JobConnect

SOC Analyst - Security Operations Center Group, Cyber Defense Operations Section

About Organization

Cyber Defense Operations Section operates a 24/7 Security Operations Center (SOC) protecting Rakuten Group's critical infrastructure. We are currently in a critical transformation phase to address the era of autonomous, AI-driven cyber threats. Our mission is to evolve from a reactive monitoring unit into a proactive, intelligence-led, and automated defense organization. We are looking for a highly technical and innovative SOC Analyst (L2) to act as a key architect of our future-ready SOC, leveraging LLMs and AI-powered tools to neutralize advanced adversaries.

Job Duties

  • AI-Driven Threat Defense: Utilize LLMs and AI-augmented security platforms to accelerate threat hunting, incident triage, and forensic analysis. Develop workflows to identify and respond to autonomous AI-based attacks.
  • SOC Transformation: Actively contribute to the SOC’s capability roadmap. Recommend and implement structural improvements to toolsets and processes to handle the evolving threat landscape.
  • Container & K8s Security: Perform deep-dive analysis into containerized environments and Kubernetes clusters. Implement security controls against container-specific exploits and automated lateral movement.
  • Capacity Development: Participate in the continuous training and upskilling of the SOC team. Translate technical findings into new playbooks and SOPs to elevate the team's response maturity.
  • Advanced Incident Response: Lead the investigation of complex incidents. Apply "Defense in Depth" principles to identify environmental gaps and propose architectural hardening.
  • Security Engineering: Collaborate with the L3 Manager to tune detection logic and integrate AI-based feedback loops into our SIEM/SOAR infrastructure.
  • Offensive Security Research: Apply an "OffSec" mindset to simulate and test defenses against AI-powered attack tools, ensuring faster and more precise responses.

Minimum Qualifications

  • Bachelor’s degree in Computer Science, Cyber Security, or equivalent.
  • 5–8 years of experience in a SOC, incident response, or security engineering role.
  • Strong understanding of SIEM/SOAR ecosystems and optimization for AI-driven detection.
  • Relevant certifications (e.g., GCIH, GCSA, CKAD, CKS, or AI-Security specific certifications).

Preferred Qualifications

  • Experience in the Telecommunications sector (e.g., 5G security, NFV, signaling protocols).
  • Experience in developing custom AI/ML models or fine-tuning LLMs for security use cases.
  • Demonstrable experience in "Red Teaming" or participating in high-level CTF competitions.
  • Experience with Infrastructure as Code (IaC) and DevSecOps pipelines.

Work Environment

  • Reporting: Reports to the Manager of the Security Operations Center Group.
  • Collaboration: Manages/mentors the 24/7 SOC team and collaborates cross-departmentally with other security functions and Business Units.
  • Tech Stack: Containerization (Docker/Kubernetes), Telco environments (5G Core, Signaling Protocols), SOAR platforms, Python/Go/Bash, Cloud Security (AWS/Azure/GCP), and LLM-based security tools.

Languages:

English (Overall - 3 - Advanced)

Skills

  • Security Operations Center (SOC)
  • Incident Response
  • Threat hunting
  • Kubernetes Security
  • Container Security
  • AI/LLM Security Tools
  • Playbook development

Related jobs

Rakuten MobileApply for this job