SlipstreamJobsFresh Startup & VC-Backed Jobs

Security GRC Program Manager

Sakana AI - Tokyo, Japan - Hybrid - posted 2026-08-27

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Sakana AI is seeking a Security GRC Program Manager to establish governance and compliance frameworks that reduce security risks to the company's employees and systems. This role bridges security, compliance, and business operations, working cross-functionally with project teams, product teams, legal, and engineering. Key responsibilities span five domains: 1. Security Governance & Strategy: Develop security strategy, policies, and procedures; support the CISO and executive leadership; translate regulatory requirements (GDPR, CBPR, FISC, ISMAP) and customer security demands into risk-based mitigation strategies; secure resources and oversee third-party/supply-chain security. 2. Security Program & Project Management: Establish and improve security risk management processes; drive security initiatives (ISMS deployment, company-wide rollouts); manage program planning, progress, budgets, and vendor relationships; develop data governance and information handling procedures. 3. Compliance & Legal: Partner with legal to translate privacy and cybersecurity regulations into security requirements; conduct privacy impact assessments; create and maintain internal compliance documentation. 4. Certification & Audit: Obtain and maintain SOC2 and ISMS certifications; plan and execute risk assessments and internal audits; respond to external audits; automate evidence collection and control monitoring using tools like Vanta/Drata. 5. Security Education: Design, deliver, and evaluate employee security training and awareness programs. Required qualifications include hands-on experience in at least one of: cybersecurity consulting, security certification programs (SOC2/ISMS), risk management, security/systems auditing, privacy regulation compliance (GDPR/CBPR), financial/government security requirements, or security training delivery. Beyond this, candidates must demonstrate technical fluency with cloud/systems architecture, ability to discuss control implementation and technical risk with engineers, strong written and verbal communication skills, cross-functional project management capability, vendor and asset management discipline, and business-level Japanese (JLPT N1). Nice-to-have skills include web application security expertise, cloud security controls (Google Cloud), vulnerability assessment/penetration testing, compliance automation platforms (Vanta/Drata), AI product development experience, AISM certification, J-SOX IT controls, mentoring capability, and business-level English. The role is based in Tokyo with hybrid flexibility. Sakana AI is an AI research company working with the Japanese government; applicants should review and align with the company's defense business policy before applying.

Similar roles