SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Sakana AI is seeking a Security GRC Program Manager to establish governance and compliance frameworks that reduce security risks to the company's employees and systems. This role bridges security, compliance, and business operations, working cross-functionally with project teams, product teams, legal, and engineering.
Key responsibilities span five domains:
1. Security Governance & Strategy: Develop security strategy, policies, and procedures; support the CISO and executive leadership; translate regulatory requirements (GDPR, CBPR, FISC, ISMAP) and customer security demands into risk-based mitigation strategies; secure resources and oversee third-party/supply-chain security.
2. Security Program & Project Management: Establish and improve security risk management processes; drive security initiatives (ISMS deployment, company-wide rollouts); manage program planning, progress, budgets, and vendor relationships; develop data governance and information handling procedures.
3. Compliance & Legal: Partner with legal to translate privacy and cybersecurity regulations into security requirements; conduct privacy impact assessments; create and maintain internal compliance documentation.
4. Certification & Audit: Obtain and maintain SOC2 and ISMS certifications; plan and execute risk assessments and internal audits; respond to external audits; automate evidence collection and control monitoring using tools like Vanta/Drata.
5. Security Education: Design, deliver, and evaluate employee security training and awareness programs.
Required qualifications include hands-on experience in at least one of: cybersecurity consulting, security certification programs (SOC2/ISMS), risk management, security/systems auditing, privacy regulation compliance (GDPR/CBPR), financial/government security requirements, or security training delivery. Beyond this, candidates must demonstrate technical fluency with cloud/systems architecture, ability to discuss control implementation and technical risk with engineers, strong written and verbal communication skills, cross-functional project management capability, vendor and asset management discipline, and business-level Japanese (JLPT N1).
Nice-to-have skills include web application security expertise, cloud security controls (Google Cloud), vulnerability assessment/penetration testing, compliance automation platforms (Vanta/Drata), AI product development experience, AISM certification, J-SOX IT controls, mentoring capability, and business-level English.
The role is based in Tokyo with hybrid flexibility. Sakana AI is an AI research company working with the Japanese government; applicants should review and align with the company's defense business policy before applying.