Now hiring

Senior Penetration Tester - Security Assurance Section (RMI Telecommunication Security Supervisory Dep) @ Rakuten

Tokyo, JPOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Job Description: About Organization At Rakuten Mobile Security Assurance, you will help secure one of the world's most advanced cloud-native telecom networks, protecting millions of customers across digital, mobile, cloud, and AI-driven services. We work on cutting-edge offensive security challenges spanning 4G/5G telecom platforms, cloud-native infrastructure, APIs, AI/ML systems, and emerging technologies. We offer an environment where innovation is encouraged, continuous learning is supported, and security experts are empowered to make a direct business impact. You will work alongside industry-leading engineers, build next-generation security capabilities, leverage AI to transform security testing, and contribute to protecting critical telecommunications infrastructure at scale.

Job Duties

• Comprehensive Penetration Testing: Conduct manual and automated testing of web/mobile applications, APIs, cloud platforms, and network infrastructure.

• AI/ML Security Assessments: Evaluate LLM-based systems, AI agents, RAG implementations, and MLOps pipelines. Identify vulnerabilities such as prompt injection, insecure model integrations, data leakage, and AI supply chain risks.

• Telecom Security Testing: Execute security assessments on telecom-specific systems, including BSS/OSS applications, eSIM platforms, subscriber management, and mobile network services.

• Red Teaming & Adversary Emulation: Support red team exercises, conduct attack path analysis, and perform exploit validation using realistic attacker techniques.

• Design & Code Review: Perform source code reviews, secure design reviews, and architecture-level security assessments.

• Reporting & Remediation: Develop proof-of-concepts, create detailed technical reports, and provide actionable remediation recommendations. Validate fixes through re-testing.

• Research & Innovation: Research emerging attack techniques, exploit methodologies, and AI-assisted offensive security methods.

Minimum Qualifications

• Experience: 10+ years of hands-on penetration testing and application security experience.

• Technical Expertise: Deep expertise in web, mobile, API, cloud, infrastructure, and AI security testing.

• Tooling: Proficiency with Burp Suite, Kali Linux, Metasploit, BloodHound, Nmap, Nessus, and modern offensive security frameworks.

• Scripting/Coding: Strong knowledge of Python, JavaScript, Bash, or PowerShell for testing and automation.

• Cloud/Infrastructure: Proficiency with cloud platforms (AWS, Azure, or GCP) and containerized environments (Kubernetes, Docker).

Preferred Qualifications

• Telecom Expertise: Experience with telecom technologies, mobile core networks, BSS/OSS systems, and cloud-native telecom applications.

• Certifications: OSCP, CRTP, CRTO, OSEP, OSWE, GPEN, GXPN, or equivalent.

• Specialized Skills:

• AI/LLM security testing and adversarial machine learning.

• Red team operations and advanced exploit development.

• Bug bounty, vulnerability research, and AI-assisted penetration testing.

Languages: English (Overall - 3 - Advanced)、 Japanese (Overall - 2 - Intermediate)

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores