Senior Cyber Threat Hunter
Senior Cyber Threat Hunter
Job type:
Permanent
Specialization:
IT Security
Language Level:
English Level - Advanced (TOEIC 860), Japanese Level - None
Location:
Setagaya-ku
Salary:
¥10,000,000 - ¥15,000,000 Yearly
Job Reference:
504414
A Global IT Service firm is seeking a highly experienced Senior Cyber Threat Hunter to join its growing cyber defense organization within the Security Engineering & Operations Department.
This role is critical in proactively identifying, analyzing, and mitigating advanced cyber threats across the innovative mobile network infrastructure, cloud environments, and digital services.
The successful candidate will play a key role in strengthening the company's cybersecurity posture by conducting hypothesis-driven threat hunting activities, researching adversary behaviors, operationalizing threat intelligence, and driving continuous improvements in detection and response capabilities.
Responsibilities:
- Proactive Threat Hunting: Develop and execute hypothesis-driven campaigns, meticulously analyzing large volumes of log, endpoint, and network data to uncover anomalous or malicious activity, and thoroughly documenting findings
- Adversary Research: Research and track adversary Tactics, Techniques, and Procedures (TTPs), leveraging frameworks like MITRE ATT&CK to build and test threat hypotheses beyond simple Indicator of Compromise (IOC) searches
- Actionable Security Improvements: Translate hunting outcomes into actionable security enhancements, creating detection logic, data requirements, false positive guidance, and validation steps for new and refined detections
- Collaboration & Improvement: Collaborate closely with the Detection Engineering team to enhance detection rules and playbooks, and contribute to the continuous improvement of hunting methodologies
- Incident Support: Partner with Cyber Threat Intelligence, Incident Response, and SOC teams to operationalize threat insights, provide support during incidents, and assist in investigation and containment efforts
- Technical Analysis: Perform in-depth technical analysis of attacker tradecraft, including lateral movement, persistence, and exfiltration techniques, to understand attack vectors and establish intrusion chains
- Tool Utilization: Utilize advanced security tools such as SIEM, UEBA, and forensic analysis platforms to conduct hunts and confirm threats
- Automation: Automate analysis and detection processes using scripting languages (e.g., Python, PowerShell) to improve efficiency and scale
- Continuous Learning: Stay current with the evolving threat landscape and emerging adversary techniques to maintain effective threat hunting capabilities
Required skills:
- Minimum of 10-12 years of experience in cybersecurity, with strong expertise in Cyber Threat Hunting
- Demonstrable experience in Incident Response and Forensics
- Exposure to Security Operations, Threat Intelligence, and Malware Analysis
- In-depth knowledge of the MITRE ATT&CK framework, including the ability to map adversary behaviors to understand attack vectors and predict potential threats
- Strong understanding of enterprise network architecture, including advanced networking concepts (e.g., TCP/IP, routing, firewalls, VPNs), networking protocols, deep packet inspection, and network traffic analysis
- Expertise in telecommunication protocols and infrastructure, particularly those relevant to mobile environments (e.g., 4G/5G, SS7, Diameter, GTP), and the ability to identify threats within these specialized networks
- Deep understanding of cloud-native environments, including Kubernetes and container orchestration, with proven experience in hunting for threats and anomalies within these complex infrastructures
- Demonstrated experience with major cloud platforms (e.g., AWS, Azure, GCP) and their native security services, with the ability to perform threat hunting across diverse cloud environments
- Experience and strong interest in leveraging advanced AI capabilities, including Machine Learning (ML) models and Large Language Models (LLMs), to enhance threat hunting, automate analysis, and improve operational efficiency
Why you should apply:
- Join one of the world's most technologically advanced mobile network operators and contribute to securing a cloud-native, large-scale telecom environment
- Work at the forefront of cyber defense, proactively hunting sophisticated threats across enterprise, cloud, and mobile network infrastructures
- Collaborate with highly skilled professionals across Threat Intelligence, Detection Engineering, Incident Response, and Security Operations teams
- Leverage cutting-edge technologies, including AI, Machine Learning, cloud-native platforms, and 4G/5G telecommunications infrastructure
- Play a direct role in shaping and improving Rakuten Mobile's detection, response, and cyber resilience capabilities
Company Overview:
This is a global company with a strong presence in multiple business sectors. It has achieved sustained growth both domestically and internationally, including in the U.S. and Europe. The company prides itself on its diverse and international environment, providing ample career opportunities and a commitment to equal opportunity. With a wide range of business activities, the company also works with various technologies. You can choose your preferred working environment, whether Windows or Mac! Meals at the employee cafeteria are free, and the chef regularly comes up with new menus, ensuring you never get bored of the meals!
Work Hours: 9:00 AM – 5:30 PM (Flextime or staggered working hours possible)
Work Style: Hybrid (Typically 4 days in the office, 1 day working from home)
Holidays: Saturdays, Sundays, public holidays, New Year holidays, paid leave, bereavement leave, and other special leave
Benefits: Full social insurance (employee pension insurance, health insurance, worker’s accident compensation insurance, unemployment insurance), DC pension plan, transportation allowance, childcare and caregiving support, cafeteria, retirement benefit system, welfare services (Relo Club), health counseling services, relocation support (visa support, moving), employee discounts (moving, language classes, etc.), and more
Interview Process: 3~4 times



