Independent Partner Network独立パートナーネットワーク

Security Risk & Compliance Partnerセキュリティリスク・コンプライアンスパートナー

For independent GRC practitioners who build risk management programs and translate regulatory frameworks into practical, board-defensible controls.リスク管理プログラムを構築し、規制フレームワークを実践的で取締役会に説明可能な統制へと落とし込む、独立系GRC専門家のための職種です。

IT Solutions & Security DivisionITソリューション&セキュリティ部門
Tokyo — Remote / Hybrid / On-Site東京 — リモート・ハイブリッド・オンサイト
Business Outsourcing Agreement (業務委託契約)業務委託契約
GRC / Risk Management FocusGRC・リスク管理特化

About This Role本職種について

The IT Solutions & Security Division is looking for independent risk and compliance specialists to lead security risk assessments, build or mature risk management programs, and help clients translate regulatory requirements into concrete, actionable controls — not just a compliance checklist.ITソリューション&セキュリティ部門は、セキュリティリスク評価の実施、リスク管理プログラムの構築・成熟化、そして規制要件を単なるコンプライアンスチェックリストではなく、具体的で実行可能な統制へと落とし込むことができる、独立系リスク・コンプライアンス専門家を求めています。

This is a B2B partnership under a Business Outsourcing Agreement (業務委託契約), not an employment relationship. You manage your own pipeline and availability; Global Access manages client contracting and invoicing.本募集は業務委託契約に基づくB2Bパートナーシップであり、雇用関係ではありません。ご自身のパイプラインと稼働状況はご自身で管理いただき、クライアントとの契約・請求はGlobal Accessが担当します。

Scope of Engagements業務範囲

Potential engagements may include:想定される業務内容:

Enterprise and technology risk assessments, including risk identification, scoring, and treatment planningリスクの特定・スコアリング・対応計画を含む、エンタープライズ・テクノロジーリスク評価
Risk management framework design and implementation (NIST CSF, ISO 27001, ISO 27002)リスク管理フレームワークの設計・導入(NIST CSF、ISO 27001、ISO 27002)
Security policy and standards development, and security governance program designセキュリティポリシー・基準の策定、およびセキュリティガバナンスプログラムの設計
Risk register development and board/executive risk reportingリスク登録簿の作成、および取締役会・経営層向けリスク報告
Regulatory readiness assessments and compliance-gap remediation planning規制対応準備状況評価、およびコンプライアンスギャップの是正計画
Third-party and vendor risk program design (complementing our TPRM service line)サードパーティ・ベンダーリスクプログラムの設計(当社TPRMサービスラインを補完)
Security control design and control-effectiveness assessmentsセキュリティ統制の設計、および統制の有効性評価
Security transformation programme advisory for organizations building GRC capability from scratchGRC体制をゼロから構築する組織向けのセキュリティトランスフォーメーションプログラム支援

What We Look For求める人物像

5+ years of hands-on GRC, risk management, or security advisory experience, with a track record of building programs clients actually use — not just delivering a framework document that sits on a shelf.GRC、リスク管理、またはセキュリティアドバイザリー分野における5年以上の実務経験。棚に眠るフレームワーク文書の納品ではなく、クライアントが実際に使用するプログラムを構築してきた実績。

Deep working knowledge of NIST CSF, ISO 27001/27002, and risk quantification methodsNIST CSF、ISO 27001/27002、リスク定量化手法に関する深い実務知識
Experience translating regulatory text (e.g. APPI, sector-specific guidance) into engineering-level controlsAPPIや業界固有ガイダンス等の規制条文を、エンジニアリングレベルの統制に落とし込む経験
CRISC, CISA, or ISO 27001 Lead Implementer/Auditor certification strongly preferredCRISC、CISA、またはISO 27001リードインプリメンター/オーディター資格を強く推奨
Comfortable presenting risk findings directly to boards and C-suite stakeholders取締役会や経営陣に対し、リスク評価結果を直接説明できること
Business or native-level Japanese is a significant advantage for board and regulator-facing work取締役会・規制当局対応業務において、ビジネス・ネイティブレベルの日本語は大きなアドバンテージ

Engagement Model契約形態

Projects may be delivered remotely, on-site in Tokyo, or hybrid, and typically run 2–12 weeks for discrete assessments, with some developing into longer advisory relationships.案件はリモート、東京都内オンサイト、またはハイブリッドで提供されます。個別評価は通常2〜12週間ですが、長期的なアドバイザリー関係に発展する案件もあります。

No requirement for full-time availability — engagements are matched to your scheduleフルタイムでの稼働は不要 — 案件はご自身のスケジュールに合わせてマッチングされます
On-site requirements (board presentations, workshops) communicated before engagement acceptanceオンサイト対応(取締役会説明、ワークショップ等)の要件は案件受諾前にご案内します

Commercial Terms & Invoicing商業条件・請求

Compensation is agreed on an engagement-by-engagement basis, considering scope, seniority, duration, and specialist scarcity. Terms are agreed before the engagement begins.報酬は案件ごとに、スコープ、シニアリティ、期間、専門性の希少性を考慮して合意されます。条件は案件開始前に合意されます。

Daily or hourly consulting rates, fixed project fees, or defined workstream fees日次・時間単価、固定プロジェクト報酬、または業務範囲別報酬
No requirement to accept every opportunity presented提示されたすべての案件を受諾する義務はありません
Global Access manages client onboarding, contracting, and invoicing directlyクライアントのオンボーディング、契約、請求はGlobal Accessが直接管理
Partners issue their own business invoices per the Business Outsourcing Agreementパートナーは業務委託契約に基づき、自身で事業者請求書を発行
Partners are responsible for their own tax, accounting, insurance, and licensing obligations納税、会計、保険、免許等の義務はパートナー自身が負担

What Partners Can Expectパートナーが得られること

Access to enterprise and multinational client opportunities matched to your specialist capabilities貴社の専門性に合致した、エンタープライズ・多国籍企業クライアントへのアクセス機会
Freedom to choose projects that fit your expertise, availability, and commercial expectations専門性、稼働可能状況、商業条件に合った案件を選択する自由
Remote, on-site in Tokyo, or hybrid delivery depending on client requirementsクライアント要件に応じたリモート、東京都内オンサイト、またはハイブリッドでの提供
Collaboration with other experienced specialists as part of multidisciplinary delivery teams多職種混成の提供チームの一員として、他の経験豊富な専門家との協業
Global Access handles client onboarding, contracting, and invoicing so you focus on deliveryクライアントのオンボーディング、契約、請求業務はGlobal Accessが担当し、貴社は提供業務に集中可能
Access to a curated professional network for knowledge-sharing and cross-referred opportunities知見共有や相互紹介の機会を含む、厳選された専門家ネットワークへのアクセス

What Success Looks Like成功の定義

A successful engagement should leave the client with clarity on the following.成功する案件は、クライアントに以下について明確な理解をもたらすものでなければなりません。

What the problem is — the specific weakness, gap, threat, or opportunity identified問題の所在 — 特定された具体的な弱点、ギャップ、脅威、または機会
Why it matters — technical findings translated into business consequences or measurable value重要性の理由 — 技術的な発見事項をビジネス上の影響または測定可能な価値に変換
What level of risk the organization is accepting (unresolved, accepted, mitigated, transferred, or residual)組織が許容しているリスクレベル(未解決、受容済み、軽減済み、移転済み、残存)
What should be done — practical, prioritized recommendations appropriate to the client's environment実施すべき対応 — クライアントの環境に適した、実践的で優先順位付けされた提言
How the recommendation can realistically be implemented, given budget and organizational readiness現実的な実装方法 — 予算や組織の準備状況を考慮した実現可能性
How improvement can be measured — control improvements, maturity indicators, or cost savings改善の測定方法 — 統制の改善、成熟度指標、コスト削減などの評価指標

Diversity & Inclusion多様性と包括性

Global Access Incorporated welcomes independent professionals and boutique firms from a wide range of technical, industry, and professional backgrounds. Our focus is on professional capability, integrity, and the ability to deliver meaningful outcomes for clients.Global Access Incorporatedは、幅広い技術・業界・専門的背景を持つ独立専門家およびブティックファームを歓迎します。当社が重視するのは、専門的能力、誠実さ、そしてクライアントに意味のある成果をもたらす力です。

How to Apply応募方法

Join the Networkパートナーネットワークへの参加

Send a brief overview of your background — your core expertise, relevant frameworks and certifications, years of experience, current availability, and preferred engagement model. Applications are reviewed on a rolling basis; qualified specialists are invited to an exploratory conversation.ご専門分野、関連するフレームワーク・資格、実務経験年数、現在の稼働可能状況、ご希望の契約形態について、簡単な経歴概要をお送りください。応募は随時審査し、条件に合う方には個別に事前対談のご案内をいたします。

Please Includeご記載いただきたい内容

  • Core areas of expertise and preferred frameworksコア専門分野および得意とするフレームワーク
  • Relevant certifications and years of experience関連資格および実務経験年数
  • Enterprise or multinational client experienceエンタープライズ・多国籍企業でのクライアント経験
  • Current availability and preferred engagement model現在の稼働可能状況およびご希望の契約形態
  • Japanese language level, if applicable日本語レベル(該当する場合)
An exploratory conversation does not guarantee a project engagement. Specific opportunities depend on client requirements, partner suitability, availability, and mutually agreed commercial terms. 事前対談は、プロジェクトへの参画を保証するものではありません。個別の機会は、クライアント要件、パートナーとしての適性、稼働状況、および合意された商業条件に基づき決定されます。

This is a B2B partnership inquiry, not a job application in the employment sense.本フォームはB2Bパートナーシップに関するお問い合わせであり、雇用契約に基づく応募ではありません。

Important Legal Notice重要法的通知

Global Access Incorporated (株式会社 GLOBAL ACCESS) is a professional services company. This partnership opportunity is offered through the IT Solutions & Security Division and is intended for independent contractors, security professionals, IT auditors, consultants, AI specialists, technology professionals, transformation consultants, and boutique consulting firms to collaborate on project-based B2B service engagements. 株式会社GLOBAL ACCESS(Global Access Incorporated)は専門サービス企業です。本パートナーシップの機会はITソリューション&セキュリティ部門を通じて提供されるものであり、独立した契約者、セキュリティ専門家、IT監査人、コンサルタント、AI専門家、テクノロジー専門家、トランスフォーメーションコンサルタント、およびブティックコンサルティングファームが、プロジェクトベースのB2Bサービス契約において協業することを目的としています。

This is not an offer of employment and does not create or imply an employment relationship. It does not constitute recruitment, introduction, or placement of personnel for third-party companies. All engagements are governed by individual Business Outsourcing Agreements (業務委託契約 / Gyōmu Itaku) between Global Access Incorporated and the applicable contracting partner entity. No employment contract (労働契約 / Rōdō Keiyaku) is created or implied. 本募集は雇用の申し込みではなく、雇用関係を創出または示唆するものでもありません。第三者企業への人材の紹介、あっせん、または配置を構成するものでもありません。すべての契約は、Global Access Incorporatedと契約パートナー法人との間の個別の業務委託契約に基づいて管理されます。雇用契約(労働契約)は作成も黙示もされません。

The partner remains an independent business and is responsible for its own tax obligations, accounting, insurance, licenses, certifications, and other legal and regulatory requirements applicable to its business. Nothing in this description guarantees a minimum volume of work, minimum compensation, or a particular number of project engagements. パートナーは独立した事業者としての立場を維持し、自らの納税義務、会計処理、保険、免許、資格、その他事業に適用される法的・規制上の要件について責任を負います。本募集要項のいかなる記載も、最低業務量、最低報酬、または一定数のプロジェクト参画を保証するものではありません。