About this role
Senior Product Security Engineer
Who we are
Mico is a company with a clear mission: to Empower every brand by building lifetime trust through humanlike technology . This ambitious goal sets the stage for our vision and core values.
By 2030, Mico aims to be the Asia No.1 Brand Empowerment Company . This mid-term goal outlines our dedication to becoming the leading force in empowering brands across Asia.
To achieve our mission, we identify four key values:
- WOW THE CUSTOMER
- INVEST IN PASSION
- BEYOND BORDERS
- BE THE CHANGE
01 · Why this role exists
Most security engineers defend a platform. You will build the agents that defend one — for 5,500+ brands in finance, insurance and retail, and for the AI that talks to their customers
Mico builds the conversational layer Japanese brands use to reach their customers — LINE, SMS/RCS, Voice AI and web — for more than 5,500 companies across finance, insurance, retail and real estate.
Three things make security engineering here different from most product companies.
Regulated industries: our customers set the bar, and it is a high one. Finance, insurance and real-estate clients require us to meet their regulators' standard for protecting both their data and their end users'. Data protection is a board-level subject here, not an engineering afterthought.
AI-native products: we build AI products, so we secure AI products. Mico's agents act on our customers' behalf. Guardrails, tool-use authorization and adversarial testing are a discipline the whole industry is still writing the playbook for. We would rather help write it than wait for it.
AI-assisted development, secured. As more of our software is built with AI, securing how we build matters as much as securing what we ship. Mico is committed to delivering not only the best value to our customers, but the most secure coding, infrastructure and data practices behind it.
We hold ISMS (ISO 27001) and Japan's Privacy Mark certification, and we work to OWASP and MITRE ATLAS guidance for the AI we ship. We are now investing in a dedicated product security function, designed agent-first, with executive sponsorship and a place in the company's half-year objectives.
This role is the senior engineer for that function. You will shape how it works rather than inherit how it has always been done — and you will do it with a mandate and a budget already in place.
02 · What you will actually do
Four areas. The first is what makes this role different from every other product security job you are looking at.
Band A — Build and run the security agents / Design, build and operate the security agents on the Claude Agent SDK with MCP tool integrations. Starting with PR Sentinel and DepGuard, then outward across the lifecycle.
- Wrap the scanners we buy so they become one coherent, low-noise signal rather than seven disconnected dashboards.
- Evaluate and red-team your own agents. False negatives and prompt injection against a security agent are your problem to catch.
- Automate the first response to customer security questionnaires, so an enterprise buyer gets a substantive answer in hours.
- Claude Agent SDK
Band B — Secure what we build
Threat-model high-risk features — new data flows, AI capabilities, auth and identity changes — before code exists.
- Own SAST, secret scanning, dependency and supply-chain security in CI, with SLAs on critical and high findings.
- Run vulnerability assessment in-house: DAST, API security testing, and hands-on penetration testing of our own products.
- Review application code and API designs, and make cross-tenant isolation structurally impossible to get wrong.
- Scope and manage external specialists where they earn their cost — crown-jewel penetration tests, independent assessments — and hold their output to a standard.
- Raise the level of the engineers around you: security champions in every squad, practical training, and reference material people actually use.
- Supply the technical evidence behind our ISMS and customer audits. The certification program is owned by our security team in Japan — you make it defensible.
Band C — Secure what we ship (AI / LLM)
- ### Red-team Mico's own AI agents: prompt injection, jailbreaks, tool abuse, data exfiltration through model output.
- Build guardrails and regression gates so a prompt or model change cannot silently weaken defenses.
- Work to OWASP LLM Top 10 and MITRE ATLAS , and turn the results into evidence our enterprise customers can read.
Band D — Secure what we hold (Data & PII)
- ### Classify data, then enforce it: masking and redaction in logs, non-production and analytics — and before anything reaches a model.
- Implement just-in-time, least-privilege access across personal data, with audit trails that stand up to scrutiny.
- Build tokenization and a mediated data-access path so no service or person reads sensitive stores directly.
03 · You will not be doing this alone
How the work is actually carried.
- Agents carry the volume. This is the entire point of our agentic approach to security. One engineer cannot review every pull request, triage every advisory and re-test every AI feature by hand, so you build the agents that do the first pass, and you spend your time on the judgment calls. Leverage is the design here, not an afterthought.
- Squads own their own fixes. You are not the person patching a dozen codebases. Security champions are named in every squad; they are the first readers of agent output and the people who land the remediation. You build the system that makes them effective.
- Work directly with VPs. Our VP and security specialists in Japan will support you on roadmap, strategy and development.
- The work is sequenced, not simultaneous. Look at the first six months below: the early work is coverage and classification. AI red-teaming and data-access controls come afterwards, once the foundation carries its own weight. Nobody is expected to start four programs in week one.
- The function grows with you. This is an opportunity to be a first member of the security team and to grow that team with you. Being first here means shaping a team — and the opportunity to become its lead in time.
04 · And what this role is not
Here is what sits outside this role, and where it actually lives.
- You will not run corporate IT. Devices, office network, helpdesk and identity administration belong elsewhere.
- You will not own ISMS / ISO 27001 audit and evidence management. Our security team in Japan owns the certification program. You support it technically — you are not the auditor.
- You will not be the compliance function. We will set this up separately, together.
05 · What you will own
Your first ninety days — the engineering pipeline
You take ownership of scanning coverage across our repositories: static analysis, dependency and supply-chain checks, and secret detection. You own data classification across our primary stores, and the threat-modelling gate that high-risk features pass through. You name the security champions in each squad and set how they work with you.
Months four to six — agents in the engineers' path
You own the review agent that gives every pull request an explanation and a suggested fix, and the orchestration layer that turns many scanners into one prioritized queue. You run assessment in-house — DAST, API security testing and penetration testing — alongside the external specialists we engage.
What good looks like: security feedback at pull-request time measured in minutes · one prioritized queue rather than many tool reports · every high-risk feature threat-modelled before build
06 · What we need
- 5–8 years in security , the majority of it in application or product security for a software product — not solely network or IT security.
- You write production code. Python, Go or TypeScript, and comfortable in Shell. You have automated security work rather than only operating tools that someone else built. (non-negotiable)
- Hands-on across the application security core: secure code review, threat modelling, API and web vulnerability assessment , OWASP Top 10 and API Top 10, and CVE/OSV-driven dependency and supply-chain security.
- Cloud security on AWS in practice — IAM, network boundaries, and real use of GuardDuty, Security Hub or CloudTrail.
- Security wired into CI/CD — SAST, SCA and secret scanning in pipelines you owned, including the unglamorous work of getting developers to accept them.
- Daily practical use of AI coding agents such as Claude Code in your own work.
- Working fluency in English. Our engineering organisation spans more than twenty nationalities across India and Japan.
What would help
- AI / LLM security — prompt injection, jailbreak and tool-abuse testing; OWASP LLM Top 10; MITRE ATLAS; harnesses such as Promptfoo, Garak or PyRIT. Rare, and genuinely valued. If you don't have it yet, this is the role where you build it.
- PII engineering at scale — classification, masking, tokenization, data-access proxies; exposure to APPI or GDPR.
- Security due diligence for regulated buyers — questionnaires, customer audits, trust centres.
- Certifications such as OSCP, GWAPT, CISSP. Useful signal, never a substitute for the work.
- Japanese language ability. Welcome, not required.
07 · Who does well here
- You would rather build the thing that finds a hundred bugs than find a hundred bugs.
- You can look at a critical finding and say this one is not actually exploitable — and defend it. Cutting noise is a skill we value as highly as finding issues.
- You explain the same risk to an engineer and to an executive in one conversation, and both act on it.
- You are comfortable being first.
- You standardise rather than repeat yourself, and you write things down. What you work out once should be usable by a dozen squads without you in the room.
- You can hold a gate without becoming a blocker. Shipping weekly is a company commitment; security has to make that faster, not slower.
08 · What you get
- Ownership of a named program with executive sponsorship, a budget and a place in the company's half-year objectives — not a security wish-list you have to fight for.
- You build with AI, not around it. Agent engineering is the core of the job, not a side project you do after hours.
- A path. Build first, grow with us and become Lead Security Engineer by building solution and team.
- Real reach. What you secure is used by more than 5,500 brands and, through them, by millions of people every day.
- A genuinely global team across India and Japan, working in English.
09 · How we hire
Four rounds. We move fast and we tell you where you stand — most candidates do not get an offer, and we would rather you learn something from the process either way.
- Screening & technical foundation — your background, and how you think about application security
- Deep technical — a real problem from our stack: threat modelling, code review, or breaking an agent
- Team fit — the engineers and squads you would work alongside
- Final — with the VP of AI Innovation & Engineering: the program, the mandate, and your first six months
Rounds one, three and four are in English. Round two includes interviewers from our Japan security team with an interpreter present — you are not expected to speak Japanese.