SOC Security Engineer
BinanceAsiaFull-time Onsite or Remote2w ago
Web3BlockchainSecuritySOCFinanceEngineeringremotecurated-jd
Job description
SOC Security Engineer at Binance
About the role
This position involves building and improving the systems that protect Binance's digital assets and user data. You will engineer solutions to automate security operations and enhance our defenses against threats.
Key facts
What you'll do
- Create, refine, and manage security tools and automation for our Security Operations Center (SOC), connecting systems like SIEM, EDR, cloud platforms, and internal security software.
- Develop services, scripts, and automated processes to enrich alerts, correlate events, and streamline investigations and responses.
- Construct and maintain connections using APIs with security tools, AWS services, and internal company systems.
- Support and enhance SIEM platforms for data intake, alert generation, and investigative capabilities.
- Contribute to the creation of security detections by parsing logs, standardizing data, and implementing detection logic.
- Assist in responding to security incidents, including initial assessment, investigation, containment, removal of threats, and post-incident review.
- Participate in the SOC on-call schedule, addressing security alerts and incidents as they arise.
- Collaborate with SOC analysts to transform operational requirements into scalable engineering solutions, troubleshoot, and optimize existing security automation, CI/CD pipelines, and platform elements.
Requirements
- Programming and Engineering: Strong practical experience in at least one programming language, such as Python (preferred), Golang, or Java.
- Production Code: Proven ability to write production-ready code, not just temporary scripts. Solid experience with RESTful APIs, covering authentication, pagination, rate limiting, and error handling. Familiarity with modern IDEs like VS Code, IntelliJ, or PyCharm, and debugging methods.
- Version Control and Cloud: Experience with Git for version control and collaborative development. Practical experience with AWS environments, including services like IAM, EC2, S3, Lambda, and CloudWatch. Experience building, deploying, and managing applications using Docker.
- Security and SOC: Hands-on experience working within or closely with a Security Operations Center (SOC). Familiarity with SIEM platforms and EDR solutions. Understanding of common sources for security data.
- Platform and Systems: Experience developing or extending security platforms or internal security tools. Strong foundational knowledge of Linux systems.
Nice to have
- Experience with security detection engineering.
Skills & tools
- Python, Golang, Java
- RESTful APIs
- VS Code, IntelliJ, PyCharm
- Git
- AWS (IAM, EC2, S3, Lambda, CloudWatch)
- Docker
- SIEM platforms
- EDR solutions
- Linux
Practical notes
- This role may require participation in an on-call rotation.