
SOC Engineer (Incident Response)
Binance
๐ง๐ฉ Bangladesh | ๐จ๐ณ China | ๐ฎ๐ฉ Indonesia | ๐ฎ๐ณ India | ๐ฎ๐ท Iran | ๐ฏ๐ด Jordan | ๐ฏ๐ต Japan | ๐ฐ๐ท South Korea | ๐ฐ๐ฟ Kazakhstan | ๐ฑ๐ฆ Laos | ๐ฑ๐ง Lebanon | ๐ฑ๐ฐ Sri Lanka | ๐ฒ๐ฒ Myanmar | ๐ฒ๐ป Maldives | ๐ฒ๐พ Malaysia | ๐ณ๐ต Nepal | ๐ด๐ฒ Oman | ๐ต๐ญ Philippines | ๐ต๐ฐ Pakistan | ๐ธ๐ฌ Singapore | ๐น๐ญ Thailand | ๐น๐ท Turkey | ๐น๐ผ Taiwan | ๐ป๐ณ Vietnam | ๐พ๐ช Yemen
Remote
3 months ago
- SIEM
- Python
- EDR
- AWS
- EC2
- IAM
- CloudWatch
- Incident Response
- triage
- Golang
- Java
- REST API
- Git
- Docker
- Linux
- DLP
- MacOS
- Swift
- Unix
3 months ago
Responsibilities
- Design, develop, and maintain SOC security platforms and tooling, with a primary focus on SIEM, SOAR, and security automation.
- Develop Python-based services, scripts, automation workflows, and security integrations with SIEM, EDR, AWS, and internal security platforms.
- Build and maintain AWS-based security services and integrations, including EC2, S3, Lambda, IAM, and CloudWatch.
- Support SIEM operations and detection engineering, including log ingestion, parsing, normalization, correlation, and detection rule development.
- Develop detection use cases and common security threat models, based on attack scenarios and real-world security incidents.
- Participate in SOC on-call rotation and incident response, including alert triage, investigation, containment, and post-incident analysis.
- Work with SOC analysts and security teams to improve security automation, detection coverage, and platform capabilities.
Requirements
- Hands-on Python development experience is required. Experience with Golang or Java is a plus.
- Hands-on experience with AWS, particularly EC2, S3, Lambda, IAM, and CloudWatch.
- Experience developing production-quality services, automation, APIs, or internal security tools.
- Practical experience using SIEM platforms for security monitoring, log analysis, and alert investigation.
- Good understanding of SOC operations and Incident Response (IR), including alert triage and security incident investigation.
- Understanding of common security threats and experience developing security detections / threat models / SIEM use cases.
- Familiarity with EDR, security telemetry, REST APIs, Git, Docker, and Linux.
- Strong problem-solving, troubleshooting, and communication skills.
Nice-to-have
- 4+ years in a SOC or security operations role with incident response focus.
- Proven experience with DLP design, deployment, and monitoring.
- Strong programming skills (macOS Swift, Unix socket programming, scripting).
- Hands-on threat hunting, forensic analysis, and APT detection experience.
- Familiarity with SIEM, EDR, and cloud security architectures.
- Knowledge of encryption, tokenization, and data classification methods.
Binance is committed to being an equal opportunity employer. We believe that having a diverse workforce is fundamental to our success.By submitting a job application, you confirm that you have read and agree to ourCandidate Privacy Notice.
SOC Engineer (Incident Response) ยท Binance