Senior Manager, Public Cloud Security - Cyber Security Defense Department (CSDD)
Rakuten · JP
8 days agoImpress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Senior Manager, Public Cloud Security - Cyber Security Defense Department (CSDD) role.
Rezi rewrites your resume against Rakuten's job description. Free.

Tailor your resume to this Senior Manager, Public Cloud Security - Cyber Security Defense Department (CSDD) role.
Rezi rewrites your resume against Rakuten's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Senior Manager, Public Cloud Security - Cyber Security Defense Department (CSDD) posting at Rakuten — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Senior Manager, Public Cloud Security - Cyber Security Defense Department (CSDD) posting at Rakuten — free, in seconds.
About the Role
This role is responsible for defining the strategy, operating model, and roadmap for Public Cloud Security, working closely with the Cloud Center of Excellence (Cloud CoE), development teams, and other technology stakeholders. The mission is to provide centralized visibility, governance, expertise, and automation for cloud security while enabling development teams to maintain ownership and accountability for remediation within their respective services.
Responsibilities
- Define and execute Rakuten's Public Cloud Security strategy, vision, and roadmap.
- Establish a scalable cloud security operating model that supports business growth and cloud adoption across multiple organizations.
- Build, lead, and scale a high-performing Public Cloud Security team while fostering a culture of automation, engineering ownership, and continuous improvement.
- Drive collaboration and alignment among the Cloud Center of Excellence (Cloud CoE), development organizations, and business stakeholders.
- Define long-term security investment priorities and technology roadmaps for cloud security capabilities.
- Lead the adoption and operation of market-leading and/or internally developed cloud security solutions.
- Build security capabilities that provide continuous visibility into cloud assets, security risks, compliance status, and remediation activities.
- Drive security automation initiatives to improve detection, response, governance, and reporting.
- Establish security guardrails and self-service security capabilities that can be consumed by development teams.
- Reduce manual security operations by integrating security controls into cloud platforms, engineering workflows, and software delivery processes.
- Promote security-by-default and security-by-design principles across public cloud environments.
- Define and maintain public cloud security policies, standards, controls, and governance frameworks.
- Establish mechanisms to continuously monitor cloud security posture and risk exposure across the organization.
- Provide executive visibility into cloud security risks, trends, compliance posture, and program effectiveness.
- Partner with compliance, privacy, risk management, and security operations teams to address regulatory requirements and emerging threats.
- Develop metrics and KPIs to measure cloud security maturity, remediation effectiveness, and operational performance.
- Partner with the Cloud Center of Excellence (Cloud CoE) and development teams to integrate security capabilities into cloud platforms and engineering workflows.
- Establish clear accountability models where development teams own remediation and risk reduction activities within their services.
- Ensure security findings are identified, prioritized, and routed to the appropriate service owners through automated processes whenever feasible.
- Enable development teams to manage security risks independently by providing guidance, training, tooling, and consulting support.
- Act as a trusted security advisor for cloud-related initiatives across multiple business units.
- Drive a culture in which security is embedded into engineering processes without reducing development velocity.
Requirements
- More than 10 years of experience in information security, cloud security, infrastructure security, or related disciplines.
- More than 5 years of leadership experience managing technical teams and large-scale security initiatives.
- Strong expertise in public cloud technologies, cloud security governance, and risk management.
- Experience implementing or operating large-scale security platforms, cloud security programs, or enterprise security services.
- Experience driving security automation and developing scalable security operating models.
- Strong understanding of identity and access management, security monitoring, data protection, vulnerability management, and cloud-native security concepts.
- Experience partnering effectively with development organizations and influencing stakeholders across multiple business units.
- Strong communication, stakeholder management, and executive presentation skills.
- Experience operating in large-scale and global technology organizations.
Skills
- Public Cloud Security
- Cloud security governance
- Risk management
- Security automation
- Identity and access management
- Security monitoring
- Data protection
- Vulnerability management
- Cloud-native security concepts
- Cloud Security Posture Management (CSPM)
- Cloud-Native Application Protection Platforms (CNAPP)
- Cloud Infrastructure Entitlement Management (CIEM)
- Security into modern software development and cloud engineering practices
- ISO 27001
- PCI DSS
- NIST
- CIS Benchmarks
Location
- Global
Work Type
- Full-time
Experience Level
- Senior Manager
- More than 10 years of experience in information security, cloud security, infrastructure security, or related disciplines
- More than 5 years of leadership experience managing technical teams and large-scale security initiatives
Education Level
- CISSP
- CCSP
About the Company
- The Technology Management Division (TMD) provides corporate IT, cyber security, and privacy governance to Rakuten Group companies and essential business management for technology organizations, thereby enabling innovation and strengthening its technology foundation.
- Within TMD, the Information Security Supervisory Department (ISSD) combines proactive cyber defense with strategic information security, privacy, and data governance to protect the company’s global assets and data.
- The Cyber Security Defense Department (CSDD) is responsible for safeguarding all Rakuten companies and users from cyber threats, ensuring the security and integrity of Rakuten Group's global internet services.
- We oversee all aspects of both Secure Development and Security Operations for services developed within the group, with dedicated security teams and operation centers strategically located in key regions worldwide.