Detection Engineering Tech Lead, Detection Engineering Group -Cyber Defense Operations Section (RMI Telecommunication Security Supervisory Dep)
Rakuten
·Today
- Location
- Rakuten Crimson House, Japan · Osaka, Japan
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Experience
- 5+ years
- Education
- Master
- Closing date
- Today
- Source
- Workday
Description
Job Description:
About the Organization
Cyber Defense Operations is the core department responsible for ensuring the safety and security of Rakuten Group's internet services. The Detection Engineering Section is tasked with architecting and building next-generation detection pipelines to defend critical infrastructure against autonomous, AI-driven attacks and sophisticated APTs. We lead the transition to a Detection-as-Code (DaC) model, utilizing eBPF-based runtime security, behavioral analytics, and LLM-integrated pipelines to deliver high-fidelity, actionable alerts. We are "defenders with an attacker's brain," committed to proactive, intelligence-led defense.
Job Duties
- Detection-as-Code (DaC) Transformation: Build and manage an end-to-end detection pipeline featuring peer reviews, version control (Git), and a reusable repository of detection rules.
- AI/LLM-Driven Detection: Architect and develop AI/LLM-based models to identify autonomous AI attacks. Use AI to automate log onboarding, normalize data, and filter "garbage logs" to drastically reduce SOC noise.
- Advanced Runtime Security: Lead the implementation of kernel-level monitoring using eBPF-based tools to provide deep visibility into containerized (K8s) and Linux-based workloads.
- Offensive Security & Threat Hunting: Perform continuous attack simulations (Red Teaming) to validate detection coverage. Lead proactive threat hunting initiatives informed by CTI and the MITRE ATT&CK/FIGHT frameworks.
- Deception & Defense-in-Depth: Deploy and manage deception technologies to create high-interaction traps. Ensure detection logic aligns with our defense-in-depth architecture.
- Cross-Functional Orchestration: Collaborate with DFIR, CTI, and SOC teams to ensure CTI is actively integrated into detection logic via AI-driven automation.
- AI Guardrails & Security: Oversee the security of our own AI/LLM models, implementing guardrails to prevent model poisoning, prompt injection, and adversarial manipulation.
- SOAR Integration: Partner with the SOC team to ensure detection logic feeds seamlessly into SOAR playbooks for machine-speed response.
Minimum Qualifications
- Experience: 10+ years in Cyber Security, with at least 5+ years in Detection Engineering or Security Research.
- Detection Engineering: Deep expertise in building detection pipelines, tuning logic for high-fidelity alerts, and managing the security rule lifecycle.
- AI/ML/LLM Proficiency: Practical experience building/tuning models for anomaly detection and log analysis.
- Technical Depth: Expert-level coding skills (Python, Go, or Rust) and mastery of Linux/Windows/Mac internals.
- Container & K8s Security: Strong hands-on experience securing Kubernetes clusters, container runtimes, and microservices architectures.
- Domain Knowledge: Understanding of Telco networks/protocols (e.g., 5G core, signaling) and Network Security (packet analysis, perimeter/internal controls).
- Offensive Mindset: Experience in penetration testing, exploit development, or red teaming.
- Education: Bachelor's or Master's degree in Computer Science, Cyber Security, or equivalent.
- Certifications: Relevant certifications (e.g., OSCP, GREM, GCFA, CKS, BTL2, or AI-Security credentials).
Preferred Qualifications
- Experience with Infrastructure as Code (Terraform, Ansible, Crossplane).
- Deep experience with eBPF tools (e.g., Tetragon, Falco, Cilium, Spyderbat).
- Active contributor to open-source detection projects (e.g., Sigma, YARA, or custom AI-detection models).
- Experience in high-scale environments (Telco, Cloud-Native, or FinTech).
Work Environment
- Department: Detection Engineering Section, Cyber Defense Operations.
- Collaboration: Work with diverse teams including security researchers, threat hunters, and AI/ML specialists.
- Tech Stack: Python/Go/Rust, Kubernetes, Linux, eBPF, Git/Sigma/YARA, LLM-integrated pipelines, SOAR, Terraform/Ansible.
- Location: Japan (Tokyo or Osaka). Domestic/overseas business travel and relocation may be required.
Languages:
English (Overall - 3 - Advanced)