マネーツリーは、「金融分野のデジタル・トランスフォーメーションを加速する包括的ソリューションを提供することにより、日本全体に永続的なポジティブな変化をもたらす」というミッションを掲げ、データとテクノロジーによって人々がよりよい金融サービスを活用できる社会を目指しています。
2025年8月には、三菱UFJ銀行(MUFG)グループの参画を受け、メガバンクの信頼性とフィンテックスタートアップの機動力を融合させた新たな成長フェーズに入り、国内唯一無二のポジションを確立。
金融データの所有者が自ら共有先を選択・管理できる「オープンバンキング」の先駆者として、私たちは今、第二の創業期を迎えています。
Role Description
Because of who our clients are, our security posture is examined continuously — by our parent group, by our enterprise clients' recurring security assessments, by our ISO 27001 certification body, and by internal risk review.
You will be responsible for that examination surface.
You are the person who reads a security requirement in Japanese, works out what it actually asks of us, finds the person inside the company who holds the answer, consults with them, and returns a defensible response on time. This is a translation role in both senses: Japanese ↔ English, and regulatory language ↔ engineering reality.
This is not a form-filling job. We use AI to handle the first draft and to search our own documentation, so the value you add is judgement, not typing. Enterprise security questions increasingly turn on real judgement calls about scope, applicability and interpretation. You will be expected to form a view and defend it, in Japanese, to sophisticated counterparties.
You will work alongside a Senior Security Engineer who is responsible for technical controls, remediation and incident response.
当社のクライアントの性質上、当社のセキュリティ体制は絶えず検証の対象となっています。親会社グループによる確認、法人顧客による定期的なセキュリティ評価、ISO 27001認証機関による審査、そして社内のリスクレビューが、継続的に行われています。
本ポジションでは、この検証対応の全体を担っていただきます。
日本語で書かれたセキュリティ要件を読み解き、それが当社に対して実際に何を求めているのかを見極め、社内で答えを持っている担当者を特定し、その担当者と協議したうえで、期限内に根拠のある回答としてまとめる——それがこの仕事の中心にあります。本ポジションは、二重の意味で「翻訳」の役割を担います。日本語と英語のあいだ、そして規制の言葉とエンジニアリングの現実とのあいだ、その両方を橋渡ししていただきます。
これは書類を埋めるだけの仕事ではありません。当社では、回答の下書きや社内文書の検索にAIを活用しています。そのため、この仕事で問われるのは作業の速さではなく、判断の質です。法
人顧客から寄せられるセキュリティに関する問いは、適用範囲・該当性・解釈をめぐる実質的な判断を要するものが増えています。ご自身の見解を持ち、専門性の高い相手に対して日本語で説
明し、必要な場面ではその見解を主張していただくことを期待しています。
技術的統制、改修対応、インシデントレスポンスを担当するシニアセキュリティエンジニアと連携して業務を進めていただきます。
What you'll be responsible for
Parent group and regulatory liaison
- Acting as our primary working contact for group-level cybersecurity governance, attending recurring syncs and periodic liaison meetings.
- Interpreting and triaging incoming requirements — questionnaires, standards updates, control
catalogues, policy briefings — most of which arrive in Japanese under short deadlines.
- Translating each requirement into concrete internal action, identifying the accountable stakeholder, and driving it to a submitted answer.
- Recurring group-level reporting and annual risk reporting cycles.
Client security assessments
- End-to-end completion of client security checklists and questionnaires — annual, biannual and ad hoc — for our banking and fintech clients.
- Managing the queue: intake, scoping, evidence gathering, internal review, submission and follow-up questions.
- Coordinating client-driven security obligations including penetration testing, threat-led testing, vulnerability assessments and threat modelling.
- Operating and continually improving our AI-assisted response workflow — drafting from curated source material and prior answers, then carefully reviewing and correcting every output before it is submitted. Keeping the underlying source material current so answer quality improves over time.
Risk management
- Running the operational risk management process: assessment, treatment planning, approval routing and monitoring.
- Determining impact and likelihood, identifying treatments, and tracking them to completion with risk owners.
- Facilitating periodic risk register reviews.
ISMS and audit
- Supporting ISO 27001 surveillance, re-certification and internal system audits: evidence preparation, control checklists, audit minutes and findings closure.
- Maintaining core ISMS documentation including the Statement of Applicability, risk register, asset register and incident register.
- Keeping information security policies current and internally consistent.
Third-party and software governance
- Running the vendor evaluation and software approval processes, including a growing volume of AI tooling requests.
- Partnering with Legal on data handling and privacy alignment, including "Privacy by Design" documentation.
親会社グループおよび規制対応の窓口
- グループ全体のサイバーセキュリティガバナンスに関する主担当として、定例ミーティングおよび定期的な連絡会議に出席していただきます。
- 質問票、基準の改定、統制カタログ、方針説明資料など、社外から届く要求事項の解釈とトリアージを行っていただきます。その多くは日本語で、かつ短い期限とともに届きます。
- 各要求事項を具体的な社内アクションに落とし込み、責任を担うべき関係者を特定し、回答の提出まで推進していただきます。
- グループ向けの定期報告および年次のリスク報告サイクルを担当していただきます。
クライアントのセキュリティ評価対応
- 銀行・フィンテック領域のクライアントから届く、年次・半期・随時のセキュリティチェックリストおよび質問票について、受付から提出までを一貫して担当していただきます。
- 受付、スコープの確定、証跡の収集、社内レビュー、提出、追加質問への対応まで、一連の案件を管理していただきます。
- ペネトレーションテスト、脅威ベースのペネトレーションテスト(TLPT)、脆弱性診断、脅威モデリングなど、クライアント起点のセキュリティ要求への対応を調整していただきます。
- 当社の既存のAI活用ワークフローを運用し、継続的に改善していただきます。整備された社内資料や過去の回答をもとに回答を作成し、提出前には必ずすべての出力を確認・修正していただきます。また、参照元となる資料を最新の状態に保ち、回答の品質を継続的に高めていただきます。
リスクマネジメント
- 評価、リスク対応計画の策定、承認ルートの管理、モニタリングまで、実務としてのリスクマネジメントプロセスを運用していただきます。
- 影響度と発生可能性を評価し、対応策を特定したうえで、リスクオーナーとともに完了まで追跡していただきます。
- 定期的なリスク登録簿のレビューを推進していただきます。
ISMSおよび監査
- ISO 27001の維持審査・更新審査、および内部システム監査を支援していただきます。証跡の準備、統制チェックリスト、議事録の作成、指摘事項のクローズまでが対象です。
- 適用宣言書、リスク登録簿、資産管理台帳、インシデント記録簿など、ISMSの中核文書を維持していただきます。
- 情報セキュリティ関連の方針類を、最新かつ整合性の取れた状態に保っていただきます。
第三者およびソフトウェアのガバナンス
- ベンダー評価およびソフトウェア利用申請の各プロセスを運用していただきます。近年はAIツールに関する申請が増加しています。
- データの取り扱いおよびプライバシー対応について、「プライバシー・バイ・デザイン」の文書化を含め、法務部門と連携していただきます。
入社後90日間
<0〜30日>
- グループのサイバーセキュリティ会議、およびクライアント評価対応1件について、一連の流れに同席していただきます。定期的に発生するコンプライアンス上の義務について、担当者と期限を含めた一覧を文書として作成していただきます。
<30〜60日>
- クライアント評価2件を、単独で提出まで担当していただきます。進行中のリスク案件を引き継いでいただきます。
<60〜90日>
- グループのサイバーセキュリティ会議に単独で出席し、当社を代表していただきます。評価対応のリードタイム短縮に向けた、優先順位付きのバックログを提示していただきます。
Required Experience
Preferred Experience
【職種 / 募集ポジション】
Senior IT Security and Compliance Specialist / シニアITセキュリティ・コンプライアンス専門職
【雇用形態】
正社員
【給与】
年収 12,000,000円 〜 13,000,000円
【勤務地】
106-0031 Tokyo, Minato City, Nishiazabu, 3 Chome−13−3 カスタリア広尾 2F
フルリモート(リモートワークを基本とし、日本国内のどこからでも勤務可能)
会社情報
【会社名】
マネーツリー株式会社
【所在地】
〒106-0031 東京都港区西麻布3-13-3 カスタリア広尾2階
【代表者】
代表取締役 ポール チャップマン
【設立日】
2012年4月23日
【事業内容】
資産管理サービス「Moneytree®︎」、財務管理サービス「Moneytree Business®︎」および金融データプラットフォーム「Moneytree LINK®︎」、融資DX「Moneytree Verify®︎」の開発・運営
【従業員数】
76名(2026年3月末時点)