Penetration Tester

Rakuten Symphony

Bengaluru

On-site

INR 4,000,000 - 7,000,000

Full time

14 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Rakuten Symphony seeks senior security experts to perform advanced penetration testing and offensive security assessments across web, mobile, APIs, cloud, AI/ML, and telecom environments.

Role focuses on identifying complex vulnerabilities, validating exploits, and supporting red team activities while strengthening engineering security posture.

Qualifications

  • 10+ years of hands-on penetration testing and application security experience.
  • Strong expertise in web, mobile, API, cloud, infrastructure, and AI security testing.
  • Experience with industry-standard offensive-security tools and frameworks.

Responsibilities

  • Conduct manual and automated penetration testing of web applications, mobile applications, APIs, cloud platforms, networks, and infrastructure.
  • Perform security assessments of AI/ML applications, LLM systems, AI agents, and MLOps pipelines.
  • Identify vulnerabilities including prompt injection and data leakage.
  • Assess telecom systems and BSS/OSS applications, eSIM, and subscriber platforms.
  • Support red team exercises, adversary emulation, attack-path analysis, and exploit validation.
  • Conduct source code reviews and architecture-level security assessments.
  • Develop proof-of-concept exploits and provide remediation guidance.
  • Validate remediation through retesting and verification.

Skills

Penetration testing
Application security
Cloud security
Web security
API security
AI/ML security testing
Red team
Kubernetes
Docker
Burp Suite
Kali Linux
Metasploit
Nmap
Nessus
BloodHound

Education

Bachelor's degree in Computer Science or related field

Tools

Burp Suite
Kali Linux
Metasploit
BloodHound
Nmap
Nessus
AWS
Azure
GCP
Kubernetes
Docker

Job description

Rakuten Symphony is reimagining telecom, changing supply chain norms and disrupting outmoded thinking that threatens the industry’s pursuit of rapid innovation and growth. Based on proven modern infrastructure practices, its open interface platforms make it possible to launch and operate advanced mobile services in a fraction of the time and cost of conventional approaches, with no compromise to network quality or security. Rakuten Symphony has operations in Japan, the United States, Singapore, India, South Korea, Europe, and the Middle East Africa region. For more information, visit: https://symphony.rakuten.com

Building on the technology Rakuten used to launch Japan’s newest mobile network, we are taking our mobile offering global.

To support our ambitions to provide an innovative cloud-native telco platform for our customers, Rakuten Symphony is looking to recruit and develop top talent from around the globe. We are looking for individuals to join our team across all functional areas of our business – from sales to engineering, support functions to product development.

Let’s build the future of mobile telecommunications together!

About Rakuten Rakuten Group, Inc. (TSE: 4755) is a global leader in internet services that empower individuals, communities, businesses and society. Founded in Tokyo in 1997 as an online marketplace, Rakuten has expanded to offer services in e-commerce, fintech, digital content and communications to approximately 1.5 billion members around the world. The Rakuten Group has over 27,000 employees, and operations in 30 countries and regions. For more information visit https://global.rakuten.com/corp/.

You will work on cutting-edge offensive security challenges spanning 4G/5G telecom platforms, cloud-native infrastructure, applications, APIs, AI/ML systems, and emerging technologies.

We offer an environment where innovation is encouraged, continuous learning is supported, and security experts are empowered to make a direct business impact.

You will have the opportunity to work alongside industry-leading engineers, build next-generation security capabilities, leverage AI to transform security testing, and contribute to protecting critical telecommunications infrastructure at scale.

If you are passionate about offensive security, enjoy solving complex technical challenges, and want to shape the future of cybersecurity in the AI era, we would love to hear from you.

Position Summary

Perform advanced penetration testing and offensive security assessments across Rakuten Mobile's web, mobile, API, cloud, AI/ML, and telecom environments. The role focuses on identifying complex security vulnerabilities, validating exploitability, supporting red team activities, and helping engineering teams strengthen the organization's security posture.

Key Responsibilities
  • Conduct manual and automated penetration testing of web applications, mobile applications, APIs, cloud platforms, networks, and infrastructure.
  • Perform security assessments of AI/ML applications, Large Language Model (LLM) systems, AI agents, Retrieval-Augmented Generation (RAG) implementations, and MLOps pipelines.
  • Identify vulnerabilities including prompt injection, insecure model integrations, sensitive data leakage, model manipulation, and AI supply chain risks.
  • Assess telecom systems and platforms, including BSS/OSS applications, eSIM platforms, subscriber management systems, mobile network services, and internet-facing telecom applications.
  • Support red team exercises, adversary emulation engagements, attack-path analysis, and exploit validation activities.
  • Conduct source code reviews, secure design reviews, and architecture-level security assessments as required.
  • Develop proof-of-concept exploits and provide comprehensive technical reports with actionable remediation guidance.
  • Validate remediation efforts through retesting and verification activities.
  • Research emerging attack techniques, exploit methodologies, AI-assisted security testing approaches, and offensive security tools.
  • Contribute to security automation initiatives and continuous security validation programs.
Required Qualifications
  • 10+ years of hands-on penetration testing and application security experience.
  • Strong expertise in web, mobile, API, cloud, infrastructure, and AI security testing.
  • Experience with Burp Suite, Kali Linux, Metasploit, BloodHound, Nmap, Nessus, and modern offensive security frameworks.
  • Familiarity with cloud platforms such as AWS, Azure, or GCP and containerized environments such as Kubernetes and Docker.
Preferred Qualifications
  • Experience with telecom technologies, mobile core networks, BSS/OSS systems, and cloud-native telecom applications is preferred.
  • Preferred certifications: OSCP, CRTP, CRTO, OSEP, OSWE, GPEN, GXPN or equivalent certifications.
  • Nice-to-Have Expertise
  • AI/LLM security testing and adversarial machine learning.
  • Red team operations and advanced exploit development.
  • Cloud and Kubernetes security assessments.
  • 5G / telecom security testing and BSS/OSS security validation.
  • Bug bounty, vulnerability research, and AI-assisted penetration testing.
Core Competencies
  • Advanced Offensive Security – Conducts complex manual penetration tests, exploit validation, and attack-path analysis.
  • Application and API Security – Assesses web, mobile, API, source-code, and application architecture risks.
  • Cloud and Infrastructure Security – Tests AWS/Azure/GCP, Kubernetes, containers, networks, identity systems, and configurations.
  • AI/ML Security Testing – Evaluates LLMs, AI agents, RAG solutions, MLOps pipelines, and AI supply-chain risks.
  • Telecom Security Expertise – Understands 4G/5G, BSS/OSS, eSIM, subscriber platforms, and cloud-native telecom environments.
  • Red Teaming and Adversary Emulation – Applies realistic attacker techniques and supports advanced offensive-security exercises.
  • Analytical Problem-Solving – Investigates complex systems, prioritizes exploitable risks, and develops practical proofs of concept.
  • Risk Communication and Reporting – Clearly explains technical findings, business impact, and actionable remediation to technical and nontechnical stakeholders.
  • Collaboration and Technical Leadership – Works effectively with engineering teams, mentors others, and drives remediation through closure.
  • Continuous Learning and Innovation – Tracks emerging attack techniques, vulnerabilities, tools, and AI-assisted testing methods.
  • Professional Ethics and Accountability – Handles sensitive information responsibly and performs testing within authorized scope.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Engineer - Penetration Tester
Senior Engineer - Penetration Tester

Rakuten Symphony • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Staff Engineer, Offensive Security
Staff Engineer, Offensive Security

Rakuten Kobo Inc. • Bengaluru

On-site
INR 4,000,000 - 8,000,000
Senior Engineer - Penetration Tester
Senior Engineer - Penetration Tester

Rakuten Kobo Inc. • Bengaluru

On-site
INR 4,500,000 - 7,500,000
Staff Engineer Offensive Security
Staff Engineer Offensive Security

Rakuten Symphony • Bengaluru

On-site
INR 4,000,000 - 8,000,000
Staff Engineer, Offensive Security
Staff Engineer, Offensive Security

Rakuten Asia Pte Ltd • Bengaluru, Indore District

On-site
INR 3,800,000 - 7,000,000
Senior Engineer - Penetration Tester
Senior Engineer - Penetration Tester

Rakuten Asia Pte Ltd • Bengaluru, Indore District

On-site
INR 3,500,000 - 6,500,000
Technical Lead Quality Assurance
Technical Lead Quality Assurance

Rakuten Symphony • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Product Manager, Network Testing & AI Automation
Product Manager, Network Testing & AI Automation

Rakuten Symphony • Indore District

On-site
INR 4,000,000 - 7,000,000
Technical Consultant
Technical Consultant

Rakuten Symphony • Bengaluru Urban

On-site
INR 3,000,000 - 5,400,000
Automation Engineer
Automation Engineer

Rakuten Symphony • Bengaluru Urban

On-site
INR 1,000,000 - 1,500,000