Jobless Developer
Rakuten Mobile, Inc. logo

Posted 14 days ago

Open

Senior Penetration Tester - Security Assurance Section (RMI Telecommunication Security Supervisory Dep)

TokyoRemoteFull-time

AI Summary

Senior Penetration Tester at Rakuten Mobile Security Assurance conducts manual and automated penetration testing across web/mobile apps, APIs, cloud platforms, and telecom infrastructure, including AI/ML and LLM security assessments, red teaming, and secure design reviews.

About this role

Job Description:

About Organization

At Rakuten Mobile Security Assurance, you will help secure one of the world's most advanced cloud-native telecom networks, protecting millions of customers across digital, mobile, cloud, and AI-driven services. We work on cutting-edge offensive security challenges spanning 4G/5G telecom platforms, cloud-native infrastructure, APIs, AI/ML systems, and emerging technologies.

We offer an environment where innovation is encouraged, continuous learning is supported, and security experts are empowered to make a direct business impact. You will work alongside industry-leading engineers, build next-generation security capabilities, leverage AI to transform security testing, and contribute to protecting critical telecommunications infrastructure at scale.

Job Duties

  • Comprehensive Penetration Testing:Conduct manual and automated testing of web/mobile applications, APIs, cloud platforms, and network infrastructure.

  • AI/ML Security Assessments:Evaluate LLM-based systems, AI agents, RAG implementations, and MLOps pipelines. Identify vulnerabilities such as prompt injection, insecure model integrations, data leakage, and AI supply chain risks.

  • Telecom Security Testing:Execute security assessments on telecom-specific systems, including BSS/OSS applications, eSIM platforms, subscriber management, and mobile network services.

  • Red Teaming & Adversary Emulation:Support red team exercises, conduct attack path analysis, and perform exploit validation using realistic attacker techniques.

  • Design & Code Review:Perform source code reviews, secure design reviews, and architecture-level security assessments.

  • Reporting & Remediation:Develop proof-of-concepts, create detailed technical reports, and provide actionable remediation recommendations. Validate fixes through re-testing.

  • Research & Innovation:Research emerging attack techniques, exploit methodologies, and AI-assisted offensive security methods.

Minimum Qualifications

  • Experience:10+ years of hands-on penetration testing and application security experience.

  • Technical Expertise:Deep expertise in web, mobile, API, cloud, infrastructure, and AI security testing.

  • Tooling:Proficiency with Burp Suite, Kali Linux, Metasploit, BloodHound, Nmap, Nessus, and modern offensive security frameworks.

  • Scripting/Coding:Strong knowledge of Python, JavaScript, Bash, or PowerShell for testing and automation.

  • Cloud/Infrastructure:Proficiency with cloud platforms (AWS, Azure, or GCP) and containerized environments (Kubernetes, Docker).

Preferred Qualifications

  • Telecom Expertise:Experience with telecom technologies, mobile core networks, BSS/OSS systems, and cloud-native telecom applications.

  • Certifications:OSCP, CRTP, CRTO, OSEP, OSWE, GPEN, GXPN, or equivalent.

  • Specialized Skills:

    • AI/LLM security testing and adversarial machine learning.

    • Red team operations and advanced exploit development.

    • Bug bounty, vulnerability research, and AI-assisted penetration testing.

Languages:

English (Overall - 3 - Advanced)

Skills

AWSAzureBashBloodHoundBurp SuiteCRTOCRTPDockerGCPGPENGXPNJavaScriptKali LinuxKubernetesMetasploitNessusNMAPOSCPOSEPOSWEPowerShellPython

Explore related jobs

Browse these categories

Market data for this role

All reports →