Job Description
Job Description
Department Overview
In Rakuten Group, the security and safety of the Internet services are guaranteed by the Cyber Security Defence Department (CSDD). CSDD covers all aspects of the System Development Life Cycle (SDLC) and operation security for all the services developed inside Rakuten Group.
Position
Why We Hire
Team expansion due to the increased demand for the work and the scope expansion.
Position Details
As a member of the CSDD Security Audit Group, you will execute offensive security activities and vulnerability assessment tests against a wide variety of systems and will be challenged to various projects in different aspects of security while working with other peer engineers. Expected tasks ranging from but are not limited to finding security vulnerabilities, writing scripts to automate security tasks, enhancing the network security of Rakuten infrastructure, and providing remediation suggestions.
Responsibilities
- Perform regular and request-based vulnerability assessment projects
- Provide reports and make recommendations to findings in a responsive fashion
- Propose remediation and aid development teams to improve their security status
Mandatory Qualifications
- Bachelors degree or above in Computer Science, Information Security, or a related field
- Minimum 2 years of experience in IT/Information Security related fields
- 2 years of experience in Web/Mobile/Network Penetration Testing and/or Vulnerability Assessment
- Understanding/working experience of DevSecOps
- Understanding of the core concepts of web/mobile application and security issues
- experience with web application vulnerability scanners (Burp Suite, AppScan, Acunetix, Web Inspect, etc)
- Deep knowledge of common software vulnerabilities, such as OWASP Top 10 and CWE/SANS Top 25
- Deep knowledge of HTTP protocol and the ability to construct/manipulate HTTP request
- Proficient in one or more scripting languages, ex: Python, Ruby
- Ability to suggest/recommend remediation to fix the vulnerability
- Proven knowledge of network and web application protocols
- Strong teamwork capability in a diverse team environment
- Ability to work in a highly diverse environment
Desired Qualifications
- Experience in Web/Mobile application development
- Experience in using major web frameworks
- Experience with at least one major commercial cloud environment
- Experience in a diverse workplace, and working well in a team environment
- Holder of any security-related certifications, ex: CEH, OSCP
- Strong verbal and written communications skill
- Strong ownership and sense of responsibility
Languages
English (Overall - 4 - Fluent)
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
