Recruitment|Penetraiton Tester

Selection Process

Step. 1 Document Screening

Please submit your resume, work history (CV), and portfolio. Based on the materials you provide, we will comprehensively review your background, skills, and motivation for applying.
We will typically notify you of the results of the document screening by email within one to two weeks.

Step. 2 Aptitude Test

We conduct a standardized aptitude test (commonly used in Japanese hiring, known as the SPI test).
This is used as an opportunity for us to get to know each other from a perspective distinct from technical skills and experience.

Step. 3 First Interview

This interview is conducted by a member of our team. We will ask about your past experience, your approach to work, and your reasons for wanting to join our company, using this as an opportunity to deepen mutual understanding.

Step. 4 Technical Assessment

By having you work on a task that closely resembles actual on-the-job work, we assess not only your knowledge and skills but also how you approach challenges and your thought process.
This is conducted either online or in person, with the level of difficulty adjusted according to the position you are applying for.

Step. 5 Second Interview

Based on the first interview and technical assessment, this interview is conducted primarily by the manager of the department you would be assigned to.
We will discuss in more concrete terms your fit with the team and your suitability for the actual work involved.

Step. 6 Final Interview

This interview is conducted by a member of our executive management or board of directors. We will share our company's vision and future direction while confirming final mutual intent.
We aim to proceed carefully so that both parties can reach a mutual understanding and start off on a positive note.

※Please note that the selection process may vary depending on the position and the status of applications.

Penetration Test Lead
Penetration Test Operator
Employment Type Full-time employee
3-month probationary period (no changes to working conditions during this period)
Work Location Ochanomizu First Building 5F, 2-5-1, Kanda Surugadai, Chiyoda-ku, Tokyo, Japan, 101-0062
Smoking Policy Indoor smoking is permitted in designated areas.
Working Hours
  • Flextime system
  • Standard working hours: 8 hours per day
  • Core hours: 11:00 AM – 2:00 PM
Working Style This is a hybrid position based in Tokyo.
While remote work is available depending on the project and team situation, regular attendance at the Tokyo office is required. Please note that all applicants must currently reside in Japan.
Holidays and Leave
  • 122 annual holidays
  • Complete two-day weekends (Saturdays and Sundays)
  • National holidays
  • Year-end and New Year holidays
  • Substitute holidays for national holidays falling on a Saturday
  • Paid leave: 20 to 22 days per year
  • Family-friendly leave (including marriage leave, maternity/paternity leave, prenatal checkup leave, childcare leave, child nursing leave, caregiving leave, bereavement leave, etc.)
Social Insurance
  • Employment Insurance
  • Health Insurance
  • Employees' Pension Insurance
  • Workers' Accident Compensation Insurance
Visa Requirements Applicants must be eligible to work in Japan.
While the company does not cover visa application fees or related costs, we will provide necessary documents and support required for the visa application process.
Salary Annual salary system
Benefits and Welfare
  • Defined contribution pension plan (401K)
  • Commuting allowance (according to company policy)
  • Housing allowance (according to company policy)
  • Payroll savings program ("Zaikei," a Japanese asset-formation savings scheme funded through payroll deduction), with additional contributions matched by the company
  • Support for obtaining professional certifications
  • Discounted rates for various insurance products
  • Congratulatory and condolence allowance
  • Flexible benefits program, administered through third-party welfare service providers (Relo Club, Benefit One)
  • Free office drinks
  • Many unofficial employee clubs (voluntary participation)
  • Employee Bug Bounty Program
Key Responsibilities As the "lead person in charge," you will be responsible for network penetration testing services provided by Cyber Defense Institute.
The Penetration Test Lead is responsible for understanding the objectives and constraints of each engagement, smoothly carrying out effective testing aligned with those objectives, and delivering results to the client.

The Penetration Test Lead is expected to fulfill the following roles:
  • Provide valuable input for test proposals and planning
  • Carry out the preparations necessary for conducting the test
  • Lead and support the Penetration Test Operators in conducting the test
  • Serve as the primary point of contact with the client during the test, handling consultations and coordination
  • Escalate to the tech lead or relevant internal departments as needed
  • Prepare deliverables, including reports
  • Report results to the client and close out the engagement
  • Assign any of the above roles to project team members as needed
  • Propose improvements to testing processes, documentation, or tools
  • Propose, research, and develop systems and tools necessary for conducting tests
Required Skills Candidates are expected to have at least two years of experience in the responsibilities described above under "Key Responsibilities," or to have acquired the following skills through self-directed study, including:
  • An understanding of common protocols at Layer 2 and above of the OSI reference model
  • Proficient OS operation skills
  • Programming ability
  • An understanding of, and practical ability in, common vulnerabilities and attack techniques
  • An understanding of attack techniques against systems using Active Directory
  • Strong writing/documentation skills (language is not restricted, but Japanese is the top priority, followed by English)
  • Strong verbal communication skills (language is not restricted, but Japanese is the top priority, followed by English)
Preferred Skills If you do not have at least two years of experience in the responsibilities described above, it is preferable that you hold one of the following certifications, or are currently working toward obtaining one.
Any certifications you hold beyond those listed here will also be taken into consideration.
  • OSCP+
  • OSEP
  • OSWA
  • OSWE
  • CRTO
  • CRTP
  • GPEN
  • GWAPT
  • GCPN
  • GXPN
  • Registered Information Security Specialist (Japan)
  • CISSP
In addition, the following experience and skills will make you a more competitive candidate:
  • Program analysis
  • Protocol analysis
  • Development of offensive security tools
  • Understanding of cloud environments and cloud-specific attack techniques
  • Understanding of CI/CD and CI/CD-specific attack techniques
  • Experience building enterprise systems
  • Understanding of generative AI
Ideal Candidate Profile Cyber Defense Institute's Red Team Group supports and advises companies and organizations in their efforts to maintain or improve security by collectively providing the capabilities, perspective, and mindset of an attacker. Our Penetration Testing and Red Team services are two concrete expressions of this kind of support.

While technical, specialized, and cognitive abilities are naturally required to carry out this work of "collectively providing the capabilities, perspective, and mindset of an attacker," our group also places great importance on the following underlying mindsets and attitudes that form the foundation of our conduct.
  • A Hacker's Mindset
    • Enjoying problem-solving
    • Taking an interest in the problems faced by the team and by others
    • Understanding how things work
    • Thinking outside the box
    • Being willing to try different approaches
    • Maintaining curiosity and a spirit of inquiry, and continuously learning
    • Doing things correctly, one step at a time
  • Teamwork
    • Working toward a shared goal
    • Communicating in a frank, honest, sincere, and courteous manner
    • Following the rules
    • Respecting each individual
  • Taking Initiative and Working Autonomously
    • Placing importance on actions and facts aimed at resolving issues and achieving goals
  • Being Accountable
    • Being aware of the impact of one's own words and actions
  • Taking Ownership
    • Not settling merely for one's own area of responsibility or role, but having the drive to see the team, organization, and company as something you help build together
  • Maintaining Physical and Mental Well-being
Employment type
Full-time employee
3-month probationary period (no changes to working conditions during this period)
Work Location
Ochanomizu First Building 5F, 2-5-1, Kanda Surugadai, Chiyoda-ku, Tokyo, Japan, 101-0062
Smoking Policy
Indoor smoking is permitted in designated areas.
Working Hours
  • Flextime system
  • Standard working hours: 8 hours per day
  • Core hours: 11:00 AM – 2:00 PM
Working Style
This is a hybrid position based in Tokyo.
While remote work is available depending on the project and team situation, regular attendance at the Tokyo office is required. Please note that all applicants must currently reside in Japan.
Holidays and Leave
  • 122 annual holidays
  • Complete two-day weekends (Saturdays and Sundays)
  • National holidays
  • Year-end and New Year holidays
  • Substitute holidays for national holidays falling on a Saturday
  • Paid leave: 20 to 22 days per year
  • Family-friendly leave (including marriage leave, maternity/paternity leave, prenatal checkup leave, childcare leave, child nursing leave, caregiving leave, bereavement leave, etc.)
Social Insurance
  • Employment Insurance
  • Health Insurance
  • Employees' Pension Insurance
  • Workers' Accident Compensation Insurance
Visa Requirements
Applicants must be eligible to work in Japan.
While the company does not cover visa application fees or related costs, we will provide necessary documents and support required for the visa application process.
Salary
Annual salary system
Benefits and Welfare
  • Defined contribution pension plan (401K)
  • Commuting allowance (according to company policy)
  • Housing allowance (according to company policy)
  • Payroll savings program ("Zaikei," a Japanese asset-formation savings scheme funded through payroll deduction), with additional contributions matched by the company
  • Support for obtaining professional certifications
  • Discounted rates for various insurance products
  • Congratulatory and condolence allowance
  • Flexible benefits program, administered through third-party welfare service providers (Relo Club, Benefit One)
  • Free office drinks
  • Many unofficial employee clubs (voluntary participation)
  • Employee Bug Bounty Program
Key Responsibilities
As the "lead person in charge," you will be responsible for network penetration testing services provided by Cyber Defense Institute.
The Penetration Test Lead is responsible for understanding the objectives and constraints of each engagement, smoothly carrying out effective testing aligned with those objectives, and delivering results to the client.

The Penetration Test Lead is expected to fulfill the following roles:
  • Provide valuable input for test proposals and planning
  • Carry out the preparations necessary for conducting the test
  • Lead and support the Penetration Test Operators in conducting the test
  • Serve as the primary point of contact with the client during the test, handling consultations and coordination
  • Escalate to the tech lead or relevant internal departments as needed
  • Prepare deliverables, including reports
  • Report results to the client and close out the engagement
  • Assign any of the above roles to project team members as needed
  • Propose improvements to testing processes, documentation, or tools
  • Propose, research, and develop systems and tools necessary for conducting tests
Required Skills
Candidates are expected to have at least two years of experience in the responsibilities described above under "Key Responsibilities," or to have acquired the following skills through self-directed study, including:
  • An understanding of common protocols at Layer 2 and above of the OSI reference model
  • Proficient OS operation skills
  • Programming ability
  • An understanding of, and practical ability in, common vulnerabilities and attack techniques
  • An understanding of attack techniques against systems using Active Directory
  • Strong writing/documentation skills (language is not restricted, but Japanese is the top priority, followed by English)
  • Strong verbal communication skills (language is not restricted, but Japanese is the top priority, followed by English)
Preferred Skills
If you do not have at least two years of experience in the responsibilities described above, it is preferable that you hold one of the following certifications, or are currently working toward obtaining one.
Any certifications you hold beyond those listed here will also be taken into consideration.
  • OSCP+
  • OSEP
  • OSWA
  • OSWE
  • CRTO
  • CRTP
  • GPEN
  • GWAPT
  • GCPN
  • GXPN
  • Registered Information Security Specialist (Japan)
  • CISSP
In addition, the following experience and skills will make you a more competitive candidate:
  • Program analysis
  • Protocol analysis
  • Development of offensive security tools
  • Understanding of cloud environments and cloud-specific attack techniques
  • Understanding of CI/CD and CI/CD-specific attack techniques
  • Experience building enterprise systems
  • Understanding of generative AI
Ideal Candidate Profile
Cyber Defense Institute's Red Team Group supports and advises companies and organizations in their efforts to maintain or improve security by collectively providing the capabilities, perspective, and mindset of an attacker. Our Penetration Testing and Red Team services are two concrete expressions of this kind of support.

While technical, specialized, and cognitive abilities are naturally required to carry out this work of "collectively providing the capabilities, perspective, and mindset of an attacker," our group also places great importance on the following underlying mindsets and attitudes that form the foundation of our conduct.
  • A Hacker's Mindset
    • Enjoying problem-solving
    • Taking an interest in the problems faced by the team and by others
    • Understanding how things work
    • Thinking outside the box
    • Being willing to try different approaches
    • Maintaining curiosity and a spirit of inquiry, and continuously learning
    • Doing things correctly, one step at a time
  • Teamwork
    • Working toward a shared goal
    • Communicating in a frank, honest, sincere, and courteous manner
    • Following the rules
    • Respecting each individual
  • Taking Initiative and Working Autonomously
    • Placing importance on actions and facts aimed at resolving issues and achieving goals
  • Being Accountable
    • Being aware of the impact of one's own words and actions
  • Taking Ownership
    • Not settling merely for one's own area of responsibility or role, but having the drive to see the team, organization, and company as something you help build together
  • Maintaining Physical and Mental Well-being
Employment Type Full-time employee
3-month probationary period (no changes to working conditions during this period)
Work Location Ochanomizu First Building 5F, 2-5-1, Kanda Surugadai, Chiyoda-ku, Tokyo, Japan, 101-0062
Smoking Policy Indoor smoking is permitted in designated areas.
Working Hours
  • Flextime system
  • Standard working hours: 8 hours per day
  • Core hours: 11:00 AM – 2:00 PM
Working Style This is a hybrid position based in Tokyo.
While remote work is available depending on the project and team situation, regular attendance at the Tokyo office is required. Please note that all applicants must currently reside in Japan.
Holidays and Leave
  • 122 annual holidays
  • Complete two-day weekends (Saturdays and Sundays)
  • National holidays
  • Year-end and New Year holidays
  • Substitute holidays for national holidays falling on a Saturday
  • Paid leave: 20 to 22 days per year
  • Family-friendly leave (including marriage leave, maternity/paternity leave, prenatal checkup leave, childcare leave, child nursing leave, caregiving leave, bereavement leave, etc.)
Social Insurance
  • Employment Insurance
  • Health Insurance
  • Employees' Pension Insurance
  • Workers' Accident Compensation Insurance
Visa Requirements Applicants must be eligible to work in Japan.
While the company does not cover visa application fees or related costs, we will provide necessary documents and support required for the visa application process.
Salary Annual salary system
Benefits and Welfare
  • Defined contribution pension plan (401K)
  • Commuting allowance (according to company policy)
  • Housing allowance (according to company policy)
  • Payroll savings program ("Zaikei," a Japanese asset-formation savings scheme funded through payroll deduction), with additional contributions matched by the company
  • Support for obtaining professional certifications
  • Discounted rates for various insurance products
  • Congratulatory and condolence allowance
  • Flexible benefits program, administered through third-party welfare service providers (Relo Club, Benefit One)
  • Free office drinks
  • Many unofficial employee clubs (voluntary participation)
  • Employee Bug Bounty Program
Key Responsibilities As a member of the team, you will be engaged in network penetration testing services provided by Cyber Defense Institute.
On each engagement, the Penetration Test Operator works as part of the testing team alongside the Penetration Test Lead, supporting the Lead's responsibilities and contributing to delivering results to the client that are aligned with the objectives of the test.

The Penetration Test Operator is expected to fulfill the following roles:
  • Conduct testing in collaboration with the Penetration Test Lead and other team members
  • Support the responsibilities carried by the Penetration Test Lead, and take on part of those responsibilities as needed
  • Propose, research, and develop systems and tools necessary for conducting tests
  • Propose improvements to testing processes, documentation, or tools
Required Skills Candidates are expected to have at least two years of experience in the responsibilities described above under "Key Responsibilities," or to have acquired the following skills through self-directed study, including:
  • An understanding of common protocols at Layer 2 and above of the OSI reference model
  • Proficient OS operation skills
  • Programming ability
  • An understanding of, and practical ability in, common vulnerabilities and attack techniques
  • An understanding of attack techniques against systems using Active Directory
Preferred Skills If you do not have at least two years of experience in the responsibilities described above, it is preferable that you hold one of the following certifications, or are currently working toward obtaining one.
Any certifications you hold beyond those listed here will also be taken into consideration.
  • OSCP+
  • OSEP
  • OSWA
  • OSWE
  • CRTO
  • CRTP
  • GPEN
  • GWAPT
  • GCPN
  • GXPN
In addition, the following experience and skills will make you a more competitive candidate:
  • Program analysis
  • Protocol analysis
  • Development of offensive security tools
  • Understanding of cloud environments and cloud-specific attack techniques
  • Understanding of CI/CD and CI/CD-specific attack techniques
  • Experience building enterprise systems
Ideal Candidate Profile Cyber Defense Institute's Red Team Group supports and advises companies and organizations in their efforts to maintain or improve security by collectively providing the capabilities, perspective, and mindset of an attacker. Our Penetration Testing and Red Team services are two concrete expressions of this kind of support.

While technical, specialized, and cognitive abilities are naturally required to carry out this work of "collectively providing the capabilities, perspective, and mindset of an attacker," our group also places great importance on the following underlying mindsets and attitudes that form the foundation of our conduct.
  • A Hacker's Mindset
    • Enjoying problem-solving
    • Taking an interest in the problems faced by the team and by others
    • Understanding how things work
    • Thinking outside the box
    • Being willing to try different approaches
    • Maintaining curiosity and a spirit of inquiry, and continuously learning
    • Doing things correctly, one step at a time
  • Teamwork
    • Working toward a shared goal
    • Communicating in a frank, honest, sincere, and courteous manner
    • Following the rules
    • Respecting each individual
  • Taking Initiative and Working Autonomously
    • Placing importance on actions and facts aimed at resolving issues and achieving goals
  • Being Accountable
    • Being aware of the impact of one's own words and actions
  • Taking Ownership
    • Not settling merely for one's own area of responsibility or role, but having the drive to see the team, organization, and company as something you help build together
  • Maintaining Physical and Mental Well-being
Employment type
Full-time employee
3-month probationary period (no changes to working conditions during this period)
Work Location
Ochanomizu First Building 5F, 2-5-1, Kanda Surugadai, Chiyoda-ku, Tokyo, Japan, 101-0062
Smoking Policy
Indoor smoking is permitted in designated areas.
Working Hours
  • Flextime system
  • Standard working hours: 8 hours per day
  • Core hours: 11:00 AM – 2:00 PM
Working Style
This is a hybrid position based in Tokyo.
While remote work is available depending on the project and team situation, regular attendance at the Tokyo office is required. Please note that all applicants must currently reside in Japan.
Holidays and Leave
  • 122 annual holidays
  • Complete two-day weekends (Saturdays and Sundays)
  • National holidays
  • Year-end and New Year holidays
  • Substitute holidays for national holidays falling on a Saturday
  • Paid leave: 20 to 22 days per year
  • Family-friendly leave (including marriage leave, maternity/paternity leave, prenatal checkup leave, childcare leave, child nursing leave, caregiving leave, bereavement leave, etc.)
Social Insurance
  • Employment Insurance
  • Health Insurance
  • Employees' Pension Insurance
  • Workers' Accident Compensation Insurance
Visa Requirements
Applicants must be eligible to work in Japan.
While the company does not cover visa application fees or related costs, we will provide necessary documents and support required for the visa application process.
Salary
Annual salary system
Benefits and Welfare
  • Defined contribution pension plan (401K)
  • Commuting allowance (according to company policy)
  • Housing allowance (according to company policy)
  • Payroll savings program ("Zaikei," a Japanese asset-formation savings scheme funded through payroll deduction), with additional contributions matched by the company
  • Support for obtaining professional certifications
  • Discounted rates for various insurance products
  • Congratulatory and condolence allowance
  • Flexible benefits program, administered through third-party welfare service providers (Relo Club, Benefit One)
  • Free office drinks
  • Many unofficial employee clubs (voluntary participation)
  • Employee Bug Bounty Program
Key Responsibilities
As a member of the team, you will be engaged in network penetration testing services provided by Cyber Defense Institute.
On each engagement, the Penetration Test Operator works as part of the testing team alongside the Penetration Test Lead, supporting the Lead's responsibilities and contributing to delivering results to the client that are aligned with the objectives of the test.

The Penetration Test Operator is expected to fulfill the following roles:
  • Conduct testing in collaboration with the Penetration Test Lead and other team members
  • Support the responsibilities carried by the Penetration Test Lead, and take on part of those responsibilities as needed
  • Propose, research, and develop systems and tools necessary for conducting tests
  • Propose improvements to testing processes, documentation, or tools
Required Skills
Candidates are expected to have at least two years of experience in the responsibilities described above under "Key Responsibilities," or to have acquired the following skills through self-directed study, including:
  • An understanding of common protocols at Layer 2 and above of the OSI reference model
  • Proficient OS operation skills
  • Programming ability
  • An understanding of, and practical ability in, common vulnerabilities and attack techniques
  • An understanding of attack techniques against systems using Active Directory
Preferred Skills
If you do not have at least two years of experience in the responsibilities described above, it is preferable that you hold one of the following certifications, or are currently working toward obtaining one.
Any certifications you hold beyond those listed here will also be taken into consideration.
  • OSCP+
  • OSEP
  • OSWA
  • OSWE
  • CRTO
  • CRTP
  • GPEN
  • GWAPT
  • GCPN
  • GXPN
In addition, the following experience and skills will make you a more competitive candidate:
  • Program analysis
  • Protocol analysis
  • Development of offensive security tools
  • Understanding of cloud environments and cloud-specific attack techniques
  • Understanding of CI/CD and CI/CD-specific attack techniques
  • Experience building enterprise systems
Ideal Candidate Profile
Cyber Defense Institute's Red Team Group supports and advises companies and organizations in their efforts to maintain or improve security by collectively providing the capabilities, perspective, and mindset of an attacker. Our Penetration Testing and Red Team services are two concrete expressions of this kind of support.

While technical, specialized, and cognitive abilities are naturally required to carry out this work of "collectively providing the capabilities, perspective, and mindset of an attacker," our group also places great importance on the following underlying mindsets and attitudes that form the foundation of our conduct.
  • A Hacker's Mindset
    • Enjoying problem-solving
    • Taking an interest in the problems faced by the team and by others
    • Understanding how things work
    • Thinking outside the box
    • Being willing to try different approaches
    • Maintaining curiosity and a spirit of inquiry, and continuously learning
    • Doing things correctly, one step at a time
  • Teamwork
    • Working toward a shared goal
    • Communicating in a frank, honest, sincere, and courteous manner
    • Following the rules
    • Respecting each individual
  • Taking Initiative and Working Autonomously
    • Placing importance on actions and facts aimed at resolving issues and achieving goals
  • Being Accountable
    • Being aware of the impact of one's own words and actions
  • Taking Ownership
    • Not settling merely for one's own area of responsibility or role, but having the drive to see the team, organization, and company as something you help build together
  • Maintaining Physical and Mental Well-being

How to Apply

To apply, please agree to our Privacy Policy and contact us using the application form below.We will get back to you shortly.
Please note that we do not accept inquiries related to recruitment by phone.