掲載日 ・ 2025/10/02
楽天グループ株式会社
楽天グループ株式会社:1022709 Senior Penetration Tester – Offensive Security Section, Cyber Security Defense Department (CSDD)
非公開
東京都
会社名
楽天グループ株式会社
会社概要
未来を信じ、より良い明日を創っていく。
イノベーションを通じて、人々と社会をエンパワーメントする。私たちは、そんな想いを大切に世界の人々に喜びと楽しさを届けます。
楽天は、E コマース、FinTech、デジタルコンテンツ、通信など、70 を超えるサービスを展開し、世界10 億以上のユーザーに利用されています。
これら様々なサービスを、楽天会員を中心としたメンバーシップを軸に有機的に結び付け、他にはない独自の「楽天エコシステム」を形成しています。ダイバーシティ推進は、楽天にとって最優先の企業戦略のひとつです。従業員の出身は70カ国・地域以上。世界中からユニークで多様な文化的背景や視点を持つ優秀な人材が集まり、イノベーションの原動力になっています。社内カフェテリアにはベジタリアン、ハラル対応のメニューを用意。礼拝所(Prayer room)もあります。
また、仕事と育児の両立支援や、障がい者雇用・活躍促進も積極的に推進。社内のLGBT(※1)当事者やアライ(※2)に対して、情報共有やサポート体制の強化も進めています。誰もが自分らしく力を最大限発揮して働ける。それが楽天のダイバーシティです。
70を超えるサービスを提供し、世界30カ国にサービス展開拠点を持ち、従業員の出身国・地域数は100を超え、オープンポジション制度を活用して多様なキャリアを描くことができる点も魅力です。
フレックスタイム制度、事情に応じたリモートワークの活用が可能です。本社には託児所やフィットネスジム、三食無料で利用可能なカフェテリアが併設されるなど、社員を支える環境が整備されています。
ポジション
1022709 Senior Penetration Tester - Offensive Security Section, Cyber Security Defense Department (CSDD)
仕事内容
Job Description:
Department Overview
The Cyber Security Defense Department (CSDD) is responsible for the security and safety of the Internet services of Rakuten Group, Inc. CSDD covers all aspects of the Secure Development Life Cycle (SDLC) and operation security for all the services developed inside Rakuten Group.
Position:
Why We Hire
The Cyber Security Defense Department’s Red Team Operations Group is looking for a Senior Penetration Tester. The successful candidate will lead and perform various types of Offensive Security activities such as Penetration Testing and Red Team Engagements and will also be involved in developing and managing the Red Team’s resources such as tooling, infrastructure, etc. This role also entails close collaboration with key stakeholders to ensure that Rakuten Group’s security vulnerabilities are appropriately mitigated and its detection capabilities continuously improved.
Position Details
You will be part of a diverse and passionate team of Offensive Security Experts, always looking for a way to get in but also for the best way to mitigate their findings. As cybersecurity professionals, we believe continuous growth and training are necessary to maintain up-to-date skills, so you will have many opportunities to level up your skills. Finally, Rakuten Group’s unique ecosystem will give you the chance to perform Penetration Testing and Red Team Engagements on a wide variety of technologies, applications and infrastructures.
Key Responsibilities:
- Lead and Perform Penetration Testing activities on web applications, networks, mobile applications, and other systems.
- Lead and Perform Red Team exercises to simulate the latest sophisticated attack scenarios.
- Collaborate with the Blue Team and IT Administrators to improve Rakuten Group’s detection and defensive capabilities.
- Produce high-quality reports and deliverables catered to technical and non-technical audiences.
- Contribute to the Red Team’s knowledge and tooling base by investigating the latest Offensive Security tactics and techniques and developing tools and scripts.
- Actively contribute to the administration, management, and continuous improvement of the Red Team’s infrastructure.
- Provide mentorship and training to junior team members.
求める経験・スキル
Mandatory Qualifications:
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- Minimum of 3-5 years of experience in penetration testing and red teaming.
- Minimum of 3-5 years of experience in performing EDR evasion.
- Minimum of 3-5 years of experience in using, administering, and automating Offensive Security Infrastructure,
- Proficiency in scripting and programming languages (e.g., Python, PowerShell, Bash).
- Familiarity with various operating systems (Windows, Linux, macOS) and network protocols.
- Relevant certifications such as OSCP, OSCE, GPEN, GXPN, CRTO, GCFA, GCIH.
Desired Qualifications:
- Experience performing Offensive Security testing against cloud environments (AWS, GCP, Azure).
- Experience or interest in performing Offensive Security testing against Generative AI systems and Large Language Models (LLMs).
- Familiarity with regulatory requirements and standards (e.g., GDPR, HIPAA, PCI-DSS).
- Fluent Japanese.