English summary for screening — check the original posting before applying.
As the first security hire, you will build and lead the security infrastructure for TuneCore Japan, a music distribution service operating in over 185 countries. You will collaborate with CTO, infrastructure, and development teams to design, implement, and operate security strategies, fostering a culture of security integrated into development.
Must-haves
- Experience in application security (AppSec), cloud security (CloudSec), and incident response (IR).
- Experience with secure coding reviews, SAST/DAST tools, and vulnerability assessments.
- Experience with AWS/GCP IAM design and network security.
- Experience with CI/CD pipeline security automation (Shift Left / DevSecOps).
- Experience with security incident detection, triage, and response.
- Experience with security policy and internal regulation development.
Nice-to-haves
- Experience with AI agent platforms and LLM APIs.
- Experience with CSPM tools.
- Experience with Terraform/CDK for IaC security reviews.
- Experience building SIEM and log monitoring infrastructure.
- Experience developing security education for developers.
- Experience with ISO 27001 / SOC 2 compliance.
Tech stack
TypeScriptGoReactNext.jsNode.jsOpenAPIAWSGCPScrumGitHubNotionClaude CodeGitHub Copilot
Work style
Onsite (implied by collaboration with internal teams and focus on organizational adoption, though specific location not stated)
Other notes
Salary is negotiable.