Staff Engineer, SOC Platform & Tools Group

Rakuten Asia Pte Ltd

Bengaluru

On-site

INR 4,000,000 - 7,000,000

Full time

11 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Rakuten Asia Pte Ltd in Bengaluru is seeking a hands-on Staff Engineer for the SOC Platform & Tools Group. You will own the telemetry lifecycle, from log ingestion to SIEM/SOAR infrastructure, bridging security, networking, and platform engineering to ensure scalable, high-fidelity data.

The role emphasizes engineering ownership over operations, with responsibilities spanning Splunk/Elastic/SOAR deployments, Cribl data routing, on-prem and GCP platform management, and infrastructure automation

Qualifications

  • 10+ years in security/SOC engineering, log management, or infrastructure engineering.
  • Hands-on production experience administering Splunk/Elastic/SOAR and SOAR platforms.
  • Expert-level experience with log pipeline tooling (Cribl Stream/Edge preferred; Logstash/Vector/Kafka considered).
  • Strong Linux administration, scripting (Python/Bash), and syslog fundamentals (TLS, load balancing, high-volume tuning).
  • Proven ability to write complex regex-based parsers, field extractions, and normalization logic.
  • Working knowledge of GCP services (Logging, IAM, GKE, Networking) and solid grasp of networking fundamentals.

Responsibilities

  • SIEM & SOAR Engineering: Architect and manage clustered, multi-site deployments of Splunk/Elastic and SOAR platforms. Own the lifecycle, performance tuning, and automation playbook development to drive down MTTR.
  • Telemetry Pipeline (Cribl): Operate Cribl Stream/Edge to parse, filter, mask, and enrich data streams. Implement intelligent routing to optimize ingest costs and enable data replay for investigations.
  • Log Collection & Onboarding: Architect high-volume syslog tiers (rsyslog/syslog-ng). Own the end-to-end onboarding of diverse telecom, network, cloud, and enterprise sources, ensuring alignment with CIM/ECS and MITRE ATT&CK.
  • Platform & Infrastructure Ops: Manage the full stack across on-premises and GCP environments. Use IaC (Terraform) and configuration management (Ansible) to automate platform health, capacity planning, and disaster recovery.
  • Systems Engineering: Administer enterprise Linux (RHEL/Ubuntu) at scale. Develop custom operational tooling and health-check scripts using Python and Bash. Install, configure, and maintain Linux servers and operating systems across on-premises and cloud environments. Monitor system performance, disk space, memory usage, and network connectivity; troubleshoot and resolve issues. Perform regular backups, disaster recovery planning, and ensure business continuity.
  • Kubernetes: Deploy and manage containerized applications using Docker and Kubernetes, ensuring high availability and fault tolerance. Implement CI/CD pipelines with Kubernetes integration for automated testing, building, and deployment workflows. Configure service discovery, load balancing, ingress controllers, and persistent storage solutions.

Skills

Security/SOC engineering
Log management
Linux administration
Python/Bash scripting
SIEM/SOAR (Splunk/Elastic)
Cribl Stream/Edge
Cloud: GCP
Networking fundamentals

Tools

Splunk
Elastic
SOAR platforms
Cribl
Kubernetes
Terraform
Ansible

Job description

Job Description: Job Title: Staff Engineer, SOC Platform & Tools Group Department: Cyber Defense Operations Section Location: Bangalore, India About the Team/Department: Position Summary: We are seeking a hands-on Senior SOC Platform Engineer to build, operate, and scale the platforms powering our detection and response capabilities. This is an engineering-focused role—not an analyst or shift-monitoring role. You will own the end-to-end telemetry lifecycle, from log ingestion and pipeline routing to SIEM/SOAR infrastructure management. You will bridge the gap between network operations, security analysts, and platform engineering to ensure high-fidelity data availability at scale.

Key Responsibilities
  • SIEM & SOAR Engineering: Architect and manage clustered, multi-site deployments of Splunk/Elastic and SOAR platforms. Own the lifecycle, performance tuning, and automation playbook development to drive down MTTR.
  • Telemetry Pipeline (Cribl): Operate Cribl Stream/Edge to parse, filter, mask, and enrich data streams. Implement intelligent routing to optimize ingest costs and enable data replay for investigations.
  • Log Collection & Onboarding: Architect high-volume syslog tiers (rsyslog/syslog-ng). Own the end-to-end onboarding of diverse telecom, network, cloud, and enterprise sources, ensuring alignment with CIM/ECS and MITRE ATT&CK.
  • Platform & Infrastructure Ops: Manage the full stack across on-premises and GCP environments. Use IaC (Terraform) and configuration management (Ansible) to automate platform health, capacity planning, and disaster recovery.
  • Systems Engineering: Administer enterprise Linux (RHEL/Ubuntu) at scale. Develop custom operational tooling and health-check scripts using Python and Bash. Install, configure, and maintain Linux servers and operating systems across on-premises and cloud environments. Monitor system performance, disk space, memory usage, and network connectivity; troubleshoot and resolve issues. Perform regular backups, disaster recovery planning, and ensure business continuity.
  • Kubernetes: Deploy and manage containerized applications using Docker and Kubernetes, ensuring high availability and fault tolerance. Implement CI/CD pipelines with Kubernetes integration for automated testing, building, and deployment workflows. Configure service discovery, load balancing, ingress controllers, and persistent storage solutions.
Required Qualifications
  • Experience: 10+ years in security/SOC engineering, log management, or infrastructure engineering.
  • SIEM/SOAR Expertise: Hands-on production experience administering Splunk/Elastic/SOAR (clustering, upgrades) and SOAR platforms (playbook development/connectors).
  • Pipeline Proficiency: Expert-level experience with log pipeline tooling (Cribl Stream/Edge preferred; Logstash/Vector/Kafka considered).
  • Infrastructure Skills: Strong Linux administration, scripting (Python/Bash), and syslog fundamentals (TLS, load balancing, high-volume tuning).
  • Data Onboarding: Proven ability to write complex regex-based parsers, field extractions, and normalization logic.
  • Cloud & Networking: Working knowledge of GCP services (Logging, IAM, GKE, Networking) and solid grasp of networking fundamentals (TCP/UDP, DNS, routing, packet capture).
  • Communication: Excellent written communication and disciplined documentation habits.
Preferred Qualifications
  • Domain Expertise: Experience in a telecom or service provider environment (Mobile Core, 5G, IMS/VoLTE, SS7/Diameter, OSS/BSS).
  • DevOps/Automation: Experience with Kubernetes/Helm, Terraform, and Ansible in hybrid environments.
  • Detection Engineering: Exposure to SPL, ES|QL, KQL, Sigma rules, and data lake/object storage tiering architectures.
  • Certifications: Splunk Architect, Elastic Certified Engineer, Cribl Certified Admin, RHCE/RHCSA, Google Professional Cloud Security Engineer, AWS Professional certificate.
RAKUTEN SHUGI PRINCIPLES

Our worldwide practices describe specific behaviours that make Rakuten unique and united across the world. We expect Rakuten employees to model these 5 Shugi Principles of Success.

  • Always improve, always advance.
  • Only be satisfied with complete success - Kaizen.
  • Be passionately professional.
  • Take an uncompromising approach to your work and be determined to be the best.
  • Hypothesize - Practice - Validate - Shikumika.
  • Use the Rakuten Cycle to success in unknown territory.
  • Maximize Customer Satisfaction.
  • The greatest satisfaction for workers in a service industry is to see their customers smile.
  • Speed!! Speed!! Speed!!
  • Always be conscious of time.
  • Take charge, set clear goals, and engage your team.

undefined undefined

Rakuten Symphony is reimagining telecom, changing supply chain norms and disrupting outmoded thinking that threatens the industry’s pursuit of rapid innovation and growth. Based on proven modern infrastructure practices, its open interface platforms make it possible to launch and operate advanced mobile services in a fraction of the time and cost of conventional approaches, with no compromise to network quality or security.

Rakuten Symphony has operations in Japan, the United States, Singapore, India, South Korea, Europe, and the Middle East Africa region. For more information, visit: https://symphony.rakuten.com Building on the technology Rakuten used to launch Japan’s newest mobile network, we are taking our mobile offering global.

To support our ambitions to provide an innovative cloud-native telco platform for our customers, Rakuten Symphony is looking to recruit and develop top talent from around the globe. We are looking for individuals to join our team across all functional areas of our business – from sales to engineering, support functions to product development. Let’s build the future of mobile telecommunications together!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Engineer, Security Operations Center
Staff Engineer, Security Operations Center

Rakuten Asia Pte Ltd • Bengaluru

On-site
INR 1,500,000 - 2,300,000
Senior Specialist, Cloud Security
Senior Specialist, Cloud Security

Rakuten Asia Pte Ltd • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Senior Specialist, Security Operation
Senior Specialist, Security Operation

Rakuten Kobo Inc. • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Technical Lead - Platform
Technical Lead - Platform

Rakuten Asia Pte Ltd • Bengaluru

On-site
INR 4,500,000 - 7,000,000
Site Reliability Engineer
Site Reliability Engineer

Rakuten Asia Pte Ltd • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Senior Engineer - Penetration Tester
Senior Engineer - Penetration Tester

Rakuten Kobo Inc. • Bengaluru

On-site
INR 4,500,000 - 7,500,000
Technical Lead, Network & Cloud Infrastructure
Technical Lead, Network & Cloud Infrastructure

Rakuten Symphony • Bengaluru

On-site
INR 3,000,000 - 6,000,000
Technical Lead (Java 17+)
Technical Lead (Java 17+)

Rakuten Symphony • Bengaluru

On-site
INR 4,500,000 - 6,000,000
Technical Lead - Integration
Technical Lead - Integration

Rakuten Kobo Inc. • Bengaluru

On-site
INR 1,500,000 - 2,700,000
Specialist, CEM
Specialist, CEM

Rakuten Asia Pte Ltd • Indore District

On-site
INR 400,000 - 650,000