Mico's mission is to empower every brand by building lifetime trust through humanlike technology. By 2030, we aim to be Asia's No.1 Brand Empowerment Company. Mico builds the conversational layer Japanese brands use to reach their customers — LINE, SMS/RCS, Voice AI and web — for more than 5,500 companies across finance, insurance, retail and real estate.
Our four core values guide everything we do:
- Wow the Customer
- Invest in Passion
- Beyond Borders
- Be the Change
Most security engineers defend a platform. You will build the agents that defend one — for 5,500+ brands in finance, insurance and retail, and for the AI that talks to their customers.
Three things make security engineering at Mico different from most product companies:
- Regulated industries set the bar, and it's a high one. Finance, insurance and real-estate clients require us to meet their regulators' standards for protecting both their data and their end users'. Data protection is a board-level subject here, not an engineering afterthought.
- We build AI products, so we secure AI products. Mico's agents act on our customers' behalf. Guardrails, tool-use authorization and adversarial testing are a discipline the whole industry is still writing the playbook for — we'd rather help write it than wait for it.
- AI-assisted development, secured. As more of our software is built with AI, securing how we build matters as much as securing what we ship.
We hold ISMS (ISO 27001) and Japan's Privacy Mark certification, and we work to OWASP and MITRE ATLAS guidance for the AI we ship. We're now investing in a dedicated product security function, designed agent-first, with executive sponsorship and a place in the company's half-year objectives. This role is the senior engineer for that function — you'll shape how it works rather than inherit how it's always been done, with a mandate and budget already in place.
Build and run the security agents. Design, build and operate the security agents on the Claude Agent SDK with MCP tool integrations, starting with PR Sentinel and DepGuard, then outward across the lifecycle.
- Wrap the scanners we buy so they become one coherent, low-noise signal rather than seven disconnected dashboards.
- Evaluate and red-team your own agents — false negatives and prompt injection against a security agent are your problem to catch.
- Automate the first response to customer security questionnaires, so an enterprise buyer gets a substantive answer in hours.
Secure what we build. Threat-model high-risk features — new data flows, AI capabilities, auth and identity changes — before code exists.
- Own SAST, secret scanning, dependency and supply-chain security in CI, with SLAs on critical and high findings.
- Run vulnerability assessment in-house: DAST, API security testing, and hands-on penetration testing of our own products.
- Review application code and API designs, and make cross-tenant isolation structurally impossible to get wrong.
- Scope and manage external specialists where they earn their cost — crown-jewel penetration tests, independent assessments — and hold their output to a standard.
- Raise the level of the engineers around you: security champions in every squad, practical training, and reference material people actually use.
- Supply the technical evidence behind our ISMS and customer audits. The certification program is owned by our security team in Japan — you make it defensible.
Secure what we ship (AI / LLM).
- Red-team Mico's own AI agents: prompt injection, jailbreaks, tool abuse, data exfiltration through model output.
- Build guardrails and regression gates so a prompt or model change cannot silently weaken defenses.
- Work to OWASP LLM Top 10 and MITRE ATLAS, and turn the results into evidence our enterprise customers can read.
Secure what we hold (Data & PII).
- Classify data, then enforce it: masking and redaction in logs, non-production and analytics — and before anything reaches a model.
- Implement just-in-time, least-privilege access across personal data, with audit trails that stand up to scrutiny.
- Build tokenization and a mediated data-access path so no service or person reads sensitive stores directly.
- Agents carry the volume. One engineer can't review every pull request, triage every advisory and re-test every AI feature by hand — you'll build the agents that do the first pass, and spend your time on the judgment calls.
- Squads own their own fixes. You won't be patching a dozen codebases yourself. Security champions are named in every squad; you build the system that makes them effective.
- You'll work directly with VPs. Our VP and security specialists in Japan will support you on roadmap, strategy and development.
- The work is sequenced, not simultaneous. Early work is coverage and classification; AI red-teaming and data-access controls come afterwards, once the foundation carries its own weight.
- The function grows with you. This is a chance to be the first member of the security team and grow that team with you — including the opportunity to become its lead in time.
- You won't run corporate IT — devices, office network, helpdesk and identity administration belong elsewhere.
- You won't own ISMS / ISO 27001 audit and evidence management — our security team in Japan owns the certification program; you support it technically.
- You won't be the compliance function — we'll set that up separately, together.
First 90 days: You take ownership of scanning coverage across our repositories (static analysis, dependency and supply-chain checks, secret detection), own data classification across our primary stores, and the threat-modelling gate that high-risk features pass through. You name the security champions in each squad and set how they work with you.
Months four to six: You own the review agent that gives every pull request an explanation and a suggested fix, and the orchestration layer that turns many scanners into one prioritized queue. You run assessment in-house — DAST, API security testing and penetration testing — alongside the external specialists we engage.
- 5–8 years in security, the majority in application or product security for a software product — not solely network or IT security.
- You write production code in Python, Go or TypeScript, and are comfortable in Shell. You've automated security work rather than only operated tools someone else built. (Non-negotiable.)
- Hands-on experience across the application security core: secure code review, threat modelling, API and web vulnerability assessment, OWASP Top 10 and API Top 10, and CVE/OSV-driven dependency and supply-chain security.
- Cloud security on AWS in practice — IAM, network boundaries, and real use of GuardDuty, Security Hub or CloudTrail.
- Security wired into CI/CD — SAST, SCA and secret scanning in pipelines you've owned, including the unglamorous work of getting developers to accept them.
- Daily practical use of AI coding agents such as Claude Code in your own work.
- Working fluency in English — our engineering organization spans more than twenty nationalities across India and Japan.
- AI / LLM security experience — prompt injection, jailbreak and tool-abuse testing; OWASP LLM Top 10; MITRE ATLAS; harnesses such as Promptfoo, Garak or PyRIT. Rare and genuinely valued — if you don't have it yet, this is the role where you'll build it.
- PII engineering at scale — classification, masking, tokenization, data-access proxies; exposure to APPI or GDPR.
- Security due diligence experience for regulated buyers — questionnaires, customer audits, trust centers.
- Certifications such as OSCP, GWAPT, or CISSP — useful signal, never a substitute for the work.
- Japanese language ability — welcome, not required.
- You'd rather build the thing that finds a hundred bugs than find a hundred bugs.
- You can look at a critical finding, say "this one isn't actually exploitable," and defend it — cutting noise is a skill we value as highly as finding issues.
- You can explain the same risk to an engineer and an executive in one conversation, and both act on it.
- You're comfortable being first.
- You standardize rather than repeat yourself, and you write things down — what you work out once should be usable by a dozen squads without you in the room.
- You can hold a gate without becoming a blocker. Shipping weekly is a company commitment; security has to make that faster, not slower.
- Ownership of a named program with executive sponsorship, a budget and a place in the company's half-year objectives — not a security wish-list you have to fight for.
- You'll build with AI, not around it. Agent engineering is the core of the job, not a side project you do after hours.
- A clear path forward — build first, grow with us, and become Lead Security Engineer by building both the solution and the team.
- Real reach — what you secure is used by more than 5,500 brands and, through them, by millions of people every day.
- A genuinely global team across India and Japan, working in English.
Four rounds. We move fast and tell you where you stand — most candidates don't get an offer, and we'd rather you learn something from the process either way.
- Screening & technical foundation — your background, and how you think about application security.
- Deep technical — a real problem from our stack: threat modelling, code review, or breaking an agent.
- Team fit — the engineers and squads you'd work alongside.
- Final — with the VP of AI Innovation & Engineering: the program, the mandate, and your first six months.
Rounds one, three and four are in English. Round two includes interviewers from our Japan security team with an interpreter present — you're not expected to speak Japanese.