Rakuten

Security Engineer, Product Security Section - Cyber Security Defense Department (CSDD)

Tokyo, Japan
Azure GCP Python Java JavaScript AWS
Description

Job Description:

Department Overview

In Rakuten, security and safety of the Internet services of our group are guaranteed by the Cyber Security Defense Department (CSDD). CSDD covers all aspects of the System Development Life Cycle (SDLC) and operation security for all the services developed inside Rakuten Group.

Our mission is to empower all product and platform development teams to understand and improve their security level by forming a community to deliver security trend information, delivering demanded and state-of-the-art security solutions and professional-grade security consulting services.

Position:

Why We Hire

We are expanding the team to meet additional demand for our work.

We are looking for a security engineer with the following attributes:

- Can effectively guide our development teams to remediate or reduce the risk of security vulnerabilities

- Can develop and maintain tools and scripts

- Has strong communication and interpersonal skills, with the ability to convey complex security concepts to technical and non-technical stakeholders

- Management aspirations as a plus, to ensure we have leaders in our future to effectively guide us

 

Position Details

Primary

- Manage vulnerabilities after assessments have been performed, until remediation or risk acceptance.

- Collaborate with development teams and other security teams to reduce the risk of identified vulnerabilities.

- Review and assess proposed remediation solutions from development teams to ensure they meet security standards.

- Develop and maintain security tools, scripts, automation frameworks, and reporting.
 

Security Education, Leadership, and Growth

- Stay up-to-date with the latest security threats, vulnerabilities, and mitigation techniques.

- Inspire innovation and deliver quality at speed across the platform and execute these to success through diligent planning, attention to detail, effective delegation, efficient decision making, and individual/team accountability.

- Provide security training and guidance to development teams.

- Provide guidance and mentorship to other team members for your areas of expertise.

- Contribute to projects where your expertise is required.

- Document security processes, procedures, and guidelines.

- Perform some security requirement analysis or design reviews and provide recommendations.

 

Work Environment

We are a small and diverse team with expertise in different domains.  Our team highly values relationships, teamwork, celebrating individuality, discovery, innovation, sharing knowledge, adaptability, mutual trust, and high-quality work.  We value working well both independently and with others.

Mandatory Qualifications:

- 3+ years of experience in cyber security (with experience handling vulnerabilities)

- Strong understanding of common security vulnerabilities and mitigation techniques.

- Proficiency in at least one programming or scripting language (e.g., Python, Java, JavaScript).

- Experience with security tools and technologies (e.g., static and dynamic analysis tools, vulnerability scanners).

- Familiarity with security frameworks and standards (e.g., NIST, ISO 27001).

Desired Qualifications:

- Degree in Computer Science, Information Security, or a related field.

- Relevant security certifications (e.g., CISSP, CEH, OSCP).

- Experience with DevSecOps practices and tools (e.g., CI/CD pipelines, container security).

- Knowledge of cloud security (e.g., AWS, Azure, Google Cloud).

- Experience with security design reviews and threat modeling.

- Familiarity with secure coding practices and code review processes.

- Japanese language ability is a bonus

#engineer #securityengineer #technologymanagementdiv #securityengineer 

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 401 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say