Security Architect (Cloud Monitoring & Response) - Product Security Section, Cyber Security Defense Department (CSDD)

Rakuten Group, Inc.

Apply to this job
Tokyo, Japan Until 9/29/2026 10+ years exp H-1B sponsor history First posted July 31, 2026 Last posted July 31, 2026
Job description

Job Description:

Business Overview

The Technology Management Division (TMD) provides corporate IT, cyber security, and privacy governance to Rakuten Group companies and essential business management for technology organizations, thereby enabling innovation and strengthening its technology foundation. Within TMD, the Information Security Supervisory Department (ISSD) combines proactive cyber defense with strategic information security, privacy, and data governance to protect the company’s global assets and data.

Department Overview

The Cyber Security Defense Department (CSDD) is responsible for safeguarding all Rakuten companies and users from cyber threats, ensuring the security and integrity of Rakuten Group's global internet services. We oversee all aspects of both Secure Development and Security Operations for services developed within the group, with dedicated security teams and operation centers strategically located in key regions worldwide.

Position:

Position Details

To design and evolve a world-class security monitoring and response ecosystem that provides deep observability and rapid defense capabilities across Rakuten’s global hybrid cloud infrastructure, ensuring our ecosystem is both secure by design and resilient by default.

<Role Overview>

We are looking for a visionary Security Architect to lead the design of our global cloud security monitoring and incident response infrastructure. You will be the technical authority responsible for creating the blueprint for how we ingest, analyze, and act upon security telemetry for our private cloud environments. You will bridge the gap between high-level security strategy and technical implementation, ensuring our platforms are capable of detecting and neutralizing advanced threats at scale.

<Key Responsibilities>

・Design and architect the next-generation security monitoring platform (SIEM/Data Lake/SOAR) capable of handling massive telemetry volume across a global, private cloud footprint

・Define the architectural patterns for high-fidelity detection, ensuring that security logs, cloud-native telemetry, and endpoint data are effectively correlated

・Architect the automated response framework (SOAR) to ensure we can contain threats at machine speed, minimizing the impact of incidents on production

・Collaborate with SRE and Cloud Platform teams to embed "Security Observability" into our infrastructure, ensuring we have the visibility required for modern threat hunting

・Evaluate and select security technologies (commercial and open-source) that align with Rakuten’s scale, latency requirements, and long-term security goals

・Establish global architectural standards for logging, monitoring, and response to ensure consistency across all Rakuten business units

Mandatory Qualifications:

・More than 10 years in IT/Security, with at least 5 years in Security Architecture, specifically focusing on SOC infrastructure or large-scale monitoring systems

・Deep expertise in architecting security for multi-cloud environments (private cloud, AWS, GCP, Azure)

・Extensive experience designing and scaling SIEM/Log Management platforms (e.g., Splunk, Chronicle, Elastic, Sentinel)

・Proven experience designing SOAR or custom automated response workflows for large-scale production environments

・Understanding of data pipelines, streaming technologies (e.g., Kafka), and the challenges of high-volume telemetry ingestion

・Exceptional ability to translate complex security architectural requirements into actionable roadmaps for engineering teams and business stakeholders

・Strong knowledge of MITRE ATT&CK, NIST, or similar frameworks as they apply to detection and response architecture

Desired Qualifications:

・Experience connecting private cloud/on-premise data centers to public cloud security monitoring architectures

・Background in software development or systems engineering; ability to "code" as part of the architectural design process

・Experience working in highly regulated, global industries (FinTech, E-commerce, Telecom)

・TOGAF, CISSP-ISSAP, or advanced cloud-architect certifications

#engineer #securityengineer #technologymanagementdiv

Languages:

English (Overall - 3 - Advanced)
About this role

Summary

Designs security monitoring and response systems for global hybrid cloud infrastructure.

Job title

Security Architect (Cloud Monitoring & Response)

Experience level

more than 10 years

Minimum experience

10+ years exp

Industry

software

Location requirements

Tokyo, Japan; remote work not specified

Salary

Not specified

Visa sponsorship

H-1B sponsor history

Management role

No

Skills & keywords

Required skills

security architectureSIEMcloud environmentsSOARtelemetry

Preferred skills

private cloud integrationsoftware developmentregulated industry experiencecertifications

Specializations

cloud securitymonitoringincident responseSIEMcloud architectures
Locations

Structured locations inferred from the posting.

Tokyo, Japan

Work arrangement unknown City