Vulnerability Management Analyst

  • 0 yrs
  • $ Not Disclosed / YEAR

Similar Jobs from Partners

Job Description

About PayPay

PayPay, a fintech company, that achieved more than 47M users within around 3.5 years since its launch in 2018 has hugely diversified employees who are from 40 different countries. To build "PayPay", we allied with Paytm, the biggest payment service company in India. Based on their customer-first technologies , we created and expanded the smartphone payment service in Japan.

Our biggest competitor is "cash". We are seeking for people who can accept this challenge positively, brush up the product at a tremendous speed that other companies could never achieve, and who are passionate about promoting and spreading such a financial life platform in a short time along with professionalism.

Job Description

PayPay DevSecOps is seeking a vulnerability management analyst  to direct our development and operations teams on maintenance and improvement of our services security.

PayPay DevSecOps focuses on supporting our teams through discovery, knowledge sharing and the automation of security configuration, testing, verification and monitoring. A strong candidate for Vulnerability Management Analyst will have a good understanding of software and infrastructure vulnerability detection, management and remediation. 

Primary Responsibilities

  • Working closely with CSIRT and Security Champions to track current security risks and mitigations

Main Responsibilities

  • Maintaining an up-to-date view of known vulnerabilities and their remediation status

  • Maintaining automated systems to assist teams with tracking current security status

  • Provide guidance to team members on methods of identifying mitigating vulnerabilities

  • Working with CSIRT and senior management to track progress on incident response

  • Working in a fast-paced environment where projects and prioritization may change frequently but maintaining a secure product is a requirement for all team members


  • Minimum of five years of demonstrated, security focused experience

  • Experience leading projects tasked with cross team vulnerability assessment and management

  • Minimum of three years experience with: 

    • DefectDojo or other vulnerability management tools

    • Crowdstrike

  • Demonstrated proficiency in python

  • Native or business level English proficiency

Preferred Qualifications

  • Experience with AWS SecurityHub and SSM

  • ArgoCD, Github Actions, Jenkins, Snyk, CodeQL

  • Neo4J

  • Native or business level Japanese proficiency

PayPay 5 senses

Working Conditions 

Employment Status

  • Full Time

Office Location

Work Hours

  • Super Flex Time (No Core Time)

  • In principle, 10:00am-6:45pm (actual working hours: 7h45m + 1h break)


  • Two days off per week (as well as national holidays, New Year's break(December 29th to January 4th))

  • Paid leave, congratulatory and bereavement leave, maternity/paternity leave, family care leave etc


  • Annual salary paid in 12 installments (monthly)

  • Based on skills, experience, and abilities

  • Reviewed once a year

  • Special Incentive once a year *Based on company performance and individual contribution and evaluation

  • Late overtime allowance, Work from anywhere allowance (JPY100,000)


  • Social Insurance (health insurance, employee pension, employment insurance and compensation insurance)

  • 401K

  • Language Learning support

  • Translation/Interpretation support

  • VISA sponsor + Relocation support