About the Role
The AppSec & Mobile Cybersecurity Lead is responsible for designing, implementing, and scaling security across Paidy’s iOS and Android applications, mobile APIs, and backend services. This role hardens the systems that power our consumer and merchant experiences by embedding security into the software development lifecycle, building automation that scales with engineering velocity, and staying ahead of an evolving threat landscape.
Responsibilities
- Define and enforce application and mobile security standards across iOS/Android apps, mobile APIs, backend services, and the SDLC
- Lead AppSec and mobile security architecture, ensuring strong access controls, secure data handling, resilient client-server interactions, and appropriate platform-level protections
- Partner with mobile and backend engineering teams to design secure-by-default services
- Conduct threat modeling to proactively identify and mitigate risks across the mobile and application stack
- Own the design and security of REST and GraphQL APIs, with a solid command of the OAuth2 protocol and mobile authentication flows
- Build and scale security testing within CI/CD pipelines: SAST, SCA, DAST, secrets scanning, container scanning, IaC checks, MAST, binary analysis, and SBOMs for mobile build infrastructure
- Integrate security gates into CircleCI and GitHub workflows
- Build custom security tooling to automate recurring security validation, coverage measurement, and control verification tasks
- Own container image and runtime scanning across mobile and application build infrastructure
- Own the vulnerability management lifecycle for applications and mobile: triage SLAs, risk ratings, remediation guidance, verification, and recurring root-cause fixes
- Monitor the mobile and application threat landscape and translate intelligence into actionable engineering priorities
- Track and respond to emerging AI-era threats including LLM and agent supply chain attacks, prompt injection, model abuse in integrated AI features, and AI-generated fraud patterns targeting mobile payment flows
- Communicate vulnerability risk and remediation posture clearly to engineering teams and security leadership
- Support audit and compliance programs including SOC 2 (Type 1 and Type 2), ISO 27001, the Japan Act on the Protection of Personal Information (APPI), and the Japan Installment Sales Act (割賦販売法)
- Provide AppSec and mobile security evidence, control mapping, and remediation tracking in support of internal and external audits
- Develop and maintain secure coding standards and application security policies
- Mentor engineering teams on secure design patterns, mobile hardening, and threat-aware development
- Build and maintain security automation using scripting, workflow tools, and AI coding tools including Claude Code
- Leverage AI-driven tooling to continuously validate security controls, detect regressions, and surface risk trends
- Deliver security awareness and enablement programs tailored to mobile and application engineers
Requirements
- 5+ years of experience in application security, mobile security, or DevSecOps with demonstrated technical depth
- Strong hands-on Android and iOS development and security hardening expertise
- Experience with end-to-end vulnerability management including SAST, SCA, and DAST tooling
- Proven experience building security controls into CI/CD pipelines on AWS
- Experience with container scanning (image and runtime) and infrastructure as code security checks
- Solid understanding of the OAuth2 protocol and experience designing and securing REST and GraphQL APIs at scale
- Broad software development experience in one or more of: Rust, Scala, Python, Java, or equivalent modern languages
- Extensive experience with AWS cloud security across common services (API Gateway, Lambda, ECS, RDS, and related)
- Confidence with Docker and Terraform as development and infrastructure tools
- Hands-on experience using AI coding tools (e.g., Claude Code) to build or automate security workflows
- Effective communicator with a pragmatic approach to security — able to build strong relationships with engineering and business stakeholders
- Business-level English required
- Japanese language ability is helpful but not required
- B.S. in Computer Science, Information Security, or a related field, or equivalent practical experience
- Japanese language proficiency (JLPT 2 or above) is desired
- Experience securing mobile payments or fintech applications in regulated environments is desired
- Demonstrated history of building custom internal security tools, not only consuming commercial products is desired
- Familiarity with the Japanese regulatory environment including APPI and the Installment Sales Act (割賦販売法) is desired
- Prior experience defending mobile platforms at scale against fraud, abuse, and automated attacks is desired
- Must be eligible to work in Japan
Skills
- Application Security
- Mobile Security
- DevSecOps
- Android Development
- iOS Development
- SAST
- SCA
- DAST
- CI/CD
- AWS
- Container Scanning
- Infrastructure as Code (IaC)
- OAuth2
- REST APIs
- GraphQL APIs
- Rust
- Scala
- Python
- Java
- AWS Cloud Security
- Docker
- Terraform
- AI Coding Tools
- Claude Code
- Threat Modeling
- Vulnerability Management
- SOC 2
- ISO 27001
- APPI
- Installment Sales Act (割賦販売法)
Location
- Japan
Work Type
- Hybrid remote
Experience Level
- 5+ years of experience in application security, mobile security, or DevSecOps
Education Level
- B.S. in Computer Science, Information Security, or a related field, or equivalent practical experience
Benefits
- Competitive salary and benefits
- Diversified team with 230+ colleagues from 35+ countries
- Exciting work opportunities in a rapid-growing organization
- Cross-functional collaboration
About the Company
- Paidy is Japan's pioneer and leading BNPL service company.
- Paidy offers instant, monthly-consolidated credit to consumers by removing hassles from payment and purchase experiences.
- Paidy uses proprietary models and machine learning to underwrite transactions in seconds and guarantee payments to merchants.
- Paidy increases revenue for merchants by reducing the number of incomplete transactions, increasing conversion rates, boosting average order values, and facilitating repeat purchases from consumers.
- Paidy has reached an agreement to join PayPal, the global payments company.
- Paidy will continue to operate its existing business, maintain its brand and support a wide variety of consumer wallets and marketplaces by providing convenient and innovative services.
- Paidy continues to innovate to make shopping easier and more fun both online and offline.
