Security Detection & Automation Engineer - Product Security Section, Cyber Security Defense Department (CSDD)
Rakuten
·Today
- Location
- Rakuten Crimson House, Japan
- Workplace
- Remote, Hybrid
- Type
- Full-time
- Department
- Engineering
- Experience
- 4+ years
- Closing date
- Today
- Source
- Workday
Description
Job Description:
Business Overview
The Technology Management Division (TMD) provides corporate IT, cyber security, and privacy governance to Rakuten Group companies and essential business management for technology organizations, thereby enabling innovation and strengthening its technology foundation. Within TMD, the Information Security Supervisory Department (ISSD) combines proactive cyber defense with strategic information security, privacy, and data governance to protect the company’s global assets and data.
Department Overview
The Cyber Security Defense Department (CSDD) is responsible for safeguarding all Rakuten companies and users from cyber threats, ensuring the security and integrity of Rakuten Group's global internet services. We oversee all aspects of both Secure Development and Security Operations for services developed within the group, with dedicated security teams and operation centers strategically located in key regions worldwide.
Position:
Position Details
To deliver comprehensive cybersecurity by embedding robust security into the design, development, and delivery of Rakuten's products and protecting our production systems through high-fidelity detection, automated response, and scalable security engineering.
We are looking for a Security Detection & Automation Engineer to join our team. You will be responsible for building the "eyes and ears" of our security ecosystem. You will develop automated detection logic, engineer security-as-code solutions, and build response playbooks that protect our private cloud environment. Your goal is to reduce the time-to-detect and time-to-remediate through automation, ensuring our global services remain resilient against evolving threats.
・Develop, tune, and maintain high-fidelity detection rules (SIEM/EDR/Cloud-Native tools) to identify malicious activity across our global hybrid cloud infrastructure
・Design and implement automated workflows (SOAR) to respond to common threats, reducing manual toil for the security operations team
・Partner with SRE and DevOps teams to integrate automated security guardrails into CI/CD pipelines
・Proactively analyze logs, traffic patterns, and system telemetry to identify sophisticated threats that bypass traditional signature-based defenses
・Build automated systems to verify the security posture of hybrid cloud configurations, ensuring continuous compliance and drift detection
・Build custom internal tools or scripts (Python/Go) to bridge gaps in our security stack and improve visibility across our cloud ecosystem
Mandatory Qualifications:
・More than 4 years of experience in security engineering, detection engineering, or incident response
・Hands-on experience securing container orchestration (Kubernetes), virtualized environments and cloud-native environments (AWS, GCP, or Azure)
・Strong proficiency in at least one language (Python, Go, or Ruby) for security automation and API integration
・Experience developing detection rules in SIEM or EDR/Cloud security platforms
・Proven ability to automate manual security tasks (SOAR or custom scripts)
・Deep understanding of network protocols, OS internals (Linux/Windows), and web application architectures
・Ability to work effectively in a global, cross-functional team and communicate complex technical concepts clearly
Desired Qualifications:
・Experience mapping detections to frameworks like MITRE ATT&CK
・Experience with CI/CD tools (Jenkins, GitLab CI, GitHub Actions) and security-as-code practices
・Experience with identity-centric security and micro-segmentation
・Relevant security certifications (e.g., GCIA, GDAT)
#engineer #securityengineer #technologymanagementdiv
Languages:
English (Overall - 3 - Advanced)