勤務形態/Contract Type
正社員/Permanent Contract
部署の紹介/Department Introduction
English Follows Japanese
川崎市に本社を置く商用車業界のトップメーカーである三菱ふそうトラック・バス株式会社において、情報技術(IT)部門は全事業部門にわたるデジタルトランスフォーメーション(DX)推進の中核的役割を担っている。IT部門はコア業務と戦略的イノベーションの双方を支援する体制を構築しており、製造・エンジニアリングをはじめとする各プロセスへの先進技術のシームレスな導入を実現している。生産領域では、IoT技術・自動化・リアルタイムデータ分析を活用し、組立ラインの効率化、ダウンタイム削減、サプライチェーン可視化向上を図るスマートファクトリー構想を推進している。このデジタル基盤により、当社は激化するグローバル市場において高い生産性と機動力を維持できている。
当社のエンジニアリング、生産、品質管理の各部門において、IT部門はイノベーション、高精度化、業務効率の卓越化を戦略的に推進する役割を担っている。
エンジニアリング部門においてIT部門は、先進的なデジタルプラットフォームを通じて、コンセプト策定、設計開発、プロトタイピング、検証試験に至るまで、車両開発ライフサイクル全体を包括的に支援している。エンジニアは、高性能コンピューティング環境、統合CAD/CAEシステム、リアルタイム設計反復・シミュレーション機能、グローバルチーム間の部門横断的協働を可能にするコラボレーションツールを活用している。
生産部門では、ITが同社のスマートマニュファクチャリング構想を支えている。これには、組立工程の監視・最適化のための産業用IoT(IIoT)センサー、ロボティクス、AI駆動型解析技術の導入が含まれている。製造現場からのリアルタイムデータを収集・分析することで、設備故障の予測、工程ロスの削減、部品のジャストインタイム納入を実現している。これらの技術は生産効率向上に加え、エネルギー消費量と材料使用量の最小化を通じて、持続可能性目標の達成も支援している。
一方、品質管理部門では、自動検査システム、デジタル品質管理ダッシュボード、根本原因分析ツールを導入し、ITシステムが厳格な品質監視を保証している。これらのプラットフォームにより、予防的品質保証が可能となり、異常の早期検出、迅速な是正措置の実施、国際的な安全・環境規制への準拠を実現している。
Within Mitsubishi Fuso’s Engineering, Production, and Quality Management departments, the IT division serves as a strategic enabler of innovation, precision, and operational excellence. In Engineering, IT supports the full lifecycle of vehicle development—from concept and design to prototyping and validation—through advanced digital platforms.
Engineers rely on high-performance computing environments, integrated CAD/CAE systems, and collaborative tools that allow for real-time design iteration, simulation, and cross-functional teamwork across global teams. In the Production domain, IT underpins the company’s smart manufacturing initiatives. This includes the deployment of Industrial IoT (IIoT) sensors, robotics, and AI-driven analytics to monitor and optimize the assembly process. Real-time data from the shop floor is collected and analyzed to predict equipment failures, reduce waste, and ensure just-in-time delivery of components. These technologies not only improve efficiency but also support sustainability goals by minimizing energy consumption and material usage.
Meanwhile, in Quality Management, IT systems ensure rigorous oversight through automated inspection systems, digital quality dashboards, and root cause analysis tools. These platforms enable proactive quality assurance, allowing teams to detect anomalies early, implement corrective actions swiftly, and maintain compliance with global safety and environmental regulations. Together, these IT-driven capabilities empower Mitsubishi Fuso to deliver high-quality, innovative vehicles that meet the evolving needs of customers worldwide.
仕事内容/Job Description
English Follows Japanese
主な責任
組織のサイバーセキュリティ態勢を強化するため、高度なペネトレーションテストおよび脆弱性評価を実施します。
セキュリティの弱点を特定し、具体的な改善策を提案するための包括的なペネトレーションテスト戦略を策定・実行します。
部門横断的なチームと協力し、ペネトレーションテストの結果を幅広いサイバーセキュリティ戦略に統合します。
最新のサイバーセキュリティ脅威、ツール、手法に関する情報を常に更新し、テストの関連性と有効性を維持します。
すべてのテスト活動が規制基準やベストプラクティスに準拠することを確保します。
現実に即した攻撃シナリオをシミュレーションする技術的専門知識を提供し、システム防御を強化します。詳細なレポートを作成し、技術的および非技術的なステークホルダーに対して効果的に結果を伝えます。
テスト活動で得られた知見を活用し、インシデント対応計画の改善を支援します。
ペネトレーションテストにおける知識共有とベストプラクティスの構築を通じて、サイバーセキュリティの継続的な改善文化に積極的に貢献します。
主な業務内容:
エンタープライズのシステム・アプリケーション・データを保護する包括的なセキュリティアーキテクチャの設計・実装
ビジネス戦略およびリスク管理方針に沿ったセキュリティコントロールの構築
ビジネス目標に整合したData@Cloud戦略の設計・実装・継続的改善
アプリケーションおよびクラウドセキュリティにおける脅威の特定と対策立案(リスク低減への貢献)
全社的なリスク評価のリード、およびITリスク台帳の管理(対応計画・指標モニタリング含む)
ISO 27001、NIST CSF、SOX、PCI-DSS、GDPR等の規制・標準への継続的な準拠の確保
内部監査・外部監査の統括(監査対応、証跡管理、是正対応の推進)
サードパーティ/ベンダーリスク管理(デューデリジェンス、評価、リスク低減)
組織全体のリスク・コンプライアンス意識向上に向けた教育・啓発活動の推進
法務、IT、セキュリティ運用、内部監査などの関連部門との連携
IT/OTセキュリティ、車両セキュリティに関するアーキテクチャ判断の専門家としての役割
IAM、ネットワークセキュリティ、エンドポイント保護、暗号化などのセキュリティ技術の選定・設計
インフラチームと密に連携し、ITおよびビジネスシステムへのセキュリティ統合を推進
Build and enhance the organization's cybersecurity posture through advanced enterprise risk and compliance programs, and vulnerability assessments.
Develop and execute comprehensive Cybersecurity strategies to identify security weaknesses and recommend actionable remediation.
Collaborate with cross-functional teams to integrate risk mitigation into broader cybersecurity strategies.
Stay updated on the latest cybersecurity threats, tools, and methodologies to maintain testing relevance and effectiveness.
Ensure compliance with regulatory standards and best practices during all cyber security and IT activities.
Provide technical expertise in simulating real-world attack scenarios to strengthen system defenses.
Prepare detailed reports and communicate findings effectively to technical and non-technical stakeholders.
Support efforts to improve incident response plans by leveraging insights gained during testing activities.
Actively contribute to a culture of continuous improvement in cybersecurity by sharing knowledge and developing best practices for Cybersecurity.
Act as subject matter expert for security architecture decisions for IT, OT Security and Vehicle Security.
Select and design security technologies (IAM, network security, endpoint protection, encryption, etc.).
Key Responsibilities:
Design and implement a comprehensive security architecture that safeguards enterprise systems, applications, and data, aligning security controls with business objectives and risk management strategies.
Design, implement, and continuously improve the Data@Cloud strategy aligned with business objectives.
Identify threats for application and cloud security, and support the development of effective security countermeasures, contributing to risk mitigation.
Lead enterprise-wide risk assessments and manage the IT risk register, including treatment plans and monitoring of risk metrics.
Ensure ongoing compliance with industry regulations and standards (e.g., ISO 27001, NIST CSF, SOX, PCI-DSS, GDPR).
Oversee internal and external audits; manage audit responses, evidence collection, and remediation tracking.
Drive third-party/vendor risk management processes including due diligence, assessments, and risk mitigation.
Champion awareness and training programs to build a strong risk and compliance culture across the organization.
Collaborate with cross-functional teams including Legal, IT, Security Operations, and Internal Audit.
Act as a subject matter expert for security architecture decisions for IT, OT Security and Vehicle Security.
Select and design security technologies (IAM, network security, endpoint protection, encryption, etc.).
Ensure integration of security controls into IT and business systems in close collaboration with Infrastructure team.
募集要件/Requirement
English follows Japanese
当社では、エンタープライズ全体のリスクおよびコンプライアンスプログラムをリード・高度化できる、経験豊富な情報セキュリティアーキテクトを募集しています。
IT・ソフトウェア開発・サイバーセキュリティ分野において段階的に経験を積み(3~6年)、ITリスク評価やグローバル環境におけるステークホルダー連携の実績を有する方を歓迎します。
また、ISO 27001、NIST、SOX、GDPRなどの規制・標準に関する深い理解と、戦略的思考力が求められます。
必須資格:
大学卒以上(関連分野であれば尚可)
以下分野における3~6年の実務経験
ソフトウェア開発/ネットワーク
アプリケーションおよびコードセキュリティ
リスクアセスメント、脅威モデリング、成熟度評価
CSSLP(Certified Secure Software Lifecycle Professional)資格
社内アプリケーションおよびAPIのセキュリティ確保
ソフトウェア/車両エコシステムのセキュリティ理解
ITセキュリティとエンジニアリング/プロダクトチームの橋渡しができること
アプリケーションおよびクラウドセキュリティの脅威特定および対策導入の実績
ISO 27001/2、NIST、SOX、COBIT、GDPR等のフレームワーク・規制に関する理解
高い分析力、コミュニケーション能力、ステークホルダーマネジメント力
歓迎資格
AWS Certified Security Specialist
CISA、CRISC、CISMなどの関連資格
言語
英語ビジネスレベル以上
日本語初級レベル以上
We are seeking an experienced Information Security Architect to lead and mature our enterprise risk and compliance programs. The ideal candidate will have 3-6 years of progressive experience in IT, SW development and Cyber Security, IT risk assessments, and stakeholder engagement across global environments. This role requires strategic thinking and deep knowledge of regulatory and compliance landscapes such as ISO 27001, NIST, SOX, GDPR, and others.
Experience
Bachelor’s or Master’s degree or related field.
3-6 years of progressive experience, SW development / Network, Application & Code Security, Risk Assessment, Threat Modelling, Maturity Assessment.
CSSLP (Certified Secure Software Lifecycle Professional) is mandatory to secure internal applications and APIs, understand the Software/vehicle ecosystem security and Bridge IT security - engineering / product teams.
AWS Certified Security Specialist is beneficial.
Proven experience in identifying threats for application and cloud security, including development of effective security countermeasures, contributing to risk mitigation.
Strong understanding of relevant frameworks and regulations (ISO 27001/2, NIST, SOX, COBIT, GDPR, etc.).
Excellent analytical, communication, and stakeholder management skills.
Preferred Certifications:
CISA, CRISC, CISM, or similar.
Languages
English: Business level or higher
Japanese: Beginner level or higher
労働条件/Working Condition
English follows Japanese
■ 勤務地
本社/川崎製作所第一敷地
住所:神奈川県川崎市中原大倉町10番地
最寄駅1:東急東横線「元住吉」駅 および JR「新川崎」駅より無料シャトルバス運行
最寄駅2:JR「平間」駅より徒歩10分
その他:自動車/自転車/オートバイ通勤も可能
■ 勤務時間
8:00-17:00
フレックスタイム制 ※コアタイム無し
リモートワーク可
■ 休日休暇
年間休日:121日(2026年)
完全週休2日制(土曜、日曜)、祝祭日(会社カレンダーに準ずる)
年次有給休暇、慶弔休暇、産前産後育児休暇、介護休暇など
■ 給与
基本給
賞与:年2回支給
手当:通勤手当、モバイルワーク手当、残業手当、子供手当、住宅手当、退職金制度(DC pension)等
※知識・経験を考慮して最終的に決定
※残業手当など各種手当は別途支給
■ Location
HQ/Kawasaki Plant 1st Premises
Address: 10 Okura-cho, Nakahara-ku, Kawasaki-shi, Kanagawa
Station 1: Company shuttle bus from Tokyu-Toyoko Line "Motosumiyoshi" station and HR "Shinkawasaki" station
Station 2: Approx 10 min walk from JR "Hirama" station
Others: Commuting by car, bicycle, or motor bike is also an option
■ Working Hours
8:00-17:00
Flexible working hours without "Core Time"
Mobile Work Policy
■ Holiday
Annual holiday: 121 days (2026)
Saturdays, Sundays and national holidays (Based on company calendar)
Paid holiday, Congratulatory and Condolence leave, Maternity leave, Nursing care leave etc...
■ Salary
Base Salary
Bonus : Twice a year
Allowance: Commuting, Mobile Work, Overtime, Child, Housing, DC pension etc..
*Salary will be decided based on knowledge and experience
*Allowances to be paid on top of the base salary