Recruitment|Web Application Testing Engineer

Selection Process

Step. 1 Document Screening

Please submit your resume, work history (CV), and portfolio. Based on the materials you provide, we will comprehensively review your background, skills, and motivation for applying.
We will typically notify you of the results of the document screening by email within one to two weeks.

Step. 2 Aptitude Test

We conduct a standardized aptitude test (commonly used in Japanese hiring, known as the SPI test).
This is used as an opportunity for us to get to know each other from a perspective distinct from technical skills and experience.

Step. 3 First Interview

This interview is conducted by a member of our team. We will ask about your past experience, your approach to work, and your reasons for wanting to join our company, using this as an opportunity to deepen mutual understanding.

Step. 4 Technical Assessment

By having you work on a task that closely resembles actual on-the-job work, we assess not only your knowledge and skills but also how you approach challenges and your thought process.
This is conducted either online or in person, with the level of difficulty adjusted according to the position you are applying for.

Step. 5 Second Interview

Based on the first interview and technical assessment, this interview is conducted primarily by the manager of the department you would be assigned to.
We will discuss in more concrete terms your fit with the team and your suitability for the actual work involved.

Step. 6 Final Interview

This interview is conducted by a member of our executive management or board of directors. We will share our company's vision and future direction while confirming final mutual intent.
We aim to proceed carefully so that both parties can reach a mutual understanding and start off on a positive note.

※Please note that the selection process may vary depending on the position and the status of applications.

Penetration Test Lead
Penetration Test Operator
Employment Type Full-time employee
3-month probationary period (no changes to working conditions during this period)
Work Location Ochanomizu First Building 5F, 2-5-1, Kanda Surugadai, Chiyoda-ku, Tokyo, Japan, 101-0062
Smoking Policy Indoor smoking is permitted in designated areas.
Working Hours
  • Flextime system
  • Standard working hours: 8 hours per day
  • Core hours: 11:00 AM – 2:00 PM
Working Style This is a hybrid position based in Tokyo.
While remote work is available depending on the project and team situation, regular attendance at the Tokyo office is required. Please note that all applicants must currently reside in Japan.
Holidays and Leave
  • 122 annual holidays
  • Complete two-day weekends (Saturdays and Sundays)
  • National holidays
  • Year-end and New Year holidays
  • Substitute holidays for national holidays falling on a Saturday
  • Paid leave: 20 to 22 days per year
  • Family-friendly leave (including marriage leave, maternity/paternity leave, prenatal checkup leave, childcare leave, child nursing leave, caregiving leave, bereavement leave, etc.)
Social Insurance
  • Employment Insurance
  • Health Insurance
  • Employees' Pension Insurance
  • Workers' Accident Compensation Insurance
Visa Requirements Applicants must be eligible to work in Japan.
While the company does not cover visa application fees or related costs, we will provide necessary documents and support required for the visa application process.
Salary Annual salary system
Benefits and Welfare
  • Defined contribution pension plan (401K)
  • Commuting allowance (according to company policy)
  • Housing allowance (according to company policy)
  • Payroll savings program ("Zaikei," a Japanese asset-formation savings scheme funded through payroll deduction), with additional contributions matched by the company
  • Support for obtaining professional certifications
  • Discounted rates for various insurance products
  • Congratulatory and condolence allowance
  • Flexible benefits program, administered through third-party welfare service providers (Relo Club, Benefit One)
  • Free office drinks
  • Many unofficial employee clubs (voluntary participation)
  • Employee Bug Bounty Program
Key Responsibilities
  • Web Application Security Testing
    • Conduct vulnerability assessments of web applications
    • Perform security testing on systems requested by clients, spanning both public and private sector organizations
    • Discover and verify vulnerabilities using tools such as Burp Suite
  • Report Writing
    • Prepare preliminary findings and formal reports (including summaries, overviews, and detailed vulnerability descriptions)
    • Produce technical yet accessible documentation grounded in a genuine risk assessment from an attacker's perspective
  • Development and Improvement of Testing Methodologies
    • Research and develop new testing approaches
    • Establish testing methodologies that incorporate the latest technologies, including the use of AI
  • Client-Facing Work (for those with roughly 2–3 years of experience or more; open for discussion)
    • Serve as the technical point of contact, handling coordination with clients
Required Skills
  • Ability to communicate smoothly in Japanese
  • A genuine interest in and enthusiasm for technology, including computers and security


In addition, candidates should demonstrate strength in at least one of the following areas:

  • Holding a Web Application Testing–Related Certification of a Certain Level of Difficulty
    • BSCP(Burp Suite Certified Practitioner)
    • OSWA
    • Other certifications of an equivalent level
  • Ongoing External Technical Activities
    • Regular participation in CTF competitions
    • Writing technical blog posts or articles
    • Speaking at conferences
    • Contributing to open-source software (OSS)
    • Organizing or running security-related study groups or communities
  • Strong Foreign Language Ability
    • Particularly the ability to communicate in English
  • Other Technical Knowledge
    • Knowledge of computer science fundamentals (operating systems, networking, programming)
    • Knowledge of the HTTP protocol (RFC 7230, 7231, 7232, 7233, 7234, 7235 ≒ RFC 2616)
    • Ability to write and review code in scripting languages (PHP, Python, shell scripting, Perl, etc.)
    • Ability to write and review code in C, C++, Java, and similar languages
    • Knowledge of network protocols (e.g., TCP/IP, routing)
    • Understanding of two or more operating systems (e.g., Android, Linux, macOS, Windows)
    • Experience in code auditing, application testing, web application security testing, and similar work
    • Knowledge of protocols related to authentication and cryptography (PKI, 802.1X, TLS, LDAP, RADIUS, Kerberos)
    • Knowledge of building, developing, executing, and mitigating exploits and similar environments
    • Knowledge of FPGA programming and the hardware layer
Preferred Skills
  • BSCP, OSWA, OSWE, CEH, or other security-related certifications
  • The ability to read technical documents and communicate in English is a further plus
Ideal Candidate Profile
  • Those Who Want to Grow Together with Their Colleagues
    • We aim to achieve a level of testing sophistication that no individual could reach alone by sharing and discussing each person's high level of technical skill as a team. We place great importance on generously sharing your own knowledge with others, as well as on maintaining a willingness to learn from your colleagues.
  • Those Who Often Lose Themselves in What They Love
    • We are looking for people who can pursue a technical challenge until they are fully satisfied with the outcome.
  • Those Who Want to Contribute to Society Through Their Technical Skills
    • We are looking for people who carry a genuine desire to make society safer through the work of security testing.
Employment type
Full-time employee
3-month probationary period (no changes to working conditions during this period)
Work Location
Ochanomizu First Building 5F, 2-5-1, Kanda Surugadai, Chiyoda-ku, Tokyo, Japan, 101-0062
Smoking Policy
Indoor smoking is permitted in designated areas.
Working Hours
  • Flextime system
  • Standard working hours: 8 hours per day
  • Core hours: 11:00 AM – 2:00 PM
Working Style
This is a hybrid position based in Tokyo.
While remote work is available depending on the project and team situation, regular attendance at the Tokyo office is required. Please note that all applicants must currently reside in Japan.
Holidays and Leave
  • 122 annual holidays
  • Complete two-day weekends (Saturdays and Sundays)
  • National holidays
  • Year-end and New Year holidays
  • Substitute holidays for national holidays falling on a Saturday
  • Paid leave: 20 to 22 days per year
  • Family-friendly leave (including marriage leave, maternity/paternity leave, prenatal checkup leave, childcare leave, child nursing leave, caregiving leave, bereavement leave, etc.)
Social Insurance
  • Employment Insurance
  • Health Insurance
  • Employees' Pension Insurance
  • Workers' Accident Compensation Insurance
Visa Requirements
Applicants must be eligible to work in Japan.
While the company does not cover visa application fees or related costs, we will provide necessary documents and support required for the visa application process.
Salary
Annual salary system
Benefits and Welfare
  • Defined contribution pension plan (401K)
  • Commuting allowance (according to company policy)
  • Housing allowance (according to company policy)
  • Payroll savings program ("Zaikei," a Japanese asset-formation savings scheme funded through payroll deduction), with additional contributions matched by the company
  • Support for obtaining professional certifications
  • Discounted rates for various insurance products
  • Congratulatory and condolence allowance
  • Flexible benefits program, administered through third-party welfare service providers (Relo Club, Benefit One)
  • Free office drinks
  • Many unofficial employee clubs (voluntary participation)
  • Employee Bug Bounty Program
Key Responsibilities
  • Web Application Security Testing
    • Conduct vulnerability assessments of web applications
    • Perform security testing on systems requested by clients, spanning both public and private sector organizations
    • Discover and verify vulnerabilities using tools such as Burp Suite
  • Report Writing
    • Prepare preliminary findings and formal reports (including summaries, overviews, and detailed vulnerability descriptions)
    • Produce technical yet accessible documentation grounded in a genuine risk assessment from an attacker's perspective
  • Development and Improvement of Testing Methodologies
    • Research and develop new testing approaches
    • Establish testing methodologies that incorporate the latest technologies, including the use of AI
  • Client-Facing Work (for those with roughly 2–3 years of experience or more; open for discussion)
    • Serve as the technical point of contact, handling coordination with clients
Required Skills
  • Ability to communicate smoothly in Japanese
  • A genuine interest in and enthusiasm for technology, including computers and security


In addition, candidates should demonstrate strength in at least one of the following areas:

  • Holding a Web Application Testing–Related Certification of a Certain Level of Difficulty
    • BSCP(Burp Suite Certified Practitioner)
    • OSWA
    • Other certifications of an equivalent level
  • Ongoing External Technical Activities
    • Regular participation in CTF competitions
    • Writing technical blog posts or articles
    • Speaking at conferences
    • Contributing to open-source software (OSS)
    • Organizing or running security-related study groups or communities
  • Strong Foreign Language Ability
    • Particularly the ability to communicate in English
  • Other Technical Knowledge
    • Knowledge of computer science fundamentals (operating systems, networking, programming)
    • Knowledge of the HTTP protocol (RFC 7230, 7231, 7232, 7233, 7234, 7235 ≒ RFC 2616)
    • Ability to write and review code in scripting languages (PHP, Python, shell scripting, Perl, etc.)
    • Ability to write and review code in C, C++, Java, and similar languages
    • Knowledge of network protocols (e.g., TCP/IP, routing)
    • Understanding of two or more operating systems (e.g., Android, Linux, macOS, Windows)
    • Experience in code auditing, application testing, web application security testing, and similar work
    • Knowledge of protocols related to authentication and cryptography (PKI, 802.1X, TLS, LDAP, RADIUS, Kerberos)
    • Knowledge of building, developing, executing, and mitigating exploits and similar environments
    • Knowledge of FPGA programming and the hardware layer
Preferred Skills
  • BSCP, OSWA, OSWE, CEH, or other security-related certifications
  • The ability to read technical documents and communicate in English is a further plus
Ideal Candidate Profile
  • Those Who Want to Grow Together with Their Colleagues
    • We aim to achieve a level of testing sophistication that no individual could reach alone by sharing and discussing each person's high level of technical skill as a team. We place great importance on generously sharing your own knowledge with others, as well as on maintaining a willingness to learn from your colleagues.
  • Those Who Often Lose Themselves in What They Love
    • We are looking for people who can pursue a technical challenge until they are fully satisfied with the outcome.
  • Those Who Want to Contribute to Society Through Their Technical Skills
    • We are looking for people who carry a genuine desire to make society safer through the work of security testing.

How to Apply

To apply, please agree to our Privacy Policy and contact us using the application form below.We will get back to you shortly.
Please note that we do not accept inquiries related to recruitment by phone.