Security Engineer - Rakuten-CERT Section, Cyber Security Defense Department (CSDD)
Rakuten Crimson House, Japan
Rakuten
楽天グループ株式会社のコーポレートサイトです。企業情報や投資家情報、プレスリリース、サステナビリティ情報、採用情報などを掲載しています。楽天グループは、イノベーションを通じて、人々と社会をエンパワーメントすることを目指しています。Job Description:
Department Overview
The Cyber Security Defense Department is responsible for all aspects of cybersecurity and secure development. Our functions include security training, security champions, security monitoring, incident response, digital forensics, penetration testing, red teaming, scanner integration, and more. We utilize a variety of technologies, including major Cloud Service Providers (CSPs) such as Azure and GCP, as well as tools like SIEM, Slack, Teams, and SOAR.
Position:
Position Details
Alert Tuning and In-Depth Analysis for Security Products:
- Analyzing alerts from security products (IDS, EDR, Firewall, SASE) and tuning them to reduce false positives.
- Identifying signs of attacks and security incidents from these alerts, and performing detailed root cause analysis and impact assessment.
- Creating and improving detection rules to address new attack techniques.
Security Product Alert Analysis and Incident Response on Windows and Linux Hosts:
- Analyzing security product alerts to identify security incidents.
- Performing initial incident response, impact assessment, containment, and remediation efforts when incidents occur.
- Developing and implementing measures to prevent recurrence after incident response.
SIEM Use Case Development:
- Developing SIEM (Security Information and Event Management) Use Cases (detection rules) for collecting and analyzing security logs.
- Improving Use Cases to address new threats and attack techniques.
- Analyzing SIEM operational status to identify and implement improvements.
- Collaborating with service personnel and related departments to integrate new logs into the SIEM.
Mandatory Qualifications:
- Minimum of 3 years of experience in cybersecurity-related fields, particularly in alert triage, incident response, and threat detection.
- Knowledge of TCP/IP networking.
- Experience with SIEM and security products (IDS/IPS, EDR, Firewall, WAF, SASE, etc.).
- Experience using scripting languages (e.g., Python, Bash).
- Strong leadership and teamwork skills in a diverse team environment with members from different backgrounds.
- Excellent verbal and written communication skills.
- Strong sense of ownership and responsibility towards work.
- Strong communication skills in English (TOEIC 800 or above)
Desired Qualifications:
- Knowledge of Linux/Windows OS security.
- Experience in managing and configuring security products.
- Experience in developing SIEM Use Cases.
- Deep understanding of the MITRE ATT&CK Framework.
- Experience in designing and building log collection and analysis systems.
- Knowledge of cloud environment (e.g., AWS, Azure, GCP) security and experience using cloud services.
- Japanese language communication skills.
- Security-related certifications (e.g., CompTIA Security+, CEH, CISSP).
#engineer
#securityengineer
#technologymanagementdiv
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: AWS Azure Bash CEH CERT CISSP Cloud CompTIA EDR Firewalls Forensics GCP IDS Incident response IPS Linux MITRE ATT&CK Monitoring Pentesting Python Red team SASE Scripting SIEM SOAR TCP/IP Threat detection Windows
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.