라쿠텐 · 채용 중 500건
Team Manager, Platform Security Group - Cyber Security Defense Department (CSDD)
Team Manager, Platform Security Group - Cyber Security Defense Department (CSDD)
보안 엔지니어정규직시니어 · 7년 이상
라쿠텐은 플랫폼 보안 팀을 이끌 팀 매니저를 채용합니다. 하이브리드 클라우드 환경에서 보안 전략 수립 및 운영을 총괄하며, 사이버 보안 방어 체계를 고도화하는 역할을 수행합니다. 정보보안 분야 7년 이상의 경력과 3년 이상의 팀 관리 경험이 필수입니다. 글로벌 환경에서 보안 엔지니어링을 주도할 역량 있는 리더를 찾습니다.
The Technology Management Division (TMD) provides corporate IT, cyber security, and privacy governance to Rakuten Group companies and essential business management for technology organizations, thereby enabling innovation and strengthening its technology foundation. Within TMD, the Information Security Supervisory Department (ISSD) combines proactive cyber defense with strategic information security, privacy, and data governance to protect the company’s global assets and data.
The Cyber Security Defense Department (CSDD) is responsible for safeguarding all Rakuten companies and users from cyber threats, ensuring the security and integrity of Rakuten Group's global internet services. We oversee all aspects of both Secure Development and Security Operations for services developed within the group, with dedicated security teams and operation centers strategically located in key regions worldwide.
As our global ecosystem grows, we are scaling our defense capabilities to stay ahead of sophisticated threat actors. We are looking for a leader to transform our platform security from reactive to proactive, ensuring resilience at the speed of our business.
Team Mission Statement
To deliver comprehensive cybersecurity by embedding robust security into the design, development and delivery of Rakuten's products for our customers' peace of mind and protecting Rakuten's production systems for our global ecosystem's operational resilience.
We are looking for a strategic and hands-on Manager to lead our platform security team. You will be responsible for the end-to-end security posture of Rakuten’s hybrid infrastructure, spanning both public cloud (AWS/GCP/Azure) and private cloud environments. You will lead a team of security engineers to embed "security-by-design" into our development lifecycle while ensuring proactive monitoring, rapid incident response, and operational stability across our global ecosystem.
Key Responsibilities
Build and maintain strategies for Rakuten’s platform security, spanning both public cloud (AWS/GCP/Azure) and private cloud environments
Manage the platform security team and defend Rakuten services and IT systems from advanced cyber attacks and crimes by partnering with our SOC and threat intelligence team
Oversee the design and implementation of core platform security controls such as security guardrails, identity and access management (IAM), and network security for both public and private cloud environments
Lead the strategy for continuous monitoring, threat hunting, and rapid incident response to maintain the resilience of production systems
Contribute to the improvement of cyber resilience in the organization and industry through the development of cyber professionals by defining and tracking key security performance indicators (KPIs) to measure the efficacy of our defense controls and the security health of our hybrid infrastructures.
Over 7 years of professional experience in the information security field
Proven operational experience in cybersecurity, such as cloud infrastructure security, vulnerability management or security monitoring & response
At least 3 years of team management experience with service delivery and budget management
Proven implementation experience of preventative & defensive controls on public cloud or private cloud environments
Experience working in a distributed, cross-timezone team
Deep understanding of the core concepts of web/mobile application and vulnerability remediation lifecycle
Experience in vulnerability management, 0-day response & stakeholder management
Deep understanding of network and web application protocols
Strong teamwork capability in a diverse team environment
Excellent consultation, problem-solving, communication, and interpersonal skills to build trust and consensus with stakeholders
Strong ownership and sense of responsibility
Experience with global, large-scale infrastructures and ecosystems
Experience with zero-trust architecture and implementing security in a global, distributed network
Experience in Web service development, implementation/operation at cloud-native system infrastructures
Experience in a diverse workplace, and working well in a team environment
Experience in vendor contract management, security strategy planning with multiple IT/security products
Experience in implementation or support for compliance and security requirements such as PCI DSS or FISC
Holder of any security-related certifications such as Security+, GIAC, CISSP, OSCP/OSCE, SSCP
#engineer #securityengineer #technologymanagementdiv
English (総合 - 3 - 上級)