Posted 2 days ago
Detection Engineering Tech Lead, Detection Engineering Group -Cyber Defense Operations Section (RMI Telecommunication Security Supervisory Dep)
AI Summary
Lead the Detection Engineering team to architect and build next-generation detection pipelines using AI/LLM, eBPF runtime security, and Detection-as-Code practices to defend critical infrastructure against autonomous AI attacks and APTs.
About this role
Job Description:
About the Organization
Cyber Defense Operations is the core department responsible for ensuring the safety and security of Rakuten Group's internet services. The Detection Engineering Section is tasked with architecting and building next-generation detection pipelines to defend critical infrastructure against autonomous, AI-driven attacks and sophisticated APTs. We lead the transition to a Detection-as-Code (DaC) model, utilizing eBPF-based runtime security, behavioral analytics, and LLM-integrated pipelines to deliver high-fidelity, actionable alerts. We are "defenders with an attacker's brain," committed to proactive, intelligence-led defense.
Job Duties
- Detection-as-Code (DaC) Transformation: Build and manage an end-to-end detection pipeline featuring peer reviews, version control (Git), and a reusable repository of detection rules.
- AI/LLM-Driven Detection: Architect and develop AI/LLM-based models to identify autonomous AI attacks. Use AI to automate log onboarding, normalize data, and filter "garbage logs" to drastically reduce SOC noise.
- Advanced Runtime Security: Lead the implementation of kernel-level monitoring using eBPF-based tools to provide deep visibility into containerized (K8s) and Linux-based workloads.
- Offensive Security & Threat Hunting: Perform continuous attack simulations (Red Teaming) to validate detection coverage. Lead proactive threat hunting initiatives informed by CTI and the MITRE ATT&CK/FIGHT frameworks.
- Deception & Defense-in-Depth: Deploy and manage deception technologies to create high-interaction traps. Ensure detection logic aligns with our defense-in-depth architecture.
- Cross-Functional Orchestration: Collaborate with DFIR, CTI, and SOC teams to ensure CTI is actively integrated into detection logic via AI-driven automation.
- AI Guardrails & Security: Oversee the security of our own AI/LLM models, implementing guardrails to prevent model poisoning, prompt injection, and adversarial manipulation.
- SOAR Integration: Partner with the SOC team to ensure detection logic feeds seamlessly into SOAR playbooks for machine-speed response.
Minimum Qualifications
- Experience: 10+ years in Cyber Security, with at least 5+ years in Detection Engineering or Security Research.
- Detection Engineering: Deep expertise in building detection pipelines, tuning logic for high-fidelity alerts, and managing the security rule lifecycle.
- AI/ML/LLM Proficiency: Practical experience building/tuning models for anomaly detection and log analysis.
- Technical Depth: Expert-level coding skills (Python, Go, or Rust) and mastery of Linux/Windows/Mac internals.
- Container & K8s Security: Strong hands-on experience securing Kubernetes clusters, container runtimes, and microservices architectures.
- Domain Knowledge: Understanding of Telco networks/protocols (e.g., 5G core, signaling) and Network Security (packet analysis, perimeter/internal controls).
- Offensive Mindset: Experience in penetration testing, exploit development, or red teaming.
- Education: Bachelor's or Master's degree in Computer Science, Cyber Security, or equivalent.
- Certifications: Relevant certifications (e.g., OSCP, GREM, GCFA, CKS, BTL2, or AI-Security credentials).
Preferred Qualifications
- Experience with Infrastructure as Code (Terraform, Ansible, Crossplane).
- Deep experience with eBPF tools (e.g., Tetragon, Falco, Cilium, Spyderbat).
- Active contributor to open-source detection projects (e.g., Sigma, YARA, or custom AI-detection models).
- Experience in high-scale environments (Telco, Cloud-Native, or FinTech).
Work Environment
- Department: Detection Engineering Section, Cyber Defense Operations.
- Collaboration: Work with diverse teams including security researchers, threat hunters, and AI/ML specialists.
- Tech Stack: Python/Go/Rust, Kubernetes, Linux, eBPF, Git/Sigma/YARA, LLM-integrated pipelines, SOAR, Terraform/Ansible.
- Location: Japan (Tokyo or Osaka). Domestic/overseas business travel and relocation may be required.
Languages:
English (Overall - 3 - Advanced)Skills
Explore related jobs
More jobs at Rakuten Mobile, Inc.
- SOC Analyst - Security Operations Center Group, Cyber Defense Operations Section (RMI Security Eng. & Ops Dep)Tokyo, Japan
- Senior Network Security Engineer, Network Security Engineering Group - Security Engineering Section (RMI Security Eng. & Ops Dep)Tokyo, Japan
- Senior Network Security Engineer, System Security Engineering Group - Security Engineering Section (RMI Security Eng. & Ops Dep)Tokyo, Japan
- Security Operations Center Group Manager (L3) -Cyber Defense Operations Section (RMI Telecommunication Security Supervisory Dep)Tokyo, Japan
- 渉外戦略室:渉外政策グループ スタッフ (RMI 渉外部)Tokyo, Japan
- 渉外調整課:担当部長/シニアマネージャー候補 (RMI 渉外部)Tokyo, Japan
Similar Ansible jobs
Jobs in Tokyo
- Senior Corporate IT EngineerSynspective · Tokyo, Tokyo
- Lead Electrical EngineerPacifico Energy Group · Tokyo, Tokyo
- Lead Civil/Structural Engineer/ManagerPacifico Energy Group · Tokyo, Tokyo
- Senior System Controls EngineerPacifico Energy Group · Tokyo, Tokyo
WPP Media | Senior Activation Executive, JapanWPP · Tokyo, Japan
People & Culture GeneralistAirTrunk · Roppongi, Tokyo
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.