JobConnect

Security Operations Center Group Manager (L3) - Cyber Defense Operations Section

About Organization

Cyber Defense Operations Section operates a 24/7 Security Operations Center (SOC) protecting Rakuten Group's critical infrastructure. We are currently in a critical transformation phase to address the era of autonomous, AI-driven cyber threats. Our goal is to evolve from a reactive monitoring unit into a proactive, intelligence-led, and autonomous defense organization. We are seeking a visionary and hands-on SOC Lead to architect our future-ready security operations, leveraging AI and automation to neutralize machine-speed attacks while mentoring high-performing security talent.

Job Duties

  • Strategic Transformation: Lead the evolution of the SOC from a reactive monitoring unit to an autonomous, AI-augmented defense organization.
  • AI & Automation Engineering: Architect and implement AI-driven detection and response workflows. Drive the integration of SOAR (Security Orchestration, Automation, and Response) to counter autonomous AI attacks.
  • Operational Leadership: Manage the 24/7 SOC team, ensuring high-availability monitoring, rapid incident response, and continuous service improvement.
  • Technical Oversight: Provide L3-level escalation support for complex incidents. Oversee security monitoring of Telco-specific network architectures, containerized environments, and Kubernetes (K8s) clusters.
  • Governance & Documentation: Establish rigorous SOC governance, including the creation and maintenance of playbooks and SOPs that meet international audit and compliance standards.
  • DFIR & Root Cause Analysis: Assist in high-stakes Digital Forensics and Incident Response (DFIR) efforts, conducting deep-dive analysis to harden the environment against future threats.
  • Stakeholder Collaboration: Partner with cross-functional security teams and Business Units to ensure security is integrated throughout the infrastructure lifecycle.
  • Innovation & Research: Stay at the bleeding edge of offensive and defensive AI research to proactively adapt security posture against evolving adversary tactics.

Minimum Qualifications

  • Leadership: Proven experience leading technical teams in a 24/7 environment; demonstrated ability to mentor and grow security talent.
  • AI/ML in Security: Deep understanding of leveraging AI for threat hunting, anomaly detection, and automated response.
  • Telco & Infrastructure: Strong experience in a Telco environment, including knowledge of SS7/Diameter/GTP protocols, 5G core security, and virtualization.
  • Cloud-Native Security: Expert-level knowledge of containerization (Docker) and Kubernetes (K8s) security.
  • Automation: Advanced scripting skills (Python, Go, or Bash) and extensive experience with SOAR platforms.
  • DFIR: Expert capability in conducting digital forensics and managing incident response lifecycles.
  • Experience: 10+ years in Cyber Security, with at least 6 years in a leadership role within a SOC.
  • Education: Bachelor's or Master's degree in Computer Science, Cyber Security, or a related field.
  • Certifications: Relevant industry certifications (e.g., CISSP, CISM, GCIH, GCFA, or equivalent).

Preferred Qualifications

  • Experience with LLM-based security tools or "AI-vs-AI" defense strategies.
  • Experience in high-traffic, low-latency environments typical of modern Telecommunications.
  • Active participation in the security community (e.g., public speaking, research papers, or open-source security tool development).
  • Experience with cloud security (AWS/Azure/GCP) in a hybrid-Telco environment.

Work Environment

  • Reporting: Reports to the Head of Cyber Defense Operations Section.
  • Collaboration: Manages the 24/7 SOC team and collaborates cross-departmentally with other security functions and Business Units.
  • Tech Stack: Containerization (Docker/K8s), Telco environment (5G Core, Signaling Protocols), SOAR platforms, Python/Go/Bash, Cloud Security (AWS/Azure/GCP), and LLM-based security tools.

Languages:

English (Overall - 3 - Advanced)

Skills

  • Security Operations Center (SOC) Management
  • SOAR (Security Orchestration, Automation, and Response)
  • AI/ML for Cybersecurity
  • Incident Response
  • Kubernetes (K8s)
  • Telecommunications Network Security
  • Security Playbook Development

Related jobs

Rakuten MobileApply for this job