Senior Security Engineer
Rakuten Symphony · India
Job Description
Job Title: Senior Cloud Security Engineer
Department: Security Engineering
Function: Security Engineering and Operations
Reports To: Manager
Location: Bangalore, India
Job Description
Rakuten Symphony is seeking a hands-on Senior Cloud Security Engineer to support security engineering and security operations for applications, cloud infrastructure, network platforms, and on-premises environments. The role will be responsible for implementing and operating security controls, configuring firewalls and WAFs, monitoring security events, investigating incidents, managing vulnerabilities, and improving the security posture of production environments. Experience with AWS and GCP security services is preferred.
Key Responsibilities
- Implement, operate, and continuously improve security controls for applications, cloud infrastructure, servers, networks, and platforms.
- Configure and manage security technologies including firewalls, WAFs, F5 security solutions, Cisco security solutions, network access controls, and traffic-filtering policies.
- Configure and maintain AWS WAF, GCP Cloud Armor, F5 Advanced WAF, and equivalent technologies.
- Configure and troubleshoot F5 BIG-IP security features, including virtual servers, access policies, SSL/TLS controls, traffic management, and WAF policies.
- Configure and manage relevant Cisco security technologies, including firewalls, network security controls, VPNs, access policies, and security monitoring.
- Develop and tune security rules to protect applications and APIs from SQL injection, cross-site scripting, path traversal, bot activity, denial-of-service attacks, and other malicious traffic.
- Monitor firewall, WAF, F5, Cisco, operating system, application, network, cloud, and security logs.
- Investigate security alerts, suspicious traffic, unauthorized access, abnormal application behavior, and potential indicators of compromise.
- Support security incident response, including analysis, containment, recovery, and post-incident improvement.
- Investigate compromised accounts, service accounts, cloud credentials, servers, containers, and application workloads.
- Implement and review identity and access management controls across cloud, network, Linux, and application environments.
- Perform security hardening and vulnerability remediation for Linux servers, virtual machines, containers, Kubernetes platforms, and cloud workloads.
- Support the secure operation of on-premises Kubernetes and managed cloud Kubernetes environments.
- Review Kubernetes configurations, workload permissions, ingress controls, secrets, container images, and exposed services.
- Perform security posture reviews and track remediation of identified weaknesses.
- Analyze findings from vulnerability scanners, security-monitoring tools, cloud security tools, penetration tests, and configuration reviews.
- Develop scripts and automation to support security monitoring, investigation, alert handling, rule deployment, and security validation.
- Support integration with SIEM, vulnerability-management, endpoint-security, and incident-response platforms.
- Participate in threat modelling, security architecture reviews, risk assessments, and security design reviews.
- Review application and infrastructure changes to ensure appropriate security controls are implemented before deployment.
- Work with application, DevOps, SRE, platform, network, infrastructure, and SOC teams to address security risks.
- Maintain security procedures, incident-response playbooks, technical standards, and operational documentation.
- Support security audits, compliance activities, evidence collection, and continuous improvement initiatives.
Required Skills and Experience
- 5–8 years of experience in security engineering, security operations, network security, infrastructure security, or cybersecurity.
- Strong hands-on experience in security monitoring, incident investigation, vulnerability management, system hardening, and security control implementation.
- Experience configuring and managing firewalls, WAFs, F5, Cisco security technologies, IAM, network controls, logging, and monitoring tools.
- Experience with AWS or GCP security services is preferred.
- Practical experience with AWS WAF, AWS IAM, security groups, CloudTrail, GuardDuty, or equivalent AWS services.
- Experience with GCP Cloud Armor, GCP IAM, VPC firewall rules, Cloud Audit Logs, or equivalent GCP services is preferred.
- Hands-on experience with F5 BIG-IP, F5 Advanced WAF, Cisco firewalls, Cisco VPN, or related security technologies.
- Good knowledge of Linux security, hardening, patching, access control, and troubleshooting.
- Experience with Kubernetes, Docker, containers, and container security.
- Good understanding of TLS, DNS, TCP/IP, routing, load balancers, reverse proxies, and network segmentation.
- Experience analyzing security logs and investigating suspicious events.
- Understanding of common attacks, including credential compromise, privilege escalation, malware, API abuse, SQL injection, cross-site scripting, SSRF, data exfiltration, and denial-of-service attacks.
- Experience with Python, Bash, PowerShell, or similar scripting languages.
- Experience with SIEM, vulnerability-management, endpoint-security, or security-monitoring platforms.
- Experience with Terraform or similar infrastructure deployment tools.
- Strong problem-solving, incident-handling, communication, and documentation skills.
Preferred Qualifications
- AWS Certified Security or equivalent certification.
- Google Professional Cloud Security Engineer certification.
- F5 or Cisco security certification.
- CISSP, CCSP, or equivalent security certification.
- Experience securing on-premises Kubernetes, Amazon EKS, or Google Kubernetes Engine.
- Experience with DevSecOps, CI/CD security, API security, and cloud-native security.
- Experience with penetration testing, threat hunting, or adversary simulation.
- Experience in telecom, distributed systems, microservices, or highly available production environments.
Role Summary
Responsible for security engineering and security operations across applications, infrastructure, Linux, Kubernetes, and cloud environments, including security monitoring, incident response, firewalls, WAF, IAM, vulnerability management, hardening, and security automation. Experience with AWS and GCP security services is preferred.
RAKUTEN SHUGI PRINCIPLES:
Our worldwide practices describe specific behaviours that make Rakuten unique and united across the world. We expect Rakuten employees to model these 5 Shugi Principles of Success.
- Always improve, always advance. Only be satisfied with complete success - Kaizen.
- Be passionately professional. Take an uncompromising approach to your work and be determined to be the best.
- Hypothesize - Practice - Validate - Shikumika. Use the Rakuten Cycle to success in unknown territory.
- Maximize Customer Satisfaction. The greatest satisfaction for workers in a service industry is to see their customers smile.
- Speed!! Speed!! Speed!! Always be conscious of time. Take charge, set clear goals, and engage your team.
Details
| Company | Rakuten Symphony |
| Location | India |
| Type | FULL TIME |
| Niche | general |
