Security & Compliance Engineer at TableCheck | Japan | Rezi

Security & Compliance Engineer at TableCheck

Security & Compliance Engineer

TableCheck · Japan

3 weeks ago

Security & Compliance Engineer

TableCheck · Japan

22 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

TableCheck, Japan's leading restaurant reservation management platform, is seeking a Security & Compliance Engineer to lead our security posture, compliance programs, and risk governance on our Site Reliability Engineering team. You will ensure TableCheck meets the highest standards of data protection and regulatory compliance on our AWS-based infrastructure.

Responsibilities

  • Own and lead end-to-end implementation, maintenance, and renewal of SOC 2 Type II, ISO 27001, PCI DSS, and related compliance programs through our compliance platform (Drata).
  • Develop, maintain, and enforce security policies, procedures, and documentation aligned with industry frameworks (NIST CSF, ISO 27001 Annex A, MITRE ATT&CK).
  • Conduct regular risk assessments, internal audits, and control effectiveness reviews; identify gaps and drive remediation through coordination with engineering and operations teams.
  • Manage third-party risk assessments and vendor security reviews, including security questionnaires and due diligence.
  • Serve as the primary point of contact for external audits and certification bodies — preparing evidence, coordinating interviews, and managing the audit lifecycle.
  • Partner with legal, privacy, and engineering teams on data protection matters, including privacy impact assessments and incident response planning.
  • Monitor regulatory changes in Japan and other operating markets (e.g., APPI, GDPR) and advise the business on compliance obligations.
  • Build and maintain relationships with engineering teams to embed security and compliance requirements into development workflows — working collaboratively rather than as a bottleneck.

Requirements

  • 3+ years in security compliance, risk, or governance roles with proven experience achieving and maintaining SOC 2 Type II and/or ISO 27001 certification (full lifecycle — from gap analysis through audit).
  • Hands-on experience with compliance automation platforms, ideally Drata.
  • Deep understanding of security frameworks and standards: SOC 2 Trust Services Criteria, ISO 27001/27002, NIST CSF, and data privacy regulations (APPI, GDPR a plus).
  • Strong written and verbal communication skills — you can translate technical security requirements into clear policies and explain business risk to non-technical stakeholders.
  • Experience coordinating with external auditors and managing the audit process end-to-end.
  • Ability to collaborate with engineering teams to remediate findings and implement controls without deep hands-on coding.
  • Familiarity with AWS security services (IAM, GuardDuty, Config) at an operational level — enough to understand cloud security controls and ask the right questions of engineering teams.

Skills

  • Security Compliance
  • Risk Management
  • Governance
  • SOC 2 Type II
  • ISO 27001
  • PCI DSS
  • Drata
  • NIST CSF
  • ISO 27001 Annex A
  • MITRE ATT&CK
  • Data Protection
  • Regulatory Compliance
  • Third-Party Risk Assessment
  • Vendor Security Review
  • External Audits
  • Privacy Impact Assessments
  • Incident Response Planning
  • APPI
  • GDPR
  • AWS Security Services (IAM, GuardDuty, Config)
  • Japanese Language Proficiency
  • SaaS Industry
  • Cloud-Native Security Concepts
  • Kubernetes
  • Serverless
  • Information Governance
  • JD
  • CIPP
  • CISM
  • CISSP

Location

  • Remote

Work Type

  • Remote
  • Full-time

Experience Level

  • 3+ years

Education Level

  • JD
  • CIPP
  • CISM
  • CISSP

About the Company

  • TableCheck, Japan's leading restaurant reservation management platform, is seeking a Security & Compliance Engineer.
  • We run a robust and fault-tolerant infrastructure built on Amazon Web Services (AWS).
  • TableCheck has embraced remote work, and as such, communication and documentation are in our blood.
  • We look for and write about signals in the noise which enables us to constantly learn from mistakes and adapt, and we expect members of our teams to constantly follow up with questions and updates to keep everyone in the loop.