und Kunden dort zu helfen, wo sie allein aufgeben würden – dann bist du bei uns richtig. Zeig uns deinen Drive. Bewirb dich.