Sobre este puesto de Staff Engineer, Offensive Security en Rakuten
Job Description:
About the Team/Department:
At Rakuten Mobile Security Assurance, you will help secure one of the world's most advanced cloud-native telecom networks, protecting millions of customers across digital, mobile, cloud, and AI-driven services.
You will work on cutting-edge offensive security challenges spanning 4G/5G telecom platforms, cloud-native infrastructure, applications, APIs, AI/ML systems, and emerging technologies.
We offer an environment where innovation is encouraged, continuous learning is supported, and security experts are empowered to make a direct business impact.
You will have the opportunity to work alongside industry-leading engineers, build next-generation security capabilities, leverage AI to transform security testing, and contribute to protecting critical telecommunications infrastructure at scale.
If you are passionate about offensive security, enjoy solving complex technical challenges, and want to shape the future of cybersecurity in the AI era, we would love to hear from you.
Position Summary
Lead Rakuten Mobile's Offensive Security program, driving security assessments across web, mobile, API, cloud, AI/ML, and telecom platforms. The role is responsible for defining offensive security strategy, leading red team operations, overseeing vulnerability management and bug bounty programs, and ensuring proactive identification and mitigation of security risks across enterprise and telecom environments.
Key Responsibilities
• Define and execute the offensive security strategy, roadmap, standards, and testing methodologies.
• Lead penetration testing, red teaming, adversary emulation, and attack surface management initiatives.
• Oversee security assessments for web applications, mobile applications, APIs, cloud platforms, AI/ML
systems, and telecom/BSS/OSS environments.
• Drive security validation of 4G/5G network components, telecom applications, eSIM/RSP platforms, subscriber management systems, and internet-facing services.
• Evaluate AI/ML models, LLM applications, AI agents, and MLOps pipelines for security vulnerabilities, prompt injection, model abuse, data poisoning, and adversarial AI attacks.
• Manage bug bounty programs, external security researchers, and vulnerability disclosure processes.
• Lead and mentor offensive security engineers and penetration testers, supporting technical capability
development and delivery quality.
• Partner with Engineering, DevOps, Cloud, Product Security, Infrastructure, and business teams to drive remediation and risk reduction.
• Build offensive security automation capabilities using AI-assisted testing, attack simulation, and continuous security validation frameworks.
• Provide leadership-level reporting on security posture, emerging threats, risk trends, and remediation progress.
Required Qualifications
• 10+ years of cybersecurity experience with significant offensive security expertise.
• Strong hands-on experience across application security, cloud security, infrastructure security, AI security, and telecom security testing.
• Deep knowledge of OWASP Top 10, API Security Top 10, MITRE ATT&CK, threat modeling, red teaming, and exploit development.
• Experience managing large-scale security programs and leading technical teams.
• Knowledge of 4G/5G architecture, telecom protocols, BSS/OSS platforms, and cloud-native technologies is highly desirable.
Preferred Qualifications
• Experience with telecom technologies, mobile core networks, BSS/OSS systems, and cloud-native telecom applications is preferred.
• Preferred certifications: OSCP, CRTP, CRTO, OSEP, OSWE, GPEN, GXPN or equivalent certifications.
Core Competencies
- Offensive Security Strategy and Technical Leadership – Defines the offensive security strategy and provides hands-on leadership for complex penetration tests, exploit validation, and attack-path analysis.
- Application, API, Mobile, and Code Security – Assesses web and mobile applications, APIs, source code, architectures, and secure design, and validates remediation effectiveness.
- Cloud, Identity, and Infrastructure Security – Tests AWS, Azure, GCP, Kubernetes, containers, networks, identity systems, hybrid environments, and cloud-native configurations.
- Telecom and 4G/5G Security – Evaluates telecom protocols, mobile core components, BSS/OSS, eSIM/RSP, subscriber platforms, network functions, and end-to-end attack paths.
- AI/ML and Emerging Technology Security – Assesses LLMs, AI agents, RAG solutions, MLOps pipelines, prompt injection, model abuse, data leakage, adversarial attacks, and AI supply-chain risks.
- Red Teaming, Adversary Emulation, and Operational Safety – Leads threat-intelligence-driven exercises using realistic attacker techniques, clear rules of engagement, safety controls, escalation paths, and stop conditions.
- Security Automation and Continuous Validation – Uses scripting, AI-assisted testing, attack simulation, and continuous validation frameworks to scale offensive security testing and integrate it into engineering workflows.
- Program Governance, Vulnerability, and Bug Bounty Management – Establishes standards, quality controls, delivery metrics, vulnerability workflows, remediation tracking, retesting, exception management, and responsible disclosure processes.
- Risk-Based Prioritization, Reporting, and Stakeholder Influence – Prioritizes findings based on exploitability and business impact, communicates risk clearly, reports trends and KPIs, and drives remediation through closure.
- People Leadership, Capability Development, Ethics, and Accountability – Leads and mentors security professionals, builds team capability, manages sensitive information responsibly, and ensures all testing is authorized, controlled, and professionally conducted.