Vendor Information Security – Japanese Bilingual
Vendor Information Security – Japanese Bilingual
Job Type: Permanent / Direct Hire
Location: Quezon City
Work Setup: Hybrid – 3 days onsite, 2 days WFHShift: Day Shift
About the Role
We are looking for a Vendor Information Security - Japanese Bilingual to join an existing team supporting information security and third-party risk management activities in Japan.The successful candidate will be responsible for assessing and managing information security risks related to vendors and third parties, reviewing security and audit documentation, and supporting security governance initiatives. This role is ideal for someone with strong experience in Vendor/Third-Party Risk Management, Information Security Governance, and Security Risk Management, rather than SOC operations.
Key Responsibilities:
- Manage and assess vendor and third-party information security risks.
- Conduct security risk assessments and review vendor security controls and practices.
- Review and analyze audit reports, vulnerability management reports, and other security-related documentation.
- Support Vendor Risk Management and third-party security governance processes.
- Identify, assess, and document information security risks and potential control gaps.
- Support compliance and security governance activities aligned with industry standards.
- Apply knowledge of ISO 27001 and information security management practices.
- Coordinate with internal stakeholders and vendor representatives regarding security requirements and assessments.
- Work closely with the existing team in Japan and communicate with Japanese stakeholders.
- Prepare and maintain accurate security risk and assessment documentation.
- Provide support for continuous improvement of vendor security and risk management processes.
- Relevant experience in Information Security, Vendor Risk Management, Third-Party Risk Management, Security Risk Management, or Information Security Governance.
- Strong experience in Vendor/Third-Party Risk Management.
- Experience reviewing audit reports and vulnerability management reports.
- Working knowledge of Information Security Governance and Security Risk Management.
- Knowledge of ISO 27001 is required, particularly for senior-level candidates.
- Japanese bilingual proficiency is required.
- JLPT N2 or N3 certification is accepted.
- Strong Japanese speaking, reading, and writing skills.
- Strong analytical, documentation, and stakeholder management skills.
- Able to work effectively with teams and stakeholders based in Japan.
- Willing to work in a hybrid setup – 3 days onsite and 2 days WFH.
- Candidates who can start ASAP are highly preferred.
Benefits
- Health insurance
- Do you have experience reviewing vendor security assessments, audit reports, vulnerability management reports, or similar security documentation? Please briefly describe.
- Do you have experience with Information Security Governance and/or ISO 27001? Please indicate your level of experience.
- What is your current Japanese proficiency level? (JLPT N2 / JLPT N3 / Other)
- Are you comfortable speaking, reading, and writing in Japanese as part of your daily work?
- What is your current/most recent basic salary and expected basic salary?
- How soon can you start if selected?
- Are you willing to work on a hybrid setup?
- Bachelor's (Preferred)
- Vendor/Third-Party Risk Management: 3 years (Preferred)
- Information Security Risk Management: 3 years (Preferred)
- Japanese Bilingual: 3 years (Preferred)