掲載日 ・ 2026/09/09
楽天グループ株式会社
楽天グループ株式会社:1035794 Team Manager, Platform Security Group – Cyber Security Defense Department (CSDD)
非公開
東京都
楽天グループ
インターネットサービス(EC、メディア、アプリ)
クラウドエンジニア
会社名
楽天グループ株式会社
会社概要
未来を信じ、より良い明日を創っていく。
イノベーションを通じて、人々と社会をエンパワーメントする。私たちは、そんな想いを大切に世界の人々に喜びと楽しさを届けます。
楽天は、E コマース、FinTech、デジタルコンテンツ、通信など、70 を超えるサービスを展開し、世界10 億以上のユーザーに利用されています。
これら様々なサービスを、楽天会員を中心としたメンバーシップを軸に有機的に結び付け、他にはない独自の「楽天エコシステム」を形成しています。ダイバーシティ推進は、楽天にとって最優先の企業戦略のひとつです。従業員の出身は70カ国・地域以上。世界中からユニークで多様な文化的背景や視点を持つ優秀な人材が集まり、イノベーションの原動力になっています。社内カフェテリアにはベジタリアン、ハラル対応のメニューを用意。礼拝所(Prayer room)もあります。
また、仕事と育児の両立支援や、障がい者雇用・活躍促進も積極的に推進。社内のLGBT(※1)当事者やアライ(※2)に対して、情報共有やサポート体制の強化も進めています。誰もが自分らしく力を最大限発揮して働ける。それが楽天のダイバーシティです。
70を超えるサービスを提供し、世界30カ国にサービス展開拠点を持ち、従業員の出身国・地域数は100を超え、オープンポジション制度を活用して多様なキャリアを描くことができる点も魅力です。
フレックスタイム制度、事情に応じたリモートワークの活用が可能です。本社には託児所やフィットネスジム、三食無料で利用可能なカフェテリアが併設されるなど、社員を支える環境が整備されています。
ポジション
1035794 Team Manager, Platform Security Group - Cyber Security Defense Department (CSDD)
仕事内容
Job Description:
Business Overview
The Technology Management Division (TMD) provides corporate IT, cyber security, and privacy governance to Rakuten Group companies and essential business management for technology organizations, thereby enabling innovation and strengthening its technology foundation. Within TMD, the Information Security Supervisory Department (ISSD) combines proactive cyber defense with strategic information security, privacy, and data governance to protect the company’s global assets and data.
Position:
Why We Hire
As our global ecosystem grows, we are scaling our defense capabilities to stay ahead of sophisticated threat actors. We are looking for a leader to transform our platform security from reactive to proactive, ensuring resilience at the speed of our business.
Team Mission Statement
To deliver comprehensive cybersecurity by embedding robust security into the design, development and delivery of Rakuten's products for our customers' peace of mind and protecting Rakuten's production systems for our global ecosystem's operational resilience.
Position Details
We are looking for a strategic and hands-on Manager to lead our platform security team. You will be responsible for the end-to-end security posture of Rakuten’s hybrid infrastructure, spanning both public cloud (AWS/GCP/Azure) and private cloud environments. You will lead a team of security engineers to embed "security-by-design" into our development lifecycle while ensuring proactive monitoring, rapid incident response, and operational stability across our global ecosystem.
Key Responsibilities
- Build and maintain strategies for Rakuten’s platform security, spanning both public cloud (AWS/GCP/Azure) and private cloud environments
- Manage the platform security team and defend Rakuten services and IT systems from advanced cyber attacks and crimes by partnering with our SOC and threat intelligence team
- Oversee the design and implementation of core platform security controls such as security guardrails, identity and access management (IAM), and network security for both public and private cloud environments
- Lead the strategy for continuous monitoring, threat hunting, and rapid incident response to maintain the resilience of production systems
- Contribute to the improvement of cyber resilience in the organization and industry through the development of cyber professionals by defining and tracking key security performance indicators (KPIs) to measure the efficacy of our defense controls and the security health of our hybrid infrastructures.
求める経験・スキル
Mandatory Qualifications:
- Over 7 years of professional experience in the information security field
- Proven operational experience in cybersecurity, such as cloud infrastructure security, vulnerability management or security monitoring & response
- At least 3 years of team management experience with service delivery and budget management
- Proven implementation experience of preventative & defensive controls on public cloud or private cloud environments
- Experience working in a distributed, cross-timezone team
- Deep understanding of the core concepts of web/mobile application and vulnerability remediation lifecycle
- Experience in vulnerability management, 0-day response & stakeholder management
- Deep understanding of network and web application protocols
- Strong teamwork capability in a diverse team environment
- Excellent consultation, problem-solving, communication, and interpersonal skills to build trust and consensus with stakeholders
- Strong ownership and sense of responsibility
Desired Qualifications:
- Experience with global, large-scale infrastructures and ecosystems
- Experience with zero-trust architecture and implementing security in a global, distributed network
- Experience in Web service development, implementation/operation at cloud-native system infrastructures
- Experience in a diverse workplace, and working well in a team environment
- Experience in vendor contract management, security strategy planning with multiple IT/security products
- Experience in implementation or support for compliance and security requirements such as PCI DSS or FISC
- Holder of any security-related certifications such as Security+, GIAC, CISSP, OSCP/OSCE, SSCP