Careers / Cybersecurity Manager
Cybersecurity Manager
Cybersecurity Governance & Risk Manager
Summary
Ahead Group is looking for a Cybersecurity Governance & Risk Manager to join a global professional services organization operating across the Asia-Pacific region. The ideal candidate will lead local cybersecurity operations in Japan, collaborate closely with global stakeholders, and drive continuous improvement across governance, risk management, and compliance frameworks.
Responsibilities
• Lead cybersecurity governance and compliance activities aligned with global standards
• Develop, maintain, and roll out cybersecurity policies and related documentation
• Design and deliver security awareness programs, including training content, videos, translations, and newsletters
• Promote and assess compliance with security policies across business units
• Conduct cross-business cyber risk management, including periodic risk reviews and record management
• Support business units with cybersecurity risk assessments during bids and contracts (CSRA)
• Perform and manage third-party risk assessments (TPRM) for service procurement
• Manage physical security risk assessments for facilities and coordinate improvements with relevant departments
• Oversee people security, including travel risk assessments for high-risk countries and regions
• Coordinate employee safety measures during disasters in alignment with BCP
• Support ISMS operations, including ISO 27001 internal and external audits
• Coordinate audit schedules, documentation, auditors, findings, and remediation actions
• Deliver ISMS user training and manage participation progress
• Support process development for change management, cyber risk management, and information asset management
• Operate and support ISMS steering committees, management reviews, and follow-up actions
• Maintain information asset registers, perform risk analysis, and implement improvement actions
• Manage progress of security-related projects
• Respond to security incidents and manage ongoing operational security activities
• Produce regular cybersecurity KPI reports
• Manage policy exceptions and support threat management activities
Required Skills
• Fluent Japanese and business-level English
• Experience conducting ISO 27001 internal audits
• Hands-on experience with third-party cybersecurity risk assessments
• Practical experience with cloud security risk assessments
• Experience operating and maintaining an Information Security Management System (ISMS)
• Experience working within global information security governance frameworks
• Working knowledge of ISO 27001, Privacy Mark, GDPR, and related security and data protection regulations
• Strong data analysis skills
Desired Skills
• Experience implementing Microsoft SharePoint, Power Automate, or BI tools
• Additional hands-on experience with third-party security risk assessments
• Experience handling vulnerability and threat alerts using threat intelligence
• Security-related certifications such as CISSP, CCSP, CISA, CISM, CRISC, or ISO 27001 Lead Auditor