Overview

Digital Forensic Investigator Jobs in Chiyoda, Tokyo, Japan at プルデンシャル・ジャパン・テクノロジー Prudential Japan Technology

Title: Digital Forensic Investigator

Company: プルデンシャル・ジャパン・テクノロジー Prudential Japan Technology

Location: Chiyoda, Tokyo, Japan

<仕事内容>

*Japanese follows the English text.

The Digital Forensics Investigator will serve as an individual technical contributor in Japan, responsible for conducting digital forensic and incident response analysis, responding to security incidents, assisting with threat hunting operations, performing incident readiness activities, and completing other related cybersecurity tasks as required in a highly dynamic global corporate environment.

You will work on extremely complex problems in which analysis of situations or data requires an evaluation of intangible variables. In addition to deep technical expertise and experience, you will bring excellent problem solving, communication and teamwork skills, along with agile ways of working, strong business insight, an inclusive leadership attitude and a continuous learning focus to all that you do

• Partner with cross-functional stakeholders across regional business units, the Information Security Office, and Global Technology teams to support and coordinate cyber incident response activities at a global scale.

• Execute complex, enterprise-wide investigations, scoping incidents across hybrid environments, including on-premises and cloud platforms such as Active Directory/Entra ID, Microsoft 365, Azure, and AWS.

• Apply advanced query techniques using SIEM and detection platforms, leveraging Splunk Search Processing Language (SPL) and Microsoft Kusto Query Language (KQL) to drive efficient, data-driven investigative workflows.

• Utilize endpoint detection and response (EDR) technologies to conduct large-scale endpoint investigations, including threat hunting, triage, and root cause analysis across distributed environments.

• Perform comprehensive digital forensic analysis across multiple domains, including log analysis, host-based forensics, memory analysis, and network traffic investigation to support active incident response efforts.

• Conduct malicious code triage and analysis, identifying indicators of compromise (IOCs), behavioral patterns, and potential impact to inform containment and remediation strategies.

• Deliver clear, concise, and actionable communication of investigative findings, producing high-quality written reports and providing verbal briefings to both technical stakeholders and senior business leadership.

• Develop and maintain scripts, detection queries, and automation workflows, leveraging tools such as XSOAR to enhance response efficiency, consistency, and scalability. Lead and contribute to strategic initiatives and continuous improvement efforts, advancing the team’s forensic, detection, and incident response capabilities across the enterprise.

Digital Forensics Investigatorは、日本における”専門性の高い技術担当”として、デジタルフォレンジクスおよびインシデントレスポンスの分析・対応を担います。

セキュリティインシデント発生時の調査、スレットハンティング業務の支援、インシデント対応体制の整備・強化、その他必要に応じたサイバーセキュリティ関連業務を、グローバルかつ変化の激しい企業環境の中で遂行していただきます。

本ポジションでは、数値化や明確な判断基準が存在しない要素も含め、状況やデータを多角的に評価しながら、極めて複雑な課題の解決に取り組むことが求められます。

そのため、深い技術的知識と実務経験に加え、優れた問題解決力、コミュニケーション能力、チームワークを発揮できる方を歓迎します。さらに、アジャイルな働き方、ビジネス視点を持った判断力、多様性を尊重する姿勢、そして常に学び続ける意欲をもって業務に取り組めることを期待しています。

●主な業務内容

・グループの生命保険各社、情報セキュリティオフィス(ISO)、グローバルテクノロジーチームなどのクロスファンクショナルなステークホルダーと連携し、グローバル規模でのサイバーインシデント対応活動を支援・調整する

・オンプレミス環境およびクラウド環境(Active Directory / Entra ID、Microsoft 365、Azure、AWS など)を含むハイブリッド環境全体を対象とした、複雑かつエンタープライズ規模の調査を実行する

・SIEM および検知プラットフォームを活用し、Splunk Search Processing Language(SPL)や Microsoft Kusto Query Language(KQL)による高度なクエリ技術を用いて、効率的かつデータドリブンな調査ワークフローを推進する

・EDR(Endpoint Detection & Response)技術を活用し、分散環境における大規模なエンドポイント調査、スレットハンティング、トリアージ、根本原因分析(RCA)を実施する

・ログ分析、ホストベースフォレンジクス、メモリ解析、ネットワークトラフィック分析など、複数領域にまたがる包括的なデジタルフォレンジクス分析を実施し、インシデント対応を支援する

・悪意あるコードのトリアージおよび分析を行い、侵害指標(IOC)、挙動パターン、潜在的な影響を特定し、封じ込めおよび復旧戦略の策定に貢献する

・調査結果について、明確・簡潔かつ実行可能な形で情報を整理・共有し、高品質な報告書の作成および技術担当者・シニアビジネスリーダー双方への口頭説明を行う

・XSOAR などのツールを活用し、スクリプト、検知クエリ、自動化ワークフローの開発・保守を行うことで、対応の効率性・一貫性・スケーラビリティを向上させる

・エンタープライズ全体におけるフォレンジクス、検知、インシデントレスポンス能力の強化を目的とした戦略的イニシアチブおよび継続的改善活動をリード、または積極的に貢献する

・仕事内容変更の範囲:会社の定める職務(2024年4月の職安法施行規則改正に伴う追記)

<組織概要>

*Japanese follows the English text.

The Cyber Defense and Response team is the Enterprise’s centralized threat management capability which safeguards the organization’s digital assets through rapid and effective protection, detection and response to cyber threats.

・A 24/7 Cyber Security Operations Center triages alerts, with further investigation and response handled by the Cyber Incident Response and Insider Risk teams

・A proactive effort consumes external intelligence, drives analysis of the company’s defensive posture, and implements solutions required to respond rapidly or detect high risk activity often missed by vendor tooling

・The Cyber Defense and Response Team partners closely with HR, Law, Risk, Global Security, and the greater GT team

Cyber Defense & Response チームは、企業全体の脅威管理機能を担う中核組織として、迅速かつ効果的な防御・検知・対応 を通じて、企業のデジタル資産を守る役割を担っています。

・24時間365日稼働のイバーセキュリティオペレーションセンター(CSOC)がアラートをトリアージし、 詳細な調査と対応はサイバーインシデント対応チーム および インサイダーリスクチーム と連携して実施。

・プロアクティブな取り組みとして外部インテリジェンスを活用し、自社の防御態勢を分析し、改善が必要な領域を特定。ベンダーツールでは検知が困難な高リスクな活動を迅速に検知・対応するためにソリューションを導入

・人事、法務、リスク管理、グローバルセキュリティ、およびGT(Global Technology)チーム全体と緊密に連携します。

<Positionの魅力/得られる経験等>

*Japanese follows the English text.

Join a team and culture where your voice matters; where every day, your work transforms our experiences to make lives better. As you put your skills to use, we’ll help you make an even bigger impact with learning experiences that can grow your technical AND leadership capabilities. You’ll be surprised by what this rock-solid organization has in store for you.

あなたの声が大切にされるチームと文化に参加しませんか。

あなたの仕事が日々、私たちの体験を変え、人々の生活をより良くしていく場所です。

あなたのスキルを発揮しながら、私たちは 技術力とリーダーシップ力の両方を伸ばせる学習の機会 を提供し、さらなるインパクトを生み出せるようサポートします。この堅実で信頼できる組織が、あなたにどんな可能性を用意しているか、きっと驚くことでしょう。

<応募要件>

*Japanese follows the English text.

≪Must≫

• Minimum of 5+ years of hands-on experience in cyber incident response and digital forensics within large, complex enterprise environments, including exposure to global or multi-region operations.

• Fluency in both Japanese and English (written and verbal), with the ability to effectively communicate complex technical concepts, investigative findings, and risk implications to diverse audiences, including technical teams and business leadership.

• Proficiency with enterprise-grade digital forensic tools and platforms, including both commercial and open-source solutions (e.g., X-Ways, EnCase), applied across a variety of investigative scenarios.

• Working knowledge of scripting and automation, with experience in languages such as Python, PowerShell, or Bash to support investigation, data analysis, and response automation.

• Strong understanding of adversarial tactics, techniques, and procedures (TTPs), with practical application of frameworks such as MITRE ATT&CK and the Lockheed Martin Cyber Kill Chain to support detection, investigation, and response activities.

・大規模かつ複雑なエンタープライズ環境において、サイバーインシデント対応およびデジタルフォレンジクスの実務経験を5年以上有していること(グローバル企業、もしくは複数地域にまたがる環境での業務経験を含む)

・日本語/英語ビジネスレベル(読み、書き、会話)

技術チームだけでなく、非技術系を含むビジネスサイドの関係者に対しても、複雑な技術内容や調査結果、リスクの影響を分かりやすく説明できること

・デジタルフォレンジクスツール(X-Ways、EnCase )の実務利用経験(商用・オープンソース不問)

・Python、PowerShell、Bash などを用いたスクリプト作成や自動化に関する基礎〜実務レベルの知識・経験を有する(調査の効率化、データ分析、レスポンス対応の自動化に携わった経験)

・攻撃者の行動パターンや手口(TTPs)に関する理解を有し、MITRE ATT&CK や Lockheed Martin Cyber Kill Chain などのフレームワークを、実際の検知・調査・インシデント対応業務に活用した経験があること

≪Want≫

• Relevant industry-recognized certifications preferred, such as CCE, EnCE, GCFE, GCFA, GCIH, GREM, GNFA, or GPEN, demonstrating validated expertise in incident response, forensics, and threat analysis.

• Bachelor’s degree in Digital Forensics, Information Security, Computer Science, Information Technology, or a related field (or equivalent practical experience in cybersecurity and incident response).

以下のような業界認知度の高い関連資格を保有していること

・CCE、EnCE、GCFE、GCFA、GCIH、GREM、GNFA、GPEN などの資格

・インシデントレスポンス、デジタルフォレンジクス、スレット分析における専門性を証明するもの

・デジタルフォレンジクス、情報セキュリティ、コンピュータサイエンス、情報技術、または関連分野における学士号(もしくはサイバーセキュリティおよびインシデントレスポンス分野での同等の実務経験)

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.