Reporting to the Global IT Security Manager in Advantest Japan headquarters, this position will be working on various aspects of information technology security across all Advantest Group companies.
This role requires an individual with a technical as well as security compliance (NIS2, CRA, SEMI 187/188) background, with the ability to work across the Global IT organization and the divisions to align IT security priorities and controls with key business objectives.
Key Responsibilities:
Threat Detection & Risk Management
- Monitor, analyze, and assess emerging cyber threats, with a particular focus on AI-enabled attacks and cloud-based risk scenarios.
- Conduct risk and vulnerability assessments and define appropriate mitigation and remediation measures in alignment with corporate risk management practices.
- Support preventive security controls, including threat intelligence, security monitoring, and AI-based anomaly detection capabilities.
Security Operations & Incident Response
- Support daily security alert monitoring activities, assess risks, and coordinate remediation actions with end users and IT teams.
- Support security incident response activities within the EU, including coordination with internal IT teams, legal functions, and external forensics partners when required.
- Contribute to effective incident management, escalation, and communication processes, working closely with SOC and CSIRT functions.
Governance, Compliance & Resilience
- Support the implementation and continuous improvement of IT security and IT risk management practices, with particular consideration for regulatory frameworks (e.g. NIS2, CRA, ISO 27001).
- Assist with coordination of penetration testing activities and follow-up actions.
- Support IT security requirements related to Business Continuity Planning (BCP) and operational resilience.
Collaboration & Stakeholder Engagement
- Work closely with global IT security teams, business units, and external partners to ensure consistent security standards and pragmatic implementation.
- Communicate security risks, incidents, and mitigation strategies clearly to both technical and non-technical stakeholders.