SOC Analyst - Security Operations Center Group, Cyber Defense Operations Section (RMI Security Eng. & Ops Dep)
Описание от работодателя
Job Description:
About Organization
Cyber Defense Operations Section operates a 24/7 Security Operations Center (SOC) protecting Rakuten Group's critical infrastructure. We are currently in a critical transformation phase to address the era of autonomous, AI-driven cyber threats. Our mission is to evolve from a reactive monitoring unit into a proactive, intelligence-led, and automated defense organization. We are looking for a highly technical and innovative SOC Analyst (L2) to act as a key architect of our future-ready SOC, leveraging LLMs and AI-powered tools to neutralize advanced adversaries.
Job Duties
AI-Driven Threat Defense: Utilize LLMs and AI-augmented security platforms to accelerate threat hunting, incident triage, and forensic analysis. Develop workflows to identify and respond to autonomous AI-based attacks.
SOC Transformation: Actively contribute to the SOC’s capability roadmap. Recommend and implement structural improvements to toolsets and processes to handle the evolving threat landscape.
Container & K8s Security: Perform deep-dive analysis into containerized environments and Kubernetes clusters. Implement security controls against container-specific exploits and automated lateral movement.
Capacity Development: Participate in the continuous training and upskilling of the SOC team. Translate technical findings into new playbooks and SOPs to elevate the team's response maturity.
Advanced Incident Response: Lead the investigation of complex incidents. Apply "Defense in Depth" principles to identify environmental gaps and propose architectural hardening.
Security Engineering: Collaborate with the L3 Manager to tune detection logic and integrate AI-based feedback loops into our SIEM/SOAR infrastructure.
Offensive Security Research: Apply an "OffSec" mindset to simulate and test defenses against AI-powered attack tools, ensuring faster and more precise responses.
Minimum Qualifications
Bachelor’s degree in Computer Science, Cyber Security, or equivalent.
5–8 years of experience in a SOC, incident response, or security engineering role.
Strong understanding of SIEM/SOAR ecosystems and optimization for AI-driven detection.
Relevant certifications (e.g., GCIH, GCSA, CKAD, CKS, or AI-Security specific certifications).
Preferred Qualifications
Experience in the Telecommunications sector (e.g., 5G security, NFV, signaling protocols).
Experience in developing custom AI/ML models or fine-tuning LLMs for security use cases.
Demonstrable experience in "Red Teaming" or participating in high-level CTF competitions.
Experience with Infrastructure as Code (IaC) and DevSecOps pipelines.
Work Environment
Reporting: Reports to the Manager of the Security Operations Center Group.
Collaboration: Manages/mentors the 24/7 SOC team and collaborates cross-departmentally with other security functions and Business Units.
Tech Stack: Containerization (Docker/Kubernetes), Telco environments (5G Core, Signaling Protocols), SOAR platforms, Python/Go/Bash, Cloud Security (AWS/Azure/GCP), and LLM-based security tools.
Languages:
English (Overall - 3 - Advanced)