About this role
Job Description: Job Title: Staff Engineer, SOC Platform & Tools Group Department: Cyber Defense Operations Section Location: Bangalore, India
About the Team/Department:
Position Summary: We are seeking a hands-on Senior SOC Platform Engineer to build, operate, and scale the platforms powering our detection and response capabilities. This is an engineering-focused role—not an analyst or shift-monitoring role. You will own the end-to-end telemetry lifecycle, from log ingestion and pipeline routing to SIEM/SOAR infrastructure management. You will bridge the gap between network operations, security analysts, and platform engineering to ensure high-fidelity data availability at scale.
Key Responsibilities:
• SIEM & SOAR Engineering: Architect and manage clustered, multi-site deployments of Splunk/Elastic and SOAR platforms. Own the lifecycle, performance tuning, and automation playbook development to drive down MTTR.
• Telemetry Pipeline (Cribl): Operate Cribl Stream/Edge to parse, filter, mask, and enrich data streams. Implement intelligent routing to optimize ingest costs and enable data replay for investigations. • Log Collection & Onboarding: Architect high-volume syslog tiers (rsyslog/syslog-ng). Own the end-to-end onboarding of diverse telecom, network, cloud, and enterprise sources, ensuring alignment with CIM/ECS and MITRE ATT&CK. • Platform & Infrastructure Ops: Manage the full stack across on-premises and GCP environments. Use IaC (Terraform) and configuration management (Ansible) to automate platform health, capacity planning, and disaster recovery. • Systems Engineering: Administer enterprise Linux (RHEL/Ubuntu) at scale. Develop custom operational tooling and health-check scripts using Python and Bash. Install, configure, and maintain Linux servers and operating systems across on-premises and cloud environments. Monitor system performance, disk space, memory usage, and network connectivity; troubleshoot and resolve issues. Perform regular backups, disaster recovery planning, and ensure business continuity. • Kubernetes: Deploy and manage containerized applications using Docker and Kubernetes, ensuring high availability and fault tolerance. Implement CI/CD pipelines with Kubernetes integration for automated testing, building, and deployment workflows. Configure service discovery, load balancing, ingress controllers, and persistent storage solutions.
Required Qualifications
• Experience: 10+ years in security/SOC engineering, log management, or infrastructure engineering. • SIEM/SOAR Expertise: Hands-on production experience administering Splunk/Elastic/SOAR (clustering, upgrades) and SOAR platforms (playbook development/connectors). • Pipeline Proficiency: Expert-level experience with log pipeline tooling (Cribl Stream/Edge preferred; Logstash/Vector/Kafka considered). • Infrastructure Skills: Strong Linux administration, scripting (Python/Bash), and syslog fundamentals (TLS, load balancing, high-volume tuning). • Data Onboarding: Proven ability to write complex regex-based parsers, field extractions, and normalization logic. • Cloud & Networking: Working knowledge of GCP services (Logging, IAM, GKE, Networking) and solid grasp of networking fundamentals (TCP/UDP, DNS, routing, packet capture). • Communication: Excellent written communication and disciplined documentation habits.
Preferred Qualifications:
• Domain Expertise: Experience in a telecom or service provider environment (Mobile Core, 5G, IMS/VoLTE, SS7/Diameter, OSS/BSS). • DevOps/Automation: Experience with Kubernetes/Helm, Terraform, and Ansible in hybrid environments. • Detection Engineering: Exposure to SPL, ES|QL, KQL, Sigma rules, and data lake/object storage tiering architectures. • Certifications: Splunk Architect, Elastic Certified Engineer, Cribl Certified Admin, RHCE/RHCSA, Google Professional Cloud Security Engineer, AWS Professional certificate.
RAKUTEN SHUGI PRINCIPLES: Our worldwide practices describe specific behaviours that make Rakuten unique and united across the world. We expect Rakuten employees to model these 5 Shugi Principles of Success.
• Always improve, always advance. Only be satisfied with complete success - Kaizen.
• Be passionately professional. Take an uncompromising approach to your work and be determined to be the best.
• Hypothesize - Practice - Validate - Shikumika. Use the Rakuten Cycle to success in unknown territory.
• Maximize Customer Satisfaction. The greatest satisfaction for workers in a service industry is to see their customers smile.
• Speed!! Speed!! Speed!! Always be conscious of time. Take charge, set clear goals, and engage your team.
• undefined
• undefined