Senior Product Security Engineer
About Mico
Mico's mission is to empower every brand by building lifetime trust through humanlike technology. By 2030, we aim to be Asia's No.1 Brand Empowerment Company. Mico builds the conversational layer Japanese brands use to reach their customers — LINE, SMS/RCS, Voice AI and web — for more than 5,500 companies across finance, insurance, retail and real estate.
Our four core values guide everything we do:
- Wow the Customer
- Invest in Passion
- Beyond Borders
- Be the Change
About the Role
Most security engineers defend a platform. You will build the agents that defend one — for 5,500+ brands in finance, insurance and retail, and for the AI that talks to their customers.
Three things make security engineering at Mico different from most product companies:
- Regulated industries set the bar, and it's a high one. Finance, insurance and real-estate clients require us to meet their regulators' standards for protecting both their data and their end users'. Data protection is a board-level subject here, not an engineering afterthought.
- We build AI products, so we secure AI products. Mico's agents act on our customers' behalf. Guardrails, tool-use authorization and adversarial testing are a discipline the whole industry is still writing the playbook for — we'd rather help write it than wait for it.
- AI-assisted development, secured. As more of our software is built with AI, securing how we build matters as much as securing what we ship.
We hold ISMS (ISO 27001) and Japan's Privacy Mark certification, and we work to OWASP and MITRE ATLAS guidance for the AI we ship. We're now investing in a dedicated product security function, designed agent-first, with executive sponsorship and a place in the company's half-year objectives. This role is the senior engineer for that function — you'll shape how it works rather than inherit how it's always been done, with a mandate and budget already in place.
What You'll Do
Build and run the security agents. Design, build and operate the security agents on the Claude Agent SDK with MCP tool integrations, starting with PR Sentinel and DepGuard, then outward across the lifecycle.
- Wrap the scanners we buy so they become one coherent, low-noise signal rather than seven disconnected dashboards.
- Evaluate and red-team your own agents — false negatives and prompt injection against a security agent are your problem to catch.
- Automate the first response to customer security questionnaires, so an enterprise buyer gets a substantive answer in hours.
Secure what we build. Threat-model high-risk features — new data flows, AI capabilities, auth and identity changes — before code exists.
- Own SAST, secret scanning, dependency and supply-chain security in CI, with SLAs on critical and high findings.
- Run vulnerability assessment in-house: DAST, API security testing, and hands-on penetration testing of our own products.
- Review application code and API designs, and make cross-tenant isolation structurally impossible to get wrong.
- Scope and manage external specialists where they earn their cost — crown-jewel penetration tests, independent assessments — and hold their output to a standard.
- Raise the level of the engineers around you: security champions in every squad, practical training, and reference material people actually use.
- Supply the technical evidence behind our ISMS and customer audits. The certification program is owned by our security team in Japan — you make it defensible.
Secure what we ship (AI / LLM).
- Red-team Mico's own AI agents: