職務の概要
Project Lightwell は、AI 時代の急速な脆弱性発見やオープンソースライブラリに潜むセキュリティリスクに対応し、エンタープライズ環境におけるソフトウェアサプライチェーンの安全確保と脆弱性修復の迅速化を推進するRed HatとIBMが共同で推進するイニシアチブです。信頼されたライブラリの活用から、脆弱性の自動識別・検証・全社展開に至るClosed-Loopな修復プロセスを確立し、お客様の継続的なプラットフォームのレジリエンス向上を支援します
本ポジションは、Lightwellイニシアチブを推進する核となるポジションで、エンタープライズ顧客のセキュリティの強化と、アプリケーションデリバリーの迅速化・効率化を牽引する、技術・戦略のスペシャリストです。
顧客の経営層(CISO、ITディレクター)から開発・運用エンジニアまで多様なステークホルダーを巻き込み、概念検証/ディスカバリー・ワークショップや戦略アセスメントサービスを主導します。現状の課題(プロセスのボトルネック、セキュリティ上の盲点、開発体験の阻害要因、コンプライアンスリスク)を可視化し、アーキテクチャの標準化・自動化・DevSecOps 推進に向けた将来像と実行可能なロードマップを策定します。
アセスメントから特定された課題に対し、構築支援コンサルティング、開発基盤の整備、技術アドバイザリー(TAM)、トレーニング等の最適なサービスソリューションを提案することで、顧客の自立支援とサービスビジネスの継続的成長を同時に推進します。
① ディスカバリー&戦略ワークショップの主導
・ CISO、セキュリティ、インフラ運用、アプリ開発、リリースエンジニアリングなどの横断チームを対象に、課題特定およびゴールアライメントのためのファシリテーションを実施。
・ Value Stream Mappingやプロセス分析手法を用いて、デリバリーのリードタイム阻害要因やセキュリティリスク(脆弱性対応の遅れ、サプライチェーンの脆弱性、開発環境の煩雑さ等)を定量・定性的に抽出。
・ 顧客のビジネス目的に応じた将来像と、それを実現するための優先順位付きネクストステップを定義・提言。
② 詳細アセスメント&ロードマップ策定
・ 以下の 3 つの核心領域を軸に、顧客環境における技術・プロセス・組織成熟度の詳細アセスメントを遂行:
1. Platform Security: OS・コンテナ基盤の標準化、アクセス制御(RBAC)、最小権限原則、構成ドリフト検知、脆弱性修正(パッチ運用)の自動化、コンプライアンス・監査対応の評価。
2. Software Delivery Velocity & DevEx: SDLC/CI/CD パイプラインの成熟度評価、開発基盤の標準化、DORA メトリクス(リードタイム、デプロイ頻度等)に基づくプロセス改善、自動化・プロモーションゲートの最適化。
3. Software Supply Chain Security: SBOMの管理、アーティファクト署名・証明、オープンソース依存関係リスク、静的/動的セキュリティテスト(SAST/DAST/SCA)の適用評価。
・ アセスメント結果を取りまとめ、エグゼクティブ向けプレゼンテーションおよび具体的・実践的な実装ロードマップを提示。
③ サービスビジネス創出とソリューション提案
・ アセスメントで明確化した課題に対し、構築サービス(環境の構築、自動化パイプライン・開発基盤実装等)、技術アドバイザリー(TAM)、人材育成を組み合わせた総合的なトランスフォーメーションプランを提案。
・ 単なる提案にとどまらず、サイド・バイ・サイドのメンタリングアプローチを通じて顧客チームの技術内製化・自立化を支援。
必須要件
1. DevSecOps & セキュリティ領域の知見 (DevSecOps & Security)
- 脆弱性管理 & ライフサイクル: CVE 脆弱性の評価・リスク優先順位付け、パッチ適用ライフサイクル管理の知見。
- サプライチェーン&アプリケーションセキュリティ: SBOM管理、ビルド/パイプラインセキュリティ、コンテナセキュリティ、CI/CD へのセキュリティ統合(Shift Left)の概念理解と実践経験。
- ガバナンス・コンプライアンス: RBAC、Identity Management、監査トレイル、セキュリティ基準(FIPS や CIS Benchmark 等)に基づくシステム標準化の知見。
2. プラットフォーム & 自動化技術知見 (Platform & Automation)
- エンタープライズ基盤技術: エンタープライズ Linux (RHEL 等)、Kubernetes / コンテナプラットフォーム (OpenShift 等) のアーキテクチャ設計・構築・運用経験。
- IT 構成管理・自動化: Ansible などの構成管理・オーケストレーションツールを用いた、インフラ構築・設定運用・パッチ適用の自動化経験。
3. コンサルティング & ファシリテーション能力
- 役員・経営層(CISO、IT 部門長)から技術現場まで、幅広いステークホルダーとのコミュニケーションおよびマルチチームワークショップの合意形成・ファシリテーション経験。
- 複雑な現状(Current State)から課題を整理し、論理的かつ実現可能な将来像(Target State)およびロードマップに落とし込むドキュメンテーション能力。
歓迎要件 (Preferred Experience & Skills)
- アプリケーション開発経験:
- Java、Go、Python、Node.js 等を用いた Web アプリケーションやマイクロサービスの開発実務経験。
- 開発基盤(Developer Platform / Factory)構築経験:
- CI/CD パイプライン(Tekton, GitLab CI, GitHub Actions, Jenkins 等)の設計・構築経験。
- 開発者の生産性向上(DevEx)や標準化を目的とした Internal Developer Platform (IDP)、Developer Hub(Backstage 等)、ソフトウェアファクトリーの構築・運用経験。
- プロセス改善手法の適用:
- VSM(Value Stream Mapping)や DORA メトリクスを用いた開発・運用プロセスの改善コンサルティング経験。
- 先進技術への知見:
- ゼロトラストアーキテクチャ (ZTA)、Post-Quantum Cryptography (PQC)、AI を活用した運用自動化 / 脆弱性分析に関する興味・知見。
- ビジネス展開実績:
- プリセールス、ソリューションアーキテクト、またはポストセールスコンサルタントとして、アセスメントから大型構築案件・長期アドバイザリー契約への展開を成功させた実績。
本ポジションのポイント (Role Highlights)
- 特定の個別サービスや技術スタックの変化に左右されない、「エンタープライズプラットフォームの標準化・自動化・セキュリティ統合・開発基盤整備」 という本質的かつ高い市場価値を持つスキルセットを活かせます。
- 開発者目線とインフラ/セキュリティ目線の両方を持ち、組織全体のトランスフォーメーションを牽引できます。
About Red Hat
Red Hat is the world’s leading provider of enterprise open source software solutions, using a community-powered approach to deliver high-performing Linux, cloud, container, and Kubernetes technologies. Spread across 40+ countries, our associates work flexibly across work environments, from in-office, to office-flex, to fully remote, depending on the requirements of their role. Red Hatters are encouraged to bring their best ideas, no matter their title or tenure. We're a leader in open source because of our open and inclusive environment. We hire creative, passionate people ready to contribute their ideas, help solve complex problems, and make an impact.
Inclusion at Red Hat
Red Hat’s culture is built on the open source principles of transparency, collaboration, and inclusion, where the best ideas can come from anywhere and anyone. When this is realized, it empowers people from different backgrounds, perspectives, and experiences to come together to share ideas, challenge the status quo, and drive innovation. Our aspiration is that everyone experiences this culture with equal opportunity and access, and that all voices are not only heard but also celebrated. We hope you will join our celebration, and we welcome and encourage applicants from all the beautiful dimensions that compose our global village.
Equal Opportunity Policy (EEO)
Red Hat is proud to be an equal opportunity workplace and an affirmative action employer. We review applications for employment without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, citizenship, age, veteran status, genetic information, physical or mental disability, medical condition, marital status, or any other basis prohibited by law.
Red Hat does not seek or accept unsolicited resumes or CVs from recruitment agencies. We are not responsible for, and will not pay, any fees, commissions, or any other payment related to unsolicited resumes or CVs except as required in a written contract between Red Hat and the recruitment agency or party requesting payment of a fee.
Red Hat supports individuals with disabilities and provides reasonable accommodations to job applicants. If you need assistance completing our online job application, email [email protected]. General inquiries, such as those regarding the status of a job application, will not receive a reply.
Skills Required
- Experience evaluating CVE vulnerabilities, prioritizing security risks, and managing patching lifecycles
- Practical experience with SBOM management, build and pipeline security, container security, and integrating security into CI/CD pipelines
- Knowledge of RBAC, identity management, audit trails, FIPS, CIS Benchmarks, and enterprise security standardization
- Architecture, implementation, and operations experience with enterprise Linux such as RHEL
- Architecture, implementation, and operations experience with Kubernetes or container platforms such as OpenShift
- Experience automating infrastructure configuration, operations, and patching using Ansible or similar tools
- Experience communicating with executives, CISO-level stakeholders, IT leaders, engineers, and cross-functional teams
- Experience facilitating multi-team workshops and building consensus
- Ability to analyze current-state environments and document practical target states and implementation roadmaps
- Practical web application or microservices development experience using Java, Go, Python, or Node.js
- Experience designing and implementing CI/CD pipelines using Tekton, GitLab CI, GitHub Actions, Jenkins, or similar tools
- Experience building or operating internal developer platforms, Developer Hubs, Backstage, or software factories
- Experience applying Value Stream Mapping or DORA metrics to development and operations improvement
- Knowledge or interest in zero trust architecture, post-quantum cryptography, or AI-based operations and vulnerability analysis
- Successful experience converting assessments into large implementation engagements or long-term advisory contracts in presales, solution architecture, or post-sales consulting
Red Hat Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Red Hat and has not been reviewed or approved by Red Hat.
-
Healthcare Strength — Healthcare coverage is presented as comprehensive, spanning medical, dental, and vision along with life and disability coverage. Access to HSA/FSA options and broadly positive reception of health benefits support the view that healthcare is a core strength.
-
Leave & Time Off Breadth — Time-off offerings are described as generous, with substantial PTO for new hires plus additional recharge days and an end-of-year shutdown for many non-critical roles. Paid volunteer time, holidays, sick days, and supportive expectations around taking time off reinforce the breadth of leave benefits.
-
Strong & Reliable Incentives — The rewards package includes performance bonuses and a recurring quarterly bonus program tied to company and individual performance. Availability of ESPP participation further adds to incentive pathways beyond base pay.
Red Hat Insights
What We Do
At Red Hat, we connect an innovative community of customers, partners, and contributors to deliver an open source stack of trusted, high-performing solutions. We offer cloud, Linux, middleware, storage, and virtualization technologies, together with award-winning global customer support, consulting, and implementation services. Red Hat is a rapidly growing company supporting more than 90% of Fortune 500 companies.
Why Work With Us
Red Hatters freely exchange different viewpoints, contribute ideas, and solve problems together. Our love of collaboration, accountability, a sense of community, and a measure of autonomy combine to create a powerful force that fosters innovation and makes Red Hat a great place to work.
Gallery
.jpg)

.png)





