Independent Partner Network独立パートナーネットワーク

IT Audit PartnerIT監査パートナー

For independent, senior IT auditors who read infrastructure and pipeline evidence directly rather than relying on screenshots and self-reported narratives.スクリーンショットや自己申告のみに頼らず、インフラやパイプラインのエビデンスを直接読み解ける、独立系シニアIT監査人のための職種です。

IT Solutions & Security DivisionITソリューション&セキュリティ部門
Tokyo — Remote / Hybrid / On-Site東京 — リモート・ハイブリッド・オンサイト
Business Outsourcing Agreement (業務委託契約)業務委託契約
IT Audit & Assurance FocusIT監査・保証業務特化

About This Role本職種について

The IT Solutions & Security Division engages independent IT auditors for formal audit engagements — ISMS/ISO 27001 internal audits, SCS Evaluation System assessments, IT general controls testing, and third-party audit readiness support — for Japan-market clients across financial services, manufacturing, and technology.ITソリューション&セキュリティ部門は、ISMS/ISO 27001内部監査、SCS評価制度アセスメント、IT全般統制テスト、第三者監査対応準備支援など、正式な監査業務のために独立系IT監査人と契約します。対象は金融、製造業、テクノロジー業界の日本市場クライアントです。

This is a B2B partnership under a Business Outsourcing Agreement (業務委託契約), not an employment relationship.本募集は業務委託契約に基づくB2Bパートナーシップであり、雇用関係ではありません。

Scope of Engagements業務範囲

Potential engagements may include:想定される業務内容:

ISMS / ISO 27001 internal audit execution, independent of the client's own operations teamクライアントの運用チームから独立した、ISMS/ISO 27001内部監査の実施
SOC 2 and IT general controls (ITGC) testing for cloud-native SaaS environmentsクラウドネイティブSaaS環境におけるSOC 2およびIT全般統制(ITGC)テスト
Reading Infrastructure-as-Code (Terraform, IaC modules) and CI/CD pipeline logs directly as audit evidence監査エビデンスとして、Infrastructure as Code(Terraform、IaCモジュール)およびCI/CDパイプラインログを直接確認
SCS Evaluation System (★2 / ★3) supplier assessment supportSCS評価制度(★2/★3)のサプライヤー評価支援
Audit bidding and tender documentation support for public and corporate procurement processes公共・企業調達プロセスにおける監査入札・書類作成支援
IT audit readiness assessments and remediation-plan development ahead of certification renewal認証更新前のIT監査準備状況評価および是正計画の策定
Evidence-quality evaluation — distinguishing system-generated evidence (logs, signed artifacts) from self-reported claimsシステム生成エビデンス(ログ、署名済み成果物)と自己申告情報を区別する、エビデンス品質評価

What We Look For求める人物像

5+ years of formal IT audit experience, ideally spanning both traditional control-testing methods and modern cloud-native / DevOps environments.正式なIT監査業務における5年以上の実務経験。従来型の統制テスト手法と、モダンなクラウドネイティブ・DevOps環境の双方に精通していることが望ましい。

CISA certification strongly preferred; ISO 27001 Lead Auditor a significant plusCISA資格を強く推奨。ISO 27001リードオーディター資格は大きなプラス
Comfort reading JSON/YAML configuration exports, Terraform plans, and CI/CD build logs as primary evidenceJSON/YAML設定エクスポート、Terraformプラン、CI/CDビルドログを主要エビデンスとして読み解けること
Experience conducting sampling for both point-in-time and continuously-operating (automated) controls一時点統制と継続稼働(自動化)統制の双方に対するサンプリング実施経験
Track record of producing audit workpapers and findings reports that hold up externally with regulators規制当局に対しても通用する監査調書・結果報告書の作成実績
English required; business-level Japanese a strong advantage for client-facing engagements in Japan英語必須。日本国内でのクライアント対応業務において、ビジネスレベルの日本語は大きなアドバンテージ

Engagement Model契約形態

Audit engagements are typically scheduled around certification renewal dates, tender deadlines, or client evidence requests, and usually run 2–8 weeks depending on scope.監査案件は通常、認証更新日、入札締切、クライアントからのエビデンス依頼に合わせてスケジュールされ、スコープに応じて通常2〜8週間で実施されます。

Remote evidence review supplemented by on-site interviews and testing where required必要に応じて、オンサイトでのヒアリング・テストを補完するリモートでのエビデンスレビュー
You are named as the auditor of record on findings you personally test and sign offご自身が直接テストし承認した結果については、監査担当者として記名されます

Commercial Terms & Invoicing商業条件・請求

Compensation is agreed on an engagement-by-engagement basis, considering scope, seniority, duration, and specialist scarcity. Terms are agreed before the engagement begins.報酬は案件ごとに、スコープ、シニアリティ、期間、専門性の希少性を考慮して合意されます。条件は案件開始前に合意されます。

Daily or hourly consulting rates, fixed project fees, or defined workstream fees日次・時間単価、固定プロジェクト報酬、または業務範囲別報酬
No requirement to accept every opportunity presented提示されたすべての案件を受諾する義務はありません
Global Access manages client onboarding, contracting, and invoicing directlyクライアントのオンボーディング、契約、請求はGlobal Accessが直接管理
Partners issue their own business invoices per the Business Outsourcing Agreementパートナーは業務委託契約に基づき、自身で事業者請求書を発行
Partners are responsible for their own tax, accounting, insurance, and licensing obligations納税、会計、保険、免許等の義務はパートナー自身が負担

What Partners Can Expectパートナーが得られること

Access to enterprise and multinational client opportunities matched to your specialist capabilities貴社の専門性に合致した、エンタープライズ・多国籍企業クライアントへのアクセス機会
Freedom to choose projects that fit your expertise, availability, and commercial expectations専門性、稼働可能状況、商業条件に合った案件を選択する自由
Remote, on-site in Tokyo, or hybrid delivery depending on client requirementsクライアント要件に応じたリモート、東京都内オンサイト、またはハイブリッドでの提供
Collaboration with other experienced specialists as part of multidisciplinary delivery teams多職種混成の提供チームの一員として、他の経験豊富な専門家との協業
Global Access handles client onboarding, contracting, and invoicing so you focus on deliveryクライアントのオンボーディング、契約、請求業務はGlobal Accessが担当し、貴社は提供業務に集中可能
Access to a curated professional network for knowledge-sharing and cross-referred opportunities知見共有や相互紹介の機会を含む、厳選された専門家ネットワークへのアクセス

What Success Looks Like成功の定義

A successful engagement should leave the client with clarity on the following.成功する案件は、クライアントに以下について明確な理解をもたらすものでなければなりません。

What the problem is — the specific weakness, gap, threat, or opportunity identified問題の所在 — 特定された具体的な弱点、ギャップ、脅威、または機会
Why it matters — technical findings translated into business consequences or measurable value重要性の理由 — 技術的な発見事項をビジネス上の影響または測定可能な価値に変換
What level of risk the organization is accepting (unresolved, accepted, mitigated, transferred, or residual)組織が許容しているリスクレベル(未解決、受容済み、軽減済み、移転済み、残存)
What should be done — practical, prioritized recommendations appropriate to the client's environment実施すべき対応 — クライアントの環境に適した、実践的で優先順位付けされた提言
How the recommendation can realistically be implemented, given budget and organizational readiness現実的な実装方法 — 予算や組織の準備状況を考慮した実現可能性
How improvement can be measured — control improvements, maturity indicators, or cost savings改善の測定方法 — 統制の改善、成熟度指標、コスト削減などの評価指標

Diversity & Inclusion多様性と包括性

Global Access Incorporated welcomes independent professionals and boutique firms from a wide range of technical, industry, and professional backgrounds.Global Access Incorporatedは、幅広い技術・業界・専門的背景を持つ独立専門家およびブティックファームを歓迎します。

How to Apply応募方法

Join the Networkパートナーネットワークへの参加

Send a brief overview of your background — your core expertise, relevant frameworks and certifications, years of experience, current availability, and preferred engagement model. Applications are reviewed on a rolling basis; qualified specialists are invited to an exploratory conversation.ご専門分野、関連するフレームワーク・資格、実務経験年数、現在の稼働可能状況、ご希望の契約形態について、簡単な経歴概要をお送りください。応募は随時審査し、条件に合う方には個別に事前対談のご案内をいたします。

Please Includeご記載いただきたい内容

  • Core areas of expertise and preferred frameworksコア専門分野および得意とするフレームワーク
  • Relevant certifications and years of experience関連資格および実務経験年数
  • Enterprise or multinational client experienceエンタープライズ・多国籍企業でのクライアント経験
  • Current availability and preferred engagement model現在の稼働可能状況およびご希望の契約形態
  • Japanese language level, if applicable日本語レベル(該当する場合)
An exploratory conversation does not guarantee a project engagement. Specific opportunities depend on client requirements, partner suitability, availability, and mutually agreed commercial terms. 事前対談は、プロジェクトへの参画を保証するものではありません。個別の機会は、クライアント要件、パートナーとしての適性、稼働状況、および合意された商業条件に基づき決定されます。

This is a B2B partnership inquiry, not a job application in the employment sense.本フォームはB2Bパートナーシップに関するお問い合わせであり、雇用契約に基づく応募ではありません。

Important Legal Notice重要法的通知

Global Access Incorporated (株式会社 GLOBAL ACCESS) is a professional services company. This partnership opportunity is offered through the IT Solutions & Security Division and is intended for independent contractors, security professionals, IT auditors, consultants, AI specialists, technology professionals, transformation consultants, and boutique consulting firms to collaborate on project-based B2B service engagements. 株式会社GLOBAL ACCESS(Global Access Incorporated)は専門サービス企業です。本パートナーシップの機会はITソリューション&セキュリティ部門を通じて提供されるものであり、独立した契約者、セキュリティ専門家、IT監査人、コンサルタント、AI専門家、テクノロジー専門家、トランスフォーメーションコンサルタント、およびブティックコンサルティングファームが、プロジェクトベースのB2Bサービス契約において協業することを目的としています。

This is not an offer of employment and does not create or imply an employment relationship. It does not constitute recruitment, introduction, or placement of personnel for third-party companies. All engagements are governed by individual Business Outsourcing Agreements (業務委託契約 / Gyōmu Itaku) between Global Access Incorporated and the applicable contracting partner entity. No employment contract (労働契約 / Rōdō Keiyaku) is created or implied. 本募集は雇用の申し込みではなく、雇用関係を創出または示唆するものでもありません。第三者企業への人材の紹介、あっせん、または配置を構成するものでもありません。すべての契約は、Global Access Incorporatedと契約パートナー法人との間の個別の業務委託契約に基づいて管理されます。雇用契約(労働契約)は作成も黙示もされません。

The partner remains an independent business and is responsible for its own tax obligations, accounting, insurance, licenses, certifications, and other legal and regulatory requirements applicable to its business. Nothing in this description guarantees a minimum volume of work, minimum compensation, or a particular number of project engagements. パートナーは独立した事業者としての立場を維持し、自らの納税義務、会計処理、保険、免許、資格、その他事業に適用される法的・規制上の要件について責任を負います。本募集要項のいかなる記載も、最低業務量、最低報酬、または一定数のプロジェクト参画を保証するものではありません。