Enthought

DevOps・情報セキュリティ マネージャー / Manager, DevOps & InfoSec

Enthought Tokyo, Japan

Software Development · 51-200 employees

10 h ago
devops Senior (5-10 yrs) Full-time Japan
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Lead the design, deployment, and operation of cloud infrastructure while owning the end-to-end information security posture for the company. Act as the primary technical contact for major enterprise customers in Japan, managing security risks and IT operations for the Tokyo office.

What they look for

DevOps Information security Cloud architecture Microsoft Azure AWS Infrastructure as code CI/CD pipelines Identity and access management Incident response Automation Risk management Network troubleshooting Security hardening Python Machine learning Scientific computing

Requirements

Requires business-level fluency in both Japanese and English to communicate technical concepts to diverse stakeholders. Candidates must possess deep expertise in cloud architecture, security standards, and automation, with a hands-on approach to infrastructure and incident management.

Benefits

Competitive compensation Flexible hybrid work Continuous learning Training programs

Full description

このポジションについて

顧客ソリューションを支えるクラウドインフラの構築・運用をリードし、あわせて Enthought の情報セキュリティ体制を一貫して担う Manager, DevOps & InfoSec を東京オフィスで募集します。自ら手を動かすプレイングマネージャーの役割です。業務比率の目安は、DevOps 約 45%、情報セキュリティ約 30%、東京オフィスおよび国内導入済みアカウントの IT・サポート運用約 25% です。当社の最大規模の顧客は日本の大手企業であり、本ポジションはインフラとセキュリティに関するお客様の一次窓口となります。そのため、日本語・英語ともにビジネスレベルの運用能力が不可欠です。当社のセキュリティ業務は、監査・コンプライアンス主導ではなく、実践的に手を動かすスタイルです。全社的なセキュリティ基準の策定から、東京オフィスのネットワークや端末のトラブル対応まで、1 週間のうちに扱う領域は非常に幅広く、この幅を面白いと感じられる方に向いています。

主な職務

  • インフラとセキュリティのエンドツーエンドの設計をリードします。クラウドアーキテクチャ、自動化、情報セキュリティに関する深い知見を活かし、顧客およびビジネスの要件を、インフラ・デプロイ・ID 管理・運用にまたがるアーキテクチャへと落とし込みます。
  • 顧客ソリューションを支えるインフラの設計・構築・運用をリードします。Infrastructure as Code、CI/CD パイプライン、デプロイ自動化、オブザーバビリティ、クラウドコストの最適化までを担当します。主に Microsoft Azure、一部 AWS を使用します。
  • Enthought の情報セキュリティ体制のオーナーとして、社内システム、製品インフラ、顧客環境に適用するセキュリティ基準・ポリシー・構成ベースラインを定義し、維持し、その実効性を担保します。
  • セキュリティリスク管理台帳のオーナーを務めます。リスクを特定し、定量化し、優先順位をつけ、自らの権限を超えるリスク受容の判断は、明確な推奨とともに VP, Technology & Professional Services に上げます。
  • ID/アクセス管理アーキテクチャのオーナーとして、権限モデル、最小権限設計、特権アクセス管理、認証標準を設計し、運用が従うべき基準を定めます。
  • セキュリティインシデント対応を一貫してリードします。検知、トリアージ、封じ込め、根絶、復旧、事後レビューまでを担い、インシデント対応計画の維持と訓練の実施も行います。
  • ソフトウェア・ライブラリ・ツールの承認を判断します。自動化されたライセンス・プライバシー・脆弱性評価をもとに意思決定を行い、新規性の高いライセンスや知的財産、契約上の論点は契約管理部門にエスカレーションします。
  • エージェントファーストに働きます。AI コーディングアシスタントおよび自律型エージェントを、インフラの構築とレビューにおける標準的な手段として活用し、定型業務にエンジニアの時間を使わずに済むよう、安全に自動化できる領域を広げ続けます。
  • エージェント型および自動化された運用に対するセキュリティガードレールを策定します。自動化システムが保持できる認証情報の範囲、その保持期間、監査証跡、そして影響範囲を定義します。
  • 顧客対応におけるセキュリティエスカレーション先および一次技術窓口を務めます。セキュリティチェックシート、デューデリジェンス、アーキテクチャに関する協議、インシデント照会に対応し、契約上の確約に関わる事項は契約管理部門を通します。営業・カスタマーサクセスがセキュリティ体制を説明する際の支援も行います。
  • デプロイ時のセキュリティ基準と、顧客環境のハードニング指針を策定します。コンサルティングチームが用いる標準を定め、顧客向けの導入が最初から最後まで安全に実行される状態をつくります。
  • DevOps の実務にセキュリティを組み込みます。シークレット管理、依存関係・脆弱性管理、コンテナおよびランタイムのハードニング、Infrastructure as Code のレビューを含みます。
  • お客様のエンジニアリングチームに対して、インフラ自動化と引き継ぎを助言・支援します。手動構成から Infrastructure as Code への移行も含みます。
  • 東京オフィスおよび国内の導入済みアカウントに対する IT・サポート運用のオーナーを務めます。入退社時の対応、端末とハードウェアのライフサイクル、オフィスのネットワークと技術環境、日々のトラブルシューティングまでを担います。地域における上位技術エスカレーション先として、他リージョンやコンサルティング要員への依存を減らす役割です。
  • Manager, DevOps & Support および VP, Technology & Professional Services と連携し、セキュリティ、社内 DevOps、顧客向け DevOps の責任範囲に空白が生じない状態を保ちます。セキュリティ体制、インシデント、主要リスクは経営層へ定期的に報告します。
  • セキュリティが一部門の関門ではなく、全員の共同責任である文化をつくります。あわせて、機能の成長に応じた技術人材の採用・育成・メンタリングを行います。
  • 技術・非技術いずれのステークホルダーにも、日本語と英語で技術的な内容を明確に伝えます。

Enthought が提供するもの

  • 意義のあるインパクト。創薬の加速から持続可能な材料の開発まで、科学的なブレークスルーに直接つながる仕事です。
  • エージェント型 AI の最前線。すべての職種が AI ツールを使いこなす自動化前提の企業で、業界における活用のあり方そのものを形づくる立場に立てます。
  • 世界水準の同僚。極めて優秀で、そして誠実な科学者・エンジニアとともに働けます。
  • 継続的な学習。Python、機械学習、科学計算に関する Enthought のトレーニングプログラムを利用できます。
  • オースティン、ケンブリッジ、東京の各拠点にまたがる、グローバルで協働的なカルチャー。
  • 東京オフィスを拠点とした柔軟なハイブリッド勤務。
  • 競争力のある報酬・福利厚生。

活躍する人

Enthought のメンバーには共通する資質があります。卓越した誠実さ、分析的知性、スピード感、複雑なものを単純化する力、開かれたコミュニケーション、人への共感、粘り強さ、そして自ら率先し、責任を全うする意志です。尽きることのない好奇心を持ち、自らの仕事に全面的なオーナーシップを持ち、エージェント型 AI の時代における科学の進め方を形づくることに心を動かされる方であれば、当社はきっと居心地のよい場所になります。

The Opportunity

We are hiring a Manager, DevOps & InfoSec in our Tokyo office to lead the cloud infrastructure behind our customer solutions and to own Enthought's information security posture end to end. This is a player-coach role, hands-on by design: roughly 45% DevOps, 30% information security, and 25% IT and support operations for the Tokyo office and our deployed Japan-based accounts. Our largest customers are Japanese enterprises, and you will be their primary technical contact on infrastructure and security, so business-level fluency in Japanese and English is essential. Our security work is practical and hands-on rather than compliance- and audit-led. The role also spans a wide range in a given week, from company-wide security standards to a network or endpoint problem in the Tokyo office, and people who find that range interesting do well in it.

Key Responsibilities

  • Design end-to-end infrastructure and security solutions, applying deep knowledge of cloud architecture, automation, and information security to translate customer and business requirements into architectures spanning infrastructure, deployment, identity, and operations.
  • Lead the design, deployment, and ongoing operation of the infrastructure behind our customer solutions, covering infrastructure-as-code, CI/CD pipelines, deployment automation, observability, and cloud spend. Most of this work runs on Microsoft Azure, with some AWS.
  • Own Enthought's information security posture. Define, maintain, and enforce the security standards, policies, and configuration baselines applied across corporate systems, product infrastructure, and customer deployments.
  • Own the security risk register. Identify, quantify, and prioritize risk, and bring risk-acceptance decisions beyond your authority to the VP, Technology & Professional Services with a clear recommendation.
  • Own identity and access architecture, including entitlement models, least-privilege design, privileged access controls, and authentication standards, and set the standards that access operations execute against.
  • Lead security incident response from detection and triage through containment, eradication, recovery, and post-incident review, and keep the incident response plan current and exercised.
  • Decide on software, library, and tooling approvals, working from automated license, privacy, and vulnerability assessments. Escalate novel license, IP, or contractual questions to Contract Administration.
  • Work agent-first, using AI coding assistants and autonomous agents as your default way to build and review infrastructure, and keep extending what can be safely automated so that routine requests do not consume engineering time.
  • Define the security guardrails for agentic and automated operations: what credentials automated systems may hold, for how long, with what audit trail, and with what blast radius.
  • Serve as the security escalation point and primary technical contact for customer engagements, covering security questionnaires, due-diligence reviews, architecture discussions, and incident inquiries. Route contractual commitments through Contract Administration, and support Sales and Customer Success in articulating our security posture.
  • Define the deployment security standards and customer environment hardening guidance that consulting teams work from, so customer-facing deployments are executed securely from start to finish.
  • Embed security into DevOps practice, covering secrets management, dependency and vulnerability management, container and runtime hardening, and infrastructure-as-code review.
  • Advise and enable customer engineering teams on infrastructure automation and handover, including migrating them from manual configuration to infrastructure-as-code.
  • Own IT and support operations for the Tokyo office and for deployed Japan-based accounts, from onboarding and offboarding support to endpoint and hardware lifecycle, local network and office technology, and day-to-day troubleshooting. You are the region's senior technical escalation point, which reduces the office's dependency on other regions and on consulting staff.
  • Partner with the Manager, DevOps & Support and the VP, Technology & Professional Services so that ownership across security, internal DevOps, and customer-facing DevOps has no gaps, and report security posture, incidents, and key risks to leadership on a regular cadence.
  • Foster a culture in which security is a shared responsibility rather than a centralized gate, and attract, develop, and mentor technical talent as the function grows.
  • Communicate technical concepts clearly to both technical and non-technical stakeholders in Japanese and English.

What We Offer

  • Meaningful impact. Your work directly advances scientific breakthroughs, from accelerating drug discovery to developing sustainable materials.
  • A front-row seat to agentic AI. We are an automation-first company where every role directs AI tools, and you will help define how the industry puts them to work.
  • World-class colleagues. You will work alongside some of the smartest, kindest scientists and engineers around.
  • Continuous learning. Enthought's training programs in Python, machine learning, and scientific computing are open to you.
  • A global, collaborative culture across our Austin, Cambridge, and Tokyo offices.
  • Flexible hybrid work based out of our Tokyo office.
  • Competitive compensation and benefits.

Similar roles