Staff AI Engineer (Lead )
Summary
Lead the design of AI agent systems that automate security workflows across the software development lifecycle, integrating LLMs, context engineering, and CI/CD tools to enforce secure coding and release governance.
Why Money Forward?
- Join Money Forward at a major strategic turning point as the company shifts from “cloud” to “AI” and advances AX (AI Transformation) beyond traditional DX.
- Help build the foundation for AI agents and “digital workers” that can autonomously perform back-office tasks across Money Forward products.
- Own greenfield architecture for agentic security workflows that directly support the company’s AI strategy, product trust, and secure AI-driven development.
- Work on a rare intersection of agentic AI, application security, and cross-team engineering leadership, shaping reusable standards, guardrails, and implementation patterns across product teams.
- Contribute to Money Forward’s ambition to become Japan’s No. 1 back-office AI company by enabling safer, faster, and more reliable AI-powered value creation.
- Help shape one of the company’s most advanced agentic AI initiatives: a multi-agent security workflow designed to support the full software development lifecycle, while keeping human review, safety boundaries, and release governance in place.
- Design end-to-end agentic security workflows for SDLC validation, patch management, proactive testing, risk reporting, and release gates.
- Own the product security context model, including architecture, data sensitivity, authentication/RBAC, credential and PII handling, logging touchpoints, release tier, and critical product flows.
- Define agent decision rules, including advisory behavior, human-review requirements, release-blocking criteria, risk thresholds, and escalation paths.
- Design and implement agent guardrails such as least-privilege access, prompt-injection handling, safe tool execution, audit logging, rollback, and kill-switch mechanisms.
- Build and maintain AI agent workflows using LLMs, context engineering, tool integrations, orchestration, harness design, loop engineering, and evaluation pipelines.
- Validate agent outputs with security experts before rules are trusted for production use.
- Lead application engineers across divisions and translate agentic workflow designs into stack-specific implementation patterns.
- Work with SRE/PRE on CI/CD integration, GitHub/CircleCI workflows, Datadog checks, staging safeguards, and release-gate mechanics.
- Coordinate with QA, privacy, and security specialists on regression validation, release readiness, PII handling, and secure coding rules.
- Own false-positive tuning, rule-change backlog, and continuous improvement of agent quality.
Requirements
Requirements
- Bachelor’s degree or higher in Computer Science, Software Engineering, or a related technical field.
- Strong experience with Python or JavaScript building LLM-based applications and AI agents, with hands-on experience in LLM tooling, frameworks, platforms, and evals.
- Strong understanding of context engineering, instruction design, prompt hardening, tool boundaries, harness design, loop engineering, and agent evaluation.
- Ability to design production-ready agent workflows with clear inputs, outputs, failure modes, human-review points, and escalation rules.
- Experience with CI/CD, observability, logging, monitoring, and production-readiness practices.
- Ability to lead 3–5 engineers across teams without direct authority.
- Strong problem-solving skills
- Strong communication skills
Preferred Skills and Experience
- Experience with AI agent frameworks such as LangGraph, LangChain, OpenAI Agents SDK, or equivalent.
- Experience integrating AI workflows into GitHub, CircleCI, Datadog, or similar engineering platforms.
- Experience creating reusable engineering standards, templates, checklists, and enablement materials.
- Working knowledge of application security concepts such as threat modeling, OWASP, secure coding, secrets handling, PII handling, and release risk assessment; or proven ability to work closely with security experts and convert their knowledge into agent rules and checklists.
- Working familiarity with additional stacks used across product teams, such as Ruby/Rails, Go, Java, React, or Vue.
- Ability to work effectively in a rapid, iterative development environment with a high degree of autonomy.
Language Requirements
- Japanese: Business-level or higher preferred. (Optional)
- English: Ability to read and write technical documentation and collaborate with engineering teams.