# Dojo Ranks: Experience, Role and Compensation Guide

Updated: 2026-10-08

## How to use this guide

This is a learning and career-discussion guide. A Dojo rank is not a hiring grade, professional license, certification, employment guarantee, or promise of a raise. Experience is relevant time spent doing security work, research, defensive operations, or responsible disclosure. Count approximate full-time-equivalent (FTE) years without double counting overlapping periods. Verified internships, research, open-source work, internal defense, and volunteer work can count when role and outcomes are reviewable.

Compensation figures are Japan gross annual pay references, not salary bands assigned to Dojo ranks. They vary by location, industry, employer, employment type, bonus, equity, and scope. ITSS bands below are skill-level estimates cited by Japan's MHLW Job Tag; security-engineer figures are 2026 recruiter job ranges. Mapping them to Dojo is an explanatory estimate only.

## Rank-by-rank map

| Dojo rank | Typical relevant experience (FTE) | Position examples | Japan pay reference | Evidence toward promotion |
|---|---:|---|---|---|
| White belt | 0 years onward | Beginner, learner | Do not infer pay from rank; use the actual occupation and job posting | Explain authorization, assets, data, and risk; pause when authorization is unclear |
| 10th kyu | 0–1 year | Security learner, IT support/operations trainee | About ¥4.2–7.0m only when the job fits ITSS levels 1–2 | System sketch and scope sheet for a synthetic case |
| 9th kyu | 0–1 year | SOC/vulnerability-management assistant | Same ITSS 1–2 reference; not a job guarantee | Findings that distinguish observations from inferences |
| 8th kyu | 0–2 years | Junior operations or monitoring analyst | ITSS 1–2 reference: about ¥4.2–7.0m | Safe validation plan, stop conditions, and escalation |
| 7th kyu | 0–2 years | Supervised security analyst | About ¥4.2–7.0m (ITSS 1–2 reference) | Evidence-backed hypothesis, impact, and uncertainty |
| 6th kyu | 1–3 years | SOC analyst, vulnerability manager | ITSS 1–3 reference: about ¥4.2–7.0m | Prioritization from synthetic logs/design material |
| 5th kyu | 1–3 years | Junior security engineer | ITSS 1–3 reference: about ¥4.2–7.0m | Reproducible safe proof and owned remediation plan |
| 4th kyu | 1–4 years | Security engineer, GRC/risk analyst | ITSS 3–4 reference: about ¥4.5–8.0m | Align technical impact, business impact, and acceptance criteria |
| 3rd kyu | 2–4 years | Practitioner handling a bounded scope independently | ITSS 3–4 reference: about ¥4.5–8.0m | Reviewable report that explains false positives and limitations |
| 2nd kyu | 2–5 years | Security engineer/consultant | ITSS 3–4 reference: about ¥4.5–8.0m | Close a case through remediation confirmation |
| 1st kyu | 3–6 years | Senior-track practitioner, technical or business-side lead | ITSS 4–5+ reference: about ¥5.1–10.86m. Job examples: East Japan ¥8–20m; West Japan ¥6–16m | Multiple cases preparing for an integrated black-belt review |
| Shodan (black belt) | Usually 3+ years as a guide | Security engineer, analyst, GRC/product-security practitioner with foundations in both axes | ITSS 4+ reference: about ¥5.1–10.86m. Security-engineer job examples: East ¥8–20m; West ¥6–16m | T and B at level 2+, integrated in one case from decision through remediation |
| Nidan | Usually 5+ years | Technical/business lead, security-architect track | ITSS 5+ reference: about ¥6.68–10.86m; job examples vary by region/employer, roughly ¥6–20m | T and B at level 3 in a complex case; track remediation |
| Sandan | Usually 7+ years | Multi-team security lead, principal track | Refer to senior specialist job examples above; no rank-specific statistic | Shared root cause and recurrence prevention across teams; independent review |
| Yondan | Usually 8+ years | Principal, security-program/architecture owner | Security-engineer job examples: East ¥8–20m; West ¥6–16m | Organization-wide improvement and before/after measures |
| Godan | Usually 10+ years | Cross-functional technical owner, security executive track | Same specialist job examples; management pay needs role-specific research | Reusable methods and residual-risk management across products/organizations |
| Rokudan | Usually 12+ years | Principal in a large organization, security-department leader track | East Japan banking Information Security Officer example: ¥17–30m. Banking-specific, not a general market range | Independently reviewed cross-organizational impact, including failures and side effects |
| Nanadan | Usually 15+ years | Industry-wide practitioner, leader of standards/defense methods | Requires role- and industry-specific research; do not treat the banking example as a rank rate | Results adopted and reproduced across organizations; mentoring |
| Hachidan | Usually 18+ years | International domain leader, research/industry collaboration owner | No comparable rank-specific pay data; consult the market for the actual role | Public independent evaluation and long-term impact/side-effect tracking |
| Kudan | Usually 20+ years | International practitioner advancing the field | No comparable rank-specific pay data | Broad replication/adoption and independent review; tenure alone is insufficient |
| Judan (honorary master) | No fixed minimum; reviewed individually | Honorary role, fellow, independent researcher, or active role-holder | No salary attached to honorary rank; actual employment and contracts determine pay | Individual review of exceptional long-term contribution by multiple independent reviewers |

## How experience is scored

Experience and sustained impact account for at most 15 of 100 promotion points. Indicative bands: 0–1 relevant years: 0–2 points; 1–3: 3–5; 3–5: 6–8; 5–8: 9–11; 8+: 12–15. Reviewers choose within a band based on scope, sustained outcomes, reuse across environments, and the candidate's own role. Senior ranks require independently reviewable impact; extra years without that evidence do not earn the points. Years are not a gate for white belt through 1st kyu. From Shodan onward, listed years are typical guides; equivalent demonstrated depth may be reviewed individually.

Evidence may include date range, approximate FTE, role, outcomes, impact, and a way to verify the work. Do not submit customer names, vulnerability details, personal data, or employment contracts for public display. NDA work can be supported by a limited reference or sanitized summary. Degrees, certifications, token spend, and report count do not substitute for experience or competence.

## Sources and interpretation

- Japan MHLW Job Tag, “Security Expert (Operations)”: cites an associated occupational-group annual wage of about ¥6.098m based on the 2025 wage survey and ITSS-level estimates (levels 1–2 about ¥4.2–7.0m; level 3 ¥4.5–7.0m; level 4 ¥5.1–8.0m; level 5+ ¥6.675–10.86m). These datasets have different populations and no official mapping to Dojo ranks. https://shigoto.mhlw.go.jp/Occupation/Detail?occupationId=321
- Robert Walters Japan, Salary Survey 2026: Security Engineer job ranges of ¥8–20m in East Japan and ¥6–16m in West Japan; East Japan banking Information Security Officer ¥17–30m. These are recruiter job ranges, not median earnings for all workers. https://www.robertwalters.co.jp/content/dam/robert-walters-redesign/country/japan/files/others/RWJ-SS2026-English.pdf
- U.S. comparison only: U.S. Bureau of Labor Statistics, Information Security Analysts, May 2024 median $124,910. Do not use this to convert Japan pay or map Dojo ranks. https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm
- NIST NICE recommends defining proficiency through practical skills, experience, and workplace impact rather than time in the field alone. https://www.nist.gov/itl/applied-cybersecurity/nice/nice-framework-resource-center/identifying-proficiency-nice-framework

Wage/job data checked: 2026-10-08. Because the references mix regions, occupations, and survey years, consult current data for the specific role and location when discussing an individual offer.
