Principal AI Risk Management Specialist - AI Governance Management Section, Information Security & Privacy Governance Department (ISPD)
RakutenJob Description:
Business Overview
The Technology Management Division (TMD) provides corporate IT, cyber security, and privacy governance to Rakuten Group companies and essential business management for technology organizations, thereby enabling innovation and strengthening its technology foundation. Within TMD, the Information Security Supervisory Department (ISSD) combines proactive cyber defense with strategic information security, privacy, and data governance to protect the company’s global assets and data.
Department Overview
The Information Security & Privacy Governance Department (ISPD) enables and accelerates business growth by establishing, maintaining, and enhancing robust information security, privacy, data, and AI governance frameworks across the Rakuten Group. We ensure Rakuten's global operations are secure, compliant, and innovative by adhering to regulatory requirements, providing comprehensive employee training, strategically managing data assets, and governing AI responsibly.
The AI Governance Management Section is responsible for designing and operating AI governance policies, risk management frameworks, operational processes, and technical controls to ensure the safe and responsible use of Artificial Intelligence throughout the Rakuten Group.
As AI technologies continue to evolve rapidly, organizations face increasingly complex risks related to regulatory compliance, information security, privacy, data protection, and AI ethics. The AI Governance Management Section works closely with engineering teams, business units, legal organizations, and executive leadership to strengthen AI governance across the Rakuten Group.
Position:
Why We Hire
This is a senior-level position responsible for advancing AI risk management and AI governance across the Rakuten Group.
Rather than serving as an operational reviewer of standard AI risk assessment requests, this role focuses on AI system architecture reviews, AI security assessments, AI risk management process design, and the development and promotion of the Group-wide AI governance model.
The successful candidate will serve as a Tier-2/Tier-3 reviewer for high-risk AI initiatives, evaluating solutions from both technical and operational perspectives while providing expert guidance to engineering and business organizations.
As a core member of the Group CISO organization, this role will contribute to the development and execution of Rakuten Group's AI Governance strategy.
Position Details
・Lead risk assessments for AI system architectures and security architecture reviews
・Assess AI system data flows, access management, and external AI service integrations
・Develop AI governance frameworks and support ongoing governance improvement
・Define and enhance AI risk management processes, governance requirements, control standards, and operational procedures
・Build and maintain system inventories, risk management frameworks, and continuous monitoring mechanisms
・Establish AI incident management and reporting procedures
・Conduct Tier-2 / Tier-3 risk reviews for high-risk initiatives and support mitigation planning and implementation
Mandatory Qualifications:
A combined total of 8 or more years of experience in one or more of the following areas:
・ Information Security Governance
・ Security Architecture
・ Cloud Security
・ IT Architecture
・ Technology Risk Management
・ Enterprise Architecture
・ AI/Machine Learning System Development
Knowledge and/or practical experience in one or more of the following:
・ Governance framework design
・ Risk assessment methodologies
・ Security control design
・ Policy and standard development
・ Collaboration and stakeholder management across engineering, business, and executive organizations, Incident response
Desired Qualifications:
・ CISSP, CISM, CCSP and Registered Information Security Specialist (RISS) or equivalent security certifications
・ AWS, Microsoft Azure, Google Cloud Security certifications
・ AIGP, AAIA, AAISM, AAIR (ISACA)
・ AI platform development
・ Security architect
・ Privacy engineering
・ AI Safety assessments
・ Security, Privacy, and AI regulatory compliance programs in global environments
#business #informationsecurity #privacygovernance #AI #technologymanagementdiv
Languages:
English (Overall - 3 - Advanced), Japanese (Overall - 4 - Fluent)