Senior Manager, Public Cloud Security - Cyber Security Defense Department (CSDD)
Rakuten
·Today
- Location
- Rakuten Crimson House, Japan
- Type
- Full-time
- Department
- IT
- Seniority
- Senior
- Experience
- 10+ years
- Closing date
- Today
- Source
- Workday
Description
Job Description:
Business Overview
The Technology Management Division (TMD) provides corporate IT, cyber security, and privacy governance to Rakuten Group companies and essential business management for technology organizations, thereby enabling innovation and strengthening its technology foundation. Within TMD, the Information Security Supervisory Department (ISSD) combines proactive cyber defense with strategic information security, privacy, and data governance to protect the company’s global assets and data.
Department Overview
The Cyber Security Defense Department (CSDD) is responsible for safeguarding all Rakuten companies and users from cyber threats, ensuring the security and integrity of Rakuten Group's global internet services. We oversee all aspects of both Secure Development and Security Operations for services developed within the group, with dedicated security teams and operation centers strategically located in key regions worldwide.
Position:
Position Details
We are seeking an experienced leader to establish and scale Rakuten's Public Cloud Security program across multiple businesses and public cloud environments.
This role is responsible for defining the strategy, operating model, and roadmap for Public Cloud Security, working closely with the Cloud Center of Excellence (Cloud CoE), development teams, and other technology stakeholders throughout the organization.
The mission of the Public Cloud Security team is to provide centralized visibility, governance, expertise, and automation for cloud security while enabling development teams to maintain ownership and accountability for remediation within their respective services.
As the Senior Manager, Public Cloud Security, you will drive the adoption of market-leading and/or internally developed security solutions, establish scalable security guardrails, expand security automation, and improve the organization's ability to identify and respond to security risks at scale. You will focus on reducing manual security operations by integrating security directly into cloud platforms and engineering workflows, allowing development teams to address security findings efficiently while maintaining enterprise-wide visibility into risk and compliance.
This role requires strong leadership, technical expertise, and the ability to influence stakeholders across multiple organizations while balancing security, operational efficiency, and business agility.
・Define and execute Rakuten's Public Cloud Security strategy, vision, and roadmap
・Establish a scalable cloud security operating model that supports business growth and cloud adoption across multiple organizations
・Build, lead, and scale a high-performing Public Cloud Security team while fostering a culture of automation, engineering ownership, and continuous improvement
・Drive collaboration and alignment among the Cloud Center of Excellence (Cloud CoE), development organizations, and business stakeholders
・Define long-term security investment priorities and technology roadmaps for cloud security capabilities
・Lead the adoption and operation of market-leading and/or internally developed cloud security solutions
・Build security capabilities that provide continuous visibility into cloud assets, security risks, compliance status, and remediation activities
・Drive security automation initiatives to improve detection, response, governance, and reporting
・Establish security guardrails and self-service security capabilities that can be consumed by development teams
・Reduce manual security operations by integrating security controls into cloud platforms, engineering workflows, and software delivery processes
・Promote security-by-default and security-by-design principles across public cloud environments
・Define and maintain public cloud security policies, standards, controls, and governance frameworks
・Establish mechanisms to continuously monitor cloud security posture and risk exposure across the organization
・Provide executive visibility into cloud security risks, trends, compliance posture, and program effectiveness
・Partner with compliance, privacy, risk management, and security operations teams to address regulatory requirements and emerging threats
・Develop metrics and KPIs to measure cloud security maturity, remediation effectiveness, and operational performance
・Partner with the Cloud Center of Excellence (Cloud CoE) and development teams to integrate security capabilities into cloud platforms and engineering workflows
・Establish clear accountability models where development teams own remediation and risk reduction activities within their services
・Ensure security findings are identified, prioritized, and routed to the appropriate service owners through automated processes whenever feasible
・Enable development teams to manage security risks independently by providing guidance, training, tooling, and consulting support
・Act as a trusted security advisor for cloud-related initiatives across multiple business units
・Drive a culture in which security is embedded into engineering processes without reducing development velocity
Mandatory Qualifications:
・More than 10 years of experience in information security, cloud security, infrastructure security, or related disciplines
・More than 5 years of leadership experience managing technical teams and large-scale security initiatives
・Strong expertise in public cloud technologies, cloud security governance, and risk management
・Experience implementing or operating large-scale security platforms, cloud security programs, or enterprise security services
・Experience driving security automation and developing scalable security operating models
・Strong understanding of identity and access management, security monitoring, data protection, vulnerability management, and cloud-native security concepts
・Experience partnering effectively with development organizations and influencing stakeholders across multiple business units
・Strong communication, stakeholder management, and executive presentation skills
・Experience operating in large-scale and global technology organizations
Desired Qualifications:
・Experience implementing Cloud Security Posture Management (CSPM)
・Cloud-Native Application Protection Platforms (CNAPP), Cloud Infrastructure Entitlement Management (CIEM), or similar technologies
・Experience building security automation, self-service security platforms, or developer-focused security services
・Experience integrating security into modern software development and cloud engineering practices
・Experience supporting large-scale internet services, e-commerce platforms, financial services, telecommunications, or other highly regulated environments
・Knowledge of industry frameworks and standards such as ISO 27001, PCI DSS, NIST, CIS Benchmarks, or equivalent
・Relevant certifications such as CISSP, CCSP, or equivalent
・Experience leading cloud transformation or enterprise security transformation initiatives
#engineer #securityengineer #technologymanagementdiv
Languages:
English (Overall - 3 - Advanced)