Appealing Points

  • Architect and build next-generation detection pipelines to defend critical infrastructure against autonomous, AI-driven attacks and sophisticated APTs, and lead the transition to a Detection-as-Code (DaC) model.
  • Work at the cutting edge of security with eBPF-based runtime security, behavioral analytics and LLM-integrated pipelines, including oversight of the security of the organization's own AI/LLM models.
  • Join a team of "defenders with an attacker's brain" in a proactive, intelligence-led defense culture, collaborating with security researchers, threat hunters and AI/ML specialists.

Annual Salary: ¥10 Million and above

Job Description

Cyber Defense Operations is the core department responsible for the safety and security of the group's internet services. The Detection Engineering Section is tasked with architecting and building next-generation detection pipelines to defend critical infrastructure against autonomous, AI-driven attacks and sophisticated APTs. The section leads the transition to a Detection-as-Code (DaC) model, using eBPF-based runtime security, behavioral analytics and LLM-integrated pipelines to deliver high-fidelity, actionable alerts. The team describes itself as "defenders with an attacker's brain," committed to proactive, intelligence-led defense.

Job Responsibilities

  • Detection-as-Code (DaC) Transformation: Build and manage an end-to-end detection pipeline featuring peer reviews, version control (Git) and a reusable repository of detection rules.
  • AI/LLM-Driven Detection: Architect and develop AI/LLM-based models to identify autonomous AI attacks. Use AI to automate log onboarding, normalize data and filter "garbage logs" to drastically reduce SOC noise.
  • Advanced Runtime Security: Lead the implementation of kernel-level monitoring using eBPF-based tools to provide deep visibility into containerized (K8s) and Linux-based workloads.
  • Offensive Security & Threat Hunting: Perform continuous attack simulations (Red Teaming) to validate detection coverage. Lead proactive threat hunting initiatives informed by CTI and the MITRE ATT&CK/FIGHT frameworks.
  • Deception & Defense-in-Depth: Deploy and manage deception technologies to create high-interaction traps. Ensure detection logic aligns with the defense-in-depth architecture.
  • Cross-Functional Orchestration: Collaborate with DFIR, CTI and SOC teams to ensure CTI is actively integrated into detection logic via AI-driven automation.
  • AI Guardrails & Security: Oversee the security of the organization's own AI/LLM models, implementing guardrails to prevent model poisoning, prompt injection and adversarial manipulation.
  • SOAR Integration: Partner with the SOC team to ensure detection logic feeds seamlessly into SOAR playbooks for machine-speed response.

Required Qualifications

  • 10+ years in Cyber Security, with at least 5+ years in Detection Engineering or Security Research.
  • Deep expertise in building detection pipelines, tuning logic for high-fidelity alerts and managing the security rule lifecycle.
  • Practical experience building/tuning models for anomaly detection and log analysis.
  • Expert-level coding skills (Python, Go or Rust) and mastery of Linux/Windows/Mac internals.
  • Strong hands-on experience securing Kubernetes clusters, container runtimes and microservices architectures.
  • Understanding of Telco networks/protocols (e.g., 5G core, signaling) and Network Security (packet analysis, perimeter/internal controls).
  • Experience in penetration testing, exploit development or red teaming.
  • Bachelor's or Master's degree in Computer Science, Cyber Security or equivalent.
  • Relevant certifications (e.g., OSCP, GREM, GCFA, CKS, BTL2 or AI-Security credentials).

Preferred Qualifications

  • Experience with Infrastructure as Code (Terraform, Ansible, Crossplane).
  • Deep experience with eBPF tools (e.g., Tetragon, Falco, Cilium, Spyderbat).
  • Active contributor to open-source detection projects (e.g., Sigma, YARA or custom AI-detection models).
  • Experience in high-scale environments (Telco, Cloud-Native or FinTech).

Language Requirements: Advanced Business level English

About Company:

The largest eCommerce company in Japan, and the third-largest eCommerce marketplace company worldwide. The organization provides a variety of consumer and business-focused services including e-commerce, e-reading, travel, banking, securities, credit card, e-money, portal and media, online marketing, and professional sports. The company is expanding globally and currently has operations throughout Asia, Western Europe, and the Americas.

[Measures against passive smoking]

No smoking indoors allowed

Designated smoking area

似たような求人

Fidel Consulting KKからの続きを読む
Fidel Consulting KK 18 days ago
Fidel Consulting KK 4 hours ago
Fidel Consulting KK 4 hours ago

Senior Detection Engineer

企業サイトでの申請
Back to search page