Job Duties
- Automate security controls and monitoring across Mercari’s platform to enable secure-by-default operations.
- Develop technical solutions to prevent or mitigate security vulnerabilities and strengthen overall system security.
- Maintain technical and security standards for production and corporate infrastructure services.
- Collaborate with security management, legal, and internal auditors on technical security matters.
- Work with platform engineering teams to balance security with other requirements.
- Review architecture proposals (infrastructure, data flows) and propose security controls to minimize risk.
- Operate in a “security as code” mindset, emphasizing automation and scalable security practices.
Technical Stack
Essential Skills
- Solid grasp of core security concepts (CIA, least privilege, authentication vs authorization, cryptography, secure protocols, application security).
- Practical use of Git, GitHub, CI/CD (GitHub Actions), and shell scripting.
- Programming experience in Go, Python, or TypeScript.
- Experience with cloud platforms (GCP, AWS, Azure), containers (Docker, Kubernetes), and Infrastructure as Code (Terraform).
- UNIX-like systems administration and hardening; proficient with POSIX utilities.
Nice-to-have Skills
- 4+ years in security roles;Bachelor’s in Computer Science or equivalent.
- Familiarity with cloud/web app architecture and Secure SDLC (SLSA).
- SQL knowledge (BigQuery, Postgres); cryptography concepts (key management, TLS, KMS, PKIs).
- Networking knowledge (TCP/UDP, DNS, HTTP); identity federation (OIDC, SAML).
- PCI-DSS or similar standards; Japanese (basic) and English (independent) language skills.
Career Growth Perspective
- Opportunity to shape security across a large platform, gaining impact at scale and exposure to cutting-edge cloud and automation technologies.
- Strong emphasis on “security as code” and automation, accelerating growth in SecDevOps, cloud security, and IaC disciplines.
- Cross-functional collaboration with security, legal, and product teams, providing broad governance, risk, and compliance experience.
- Clear path toward senior/lead security engineering, security architecture, threat modeling, and incident response roles, with potential for multi-cloud specialization and language skills development.
企業についての所感
シリコンバレー企業に近い文化の日本企業。年収レベルも他のメガベンと比べて高い。まともに昇進すれば1000万円超。テックなイメージはあるが、プロダクト指向が強い企業で選考でアプリの使用経験なども聞いてくる。システムデザインの面接があり対策推奨。
データ取得日: 2026/9/10
面接に向けて、考え方と伝え方を学習コンテンツで整理しましょう。
面接対策コンテンツを見る