Security Architect (SIEM & IR Security Engineering) - Rakuten-CERT Section, Cyber Security Defense Department (CSDD)
取得日 2026年10月2日・最終確認 2026年10月2日
募集要項
記載なし
東京都
記載なし
記載なし
募集内容
Job Description
Business Overview
The Technology Management Division (TMD) provides Corporate IT, and Cyber Security & Privacy Governance to Rakuten Group companies and essential business management for technology organizations, thereby enabling innovation and strengthening the technology foundation.
Within TMD, the Technology Management Services Supervisory Department (TMSSD) plays a vital role in CIO Governance, IT financial management, IT procurement, Quality Management System (QMS), technology-related public relations, and human resources strategy. By promoting efficiency, quality, risk management, and organizational strength, we ensure that Tech Divisions remain agile and at the forefront of technological advancement.
Department Overview
The Cyber Security Defense Department (CSDD) is responsible for safeguarding all Rakuten companies and users from cyber threats, ensuring the security and integrity of Rakuten Group's global internet services. We oversee all aspects of both Secure Development and Security Operations for services developed within the group, with dedicated security teams and operation centers strategically located in key regions worldwide.
Position:
Position Details
The Security Architect acts as the strategic partner to our Security Engineering (SIEM/IR) team. While the Security Engineering team focuses on the "detect and respond" lifecycle, the Security Architect focuses on the "design and prevent" lifecycle. You will define the security blueprints, architectural standards, and governance models that our security engineers will ultimately monitor and defend.
This role is a perfect fit for a senior expert with leadership aspirations who wants to influence the security posture of the entire Rakuten ecosystem.
Unlike purely consultative roles, this position allows you to influence the Cyber Security Defense Department’s operational efficiency. By designing the standards that the SIEM/IR team enforces, you are directly responsible for reducing the "noise" and increasing the "signal" in our global security operations.
Key Responsibilities
Architectural Governance
- Develop and maintain technical security standards, policies, and guidelines that provide the foundation for secure system development
Design-Phase Security
- Lead security requirements and design reviews for new projects, ensuring that architectural flaws are caught before they reach production
Feedback Loop Integration
- Collaborate closely with the SIEM & Incident Response team to translate real-world threat data (TTPs, IOCs) into proactive architectural changes and hardening strategies
Strategic Leadership
- Mentor junior staff and collaborate with cross-functional stakeholders to build consensus on security roadmaps
Innovation & Scaling
- Drive the evolution of our security posture by integrating modern security patterns (e.g., Zero Trust, DevSecOps) into the SDLC
<Collaboration with the Security Engineering Team>
- Work in tandem with the Security Engineers
Bridge the Gap
- Use findings from IR playbooks and SIEM detection use cases to update organizational security policies
Security by Design
- Ensure that as the engineering team develops new detection capabilities, the underlying system architecture supports visibility, logging, and automated remediation
Mandatory Qualifications
- Education: Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field (or equivalent professional experience)
- Professional Experience: More than 8 years of experience in cybersecurity, with a proven track record in security architecture, system design, or senior-level security engineering
- Architectural Expertise: Demonstrated experience in designing secure system architectures, integrating security into the SDLC, and applying security patterns (e.g., Zero Trust, Defense-in-Depth) to complex enterprise environments
- Operational Foundation: Strong understanding of security operations (SIEM, Incident Response, Forensics) sufficient to inform the design of resilient, monitorable, and defensible architectures
- Framework Proficiency: Expert-level knowledge of industry-standard frameworks (NIST, CIS, ISO 27001) and the ability to map these requirements to technical controls and business processes
- Cloud & Modern Infrastructure: Significant experience designing and governing secure architectures within major commercial cloud environments (e.g., AWS, GCP, or Azure)
- Threat-Informed Design: Deep familiarity with the MITRE ATT&CK framework, specifically how to translate adversary TTPs into proactive architectural hardening and detection requirements
- Communication & Influence: Exceptional ability to translate complex security risks and architectural trade-offs into clear, actionable insights for both technical teams and non-technical executive stakeholders
- Leadership Potential: Demonstrated interest in people management and a clear ambition to grow into a formal leadership role within the Cyber Security Defense Department (CSDD)
- Soft Skills: Proven ability to build consensus, navigate complex organizational structures, and maintain a collaborative approach in a fast-paced, high-pressure environment
Desired Qualifications
- Related professional certifications such as CISSP, CISM, or equivalent architectural certifications
- Japanese language skills are a significant advantage for cross-departmental coordination
#engineer #securityengineer #technologymanagementdiv
Languages:
English (Overall - 3 - Advanced)
求人情報は各社が公開している採用ページから取得しています。掲載企業とAirTAの間に資本関係や提携関係はありません。
掲載企業の方はこちら(掲載内容の確認、掲載停止のご依頼)