Security Operations Center Group Manager (L3) - Cyber Defense Operations Section
- Rakuten Mobile
- Akashi, Japan
- JPY 12,000,000 – JPY 18,000,000
About Organization
Cyber Defense Operations Section operates a 24/7 Security Operations Center (SOC) protecting Rakuten Group's critical infrastructure. We are currently in a critical transformation phase to address the era of autonomous, AI-driven cyber threats. Our goal is to evolve from a reactive monitoring unit into a proactive, intelligence-led, and autonomous defense organization. We are seeking a visionary and hands-on SOC Lead to architect our future-ready security operations, leveraging AI and automation to neutralize machine-speed attacks while mentoring high-performing security talent.
Job Duties
- Strategic Transformation: Lead the evolution of the SOC from a reactive monitoring unit to an autonomous, AI-augmented defense organization.
- AI & Automation Engineering: Architect and implement AI-driven detection and response workflows. Drive the integration of SOAR (Security Orchestration, Automation, and Response) to counter autonomous AI attacks.
- Operational Leadership: Manage the 24/7 SOC team, ensuring high-availability monitoring, rapid incident response, and continuous service improvement.
- Technical Oversight: Provide L3-level escalation support for complex incidents. Oversee security monitoring of Telco-specific network architectures, containerized environments, and Kubernetes (K8s) clusters.
- Governance & Documentation: Establish rigorous SOC governance, including the creation and maintenance of playbooks and SOPs that meet international audit and compliance standards.
- DFIR & Root Cause Analysis: Assist in high-stakes Digital Forensics and Incident Response (DFIR) efforts, conducting deep-dive analysis to harden the environment against future threats.
- Stakeholder Collaboration: Partner with cross-functional security teams and Business Units to ensure security is integrated throughout the infrastructure lifecycle.
- Innovation & Research: Stay at the bleeding edge of offensive and defensive AI research to proactively adapt security posture against evolving adversary tactics.
Minimum Qualifications
- Leadership: Proven experience leading technical teams in a 24/7 environment; demonstrated ability to mentor and grow security talent.
- AI/ML in Security: Deep understanding of leveraging AI for threat hunting, anomaly detection, and automated response.
- Telco & Infrastructure: Strong experience in a Telco environment, including knowledge of SS7/Diameter/GTP protocols, 5G core security, and virtualization.
- Cloud-Native Security: Expert-level knowledge of containerization (Docker) and Kubernetes (K8s) security.
- Automation: Advanced scripting skills (Python, Go, or Bash) and extensive experience with SOAR platforms.
- DFIR: Expert capability in conducting digital forensics and managing incident response lifecycles.
- Experience: 10+ years in Cyber Security, with at least 6 years in a leadership role within a SOC.
- Education: Bachelor's or Master's degree in Computer Science, Cyber Security, or a related field.
- Certifications: Relevant industry certifications (e.g., CISSP, CISM, GCIH, GCFA, or equivalent).
Preferred Qualifications
- Experience with LLM-based security tools or "AI-vs-AI" defense strategies.
- Experience in high-traffic, low-latency environments typical of modern Telecommunications.
- Active participation in the security community (e.g., public speaking, research papers, or open-source security tool development).
- Experience with cloud security (AWS/Azure/GCP) in a hybrid-Telco environment.
Work Environment
- Reporting: Reports to the Head of Cyber Defense Operations Section.
- Collaboration: Manages the 24/7 SOC team and collaborates cross-departmentally with other security functions and Business Units.
- Tech Stack: Containerization (Docker/K8s), Telco environment (5G Core, Signaling Protocols), SOAR platforms, Python/Go/Bash, Cloud Security (AWS/Azure/GCP), and LLM-based security tools.
Languages:
English (Overall - 3 - Advanced)
Skills
- Security Operations Center (SOC) Management
- SOAR (Security Orchestration, Automation, and Response)
- AI/ML for Cybersecurity
- Incident Response
- Kubernetes (K8s)
- Telecommunications Network Security
- Security Playbook Development






