SOC Analyst - Security Operations Center Group, Cyber Defense Operations Section (RMI Security Eng. & Ops Dep)
Rakuten
·Today
- Location
- Rakuten Crimson House, Japan · Osaka, Japan
- Type
- Full-time
- Department
- Operations
- Experience
- 5+ years
- Closing date
- Today
- Source
- Workday
Description
Job Description:
About Organization
Cyber Defense Operations Section operates a 24/7 Security Operations Center (SOC) protecting Rakuten Group's critical infrastructure. We are currently in a critical transformation phase to address the era of autonomous, AI-driven cyber threats. Our mission is to evolve from a reactive monitoring unit into a proactive, intelligence-led, and automated defense organization. We are looking for a highly technical and innovative SOC Analyst (L2) to act as a key architect of our future-ready SOC, leveraging LLMs and AI-powered tools to neutralize advanced adversaries.
Job Duties
- AI-Driven Threat Defense: Utilize LLMs and AI-augmented security platforms to accelerate threat hunting, incident triage, and forensic analysis. Develop workflows to identify and respond to autonomous AI-based attacks.
- SOC Transformation: Actively contribute to the SOC’s capability roadmap. Recommend and implement structural improvements to toolsets and processes to handle the evolving threat landscape.
- Container & K8s Security: Perform deep-dive analysis into containerized environments and Kubernetes clusters. Implement security controls against container-specific exploits and automated lateral movement.
- Capacity Development: Participate in the continuous training and upskilling of the SOC team. Translate technical findings into new playbooks and SOPs to elevate the team's response maturity.
- Advanced Incident Response: Lead the investigation of complex incidents. Apply "Defense in Depth" principles to identify environmental gaps and propose architectural hardening.
- Security Engineering: Collaborate with the L3 Manager to tune detection logic and integrate AI-based feedback loops into our SIEM/SOAR infrastructure.
- Offensive Security Research: Apply an "OffSec" mindset to simulate and test defenses against AI-powered attack tools, ensuring faster and more precise responses.
Minimum Qualifications
- Bachelor’s degree in Computer Science, Cyber Security, or equivalent.
- 5–8 years of experience in a SOC, incident response, or security engineering role.
- Strong understanding of SIEM/SOAR ecosystems and optimization for AI-driven detection.
- Relevant certifications (e.g., GCIH, GCSA, CKAD, CKS, or AI-Security specific certifications).
Preferred Qualifications
- Experience in the Telecommunications sector (e.g., 5G security, NFV, signaling protocols).
- Experience in developing custom AI/ML models or fine-tuning LLMs for security use cases.
- Demonstrable experience in "Red Teaming" or participating in high-level CTF competitions.
- Experience with Infrastructure as Code (IaC) and DevSecOps pipelines.
Work Environment
- Reporting: Reports to the Manager of the Security Operations Center Group.
- Collaboration: Manages/mentors the 24/7 SOC team and collaborates cross-departmentally with other security functions and Business Units.
- Tech Stack: Containerization (Docker/Kubernetes), Telco environments (5G Core, Signaling Protocols), SOAR platforms, Python/Go/Bash, Cloud Security (AWS/Azure/GCP), and LLM-based security tools.
Languages:
English (Overall - 3 - Advanced)