Platform Security Engineer - Mercari Employment Status: Full-time Work Hours: Full Flextime (no core time) Office: Roppongi
About Mercari
Circulate all forms of value to unleash the potential in all people \"What can I do to help society thrive with the finite resources we have?\" The Mercari marketplace app was born in 2013 out of this thought by our founder Shintaro Yamada as he traveled the world. We believe that by circulating all forms of value, not just physical things and money, we can create opportunities for anyone to realize their dreams and contribute to society and the people around them. Mercari aims to use technology to connect people all over the world and create a world where anyone can unleash their potential. For more information about Mercari Group’s mission, see Mercari’s Culture Doc
Key Responsibilities
Strengthen the resilience and enhance the security posture of the foundational platform on which our services are built
Execute impactful projects across the organization to ensure integration of security best practices, frameworks, and regulations
Automate security controls and monitoring
Develop technical solutions to prevent or mitigate security vulnerabilities
Maintain technical & security standards for production and corporate infrastructure services
Collaborate with security management professionals, the legal team, and internal auditors on technical security matters
Work with platform engineering teams to balance security with other requirements
Review architecture proposals and propose security controls to minimize risks
Required Qualifications
Strong understanding of core computer security concepts including the CIA triad, principle of least privilege, authentication vs. authorization, cryptography, security protocols, application security
Experience with standard software development tools such as Git, GitHub, CI/CD tools (GitHub Actions), and shell scripting
Programming experience with one or more programming languages including Go, Python or TypeScript
Experience using and configuring public cloud infrastructure platforms (GCP, Google Workspace, AWS, Azure), as well as container technologies (Docker, Kubernetes) and Infrastructure as Code (Terraform)
Experience with UNIX-like systems (Linux, macOS) configuration, administration and hardening
Preferred Qualifications
4+ years of experience in security domains
Bachelor's degree in Computer Science or equivalent practical experience
Familiarity with cloud and web application architecture and best practices
Familiarity with secure software development lifecycle (Secure SDLC, SLSA)
Knowledge of SQL (BigQuery, Postgres, etc)
Familiarity with applied cryptography (key management, TLS, PKIs, KMSes, etc)
Familiarity with networking - TCP/UDP, DNS, HTTP
Experience with configuring identity federation (OIDC, SAML)
Familiarity with PCI-DSS or other information security or privacy standards
Please let Mercari know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.