SOC Security EngineerActive

The opportunity

Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. We are trusted by 300+ million people in 100+ countries for our industry-leading security, user fund transparency, trading engine speed,…

What you'll do

  • Design, develop, and maintain SOC security platforms and tooling, with a: primary focus on SIEM, SOAR, and security automation.

  • Develop Python-based services, scripts, automation workflows, and security: integrations with SIEM, EDR, AWS, and internal security platforms.

  • Build and maintain AWS-based security services and integrations, including: EC2, S3, Lambda, IAM, and CloudWatch.

  • Support SIEM operations and detection engineering, including log ingestion,: parsing, normalization, correlation, and detection rule development.

  • Develop detection use cases and common security threat models, based on: attack scenarios and real-world security incidents.

  • Participate in SOC on-call rotation and incident response, including alert: triage, investigation, containment, and post-incident analysis.

What they're looking for

  • Hands-on Python development experience is required. Experience with Golang or Java is a plus.
  • Hands-on experience with AWS, particularly EC2, S3, Lambda, IAM, and CloudWatch.
  • Experience developing production-quality services, automation, APIs, or internal security tools.
  • Practical experience using SIEM platforms for security monitoring, log analysis, and alert investigation.
  • Good understanding of SOC operations and Incident Response (IR), including: alert triage and security incident investigation.
  • Understanding of common security threats and experience developing security: detections / threat models / SIEM use cases.
  • Familiarity with EDR, security telemetry, REST APIs, Git, Docker, and Linux.
  • Strong problem-solving, troubleshooting, and communication skills.