Назад
2 дня назад

SOC Engineer (Incident Response & Python Automation)

Формат работы
remote (только ASIA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
SOC Engineer (Incident Response & Python Automation) (SIEM, SOAR, AWS, Python): Designing and maintaining SOC security platforms, detection tooling, and Python-based automation for SIEM, EDR, AWS, and internal security systems with an accent on incident response, detection engineering, and cloud security integrations. Focus on building detection use cases, automating alert investigation, and handling containment and post-incident analysis in an on-call SOC environment.

Location: Remote in Asia

Company

Binance operates a global blockchain ecosystem covering cryptocurrency exchange, trading and finance, payments, institutional services, and Web3 products.

What you will do

  • Design, develop, and maintain SOC security platforms and tooling focused on SIEM, SOAR, and security automation.
  • Develop Python services, scripts, workflows, APIs, and integrations with SIEM, EDR, AWS, and internal security platforms.
  • Build and maintain AWS security services using EC2, S3, Lambda, IAM, and CloudWatch.
  • Support SIEM operations and detection engineering, including log ingestion, parsing, normalization, correlation, and rule development.
  • Develop threat models and detection use cases based on attack scenarios and real-world incidents.
  • Participate in SOC on-call rotation and incident response, covering triage, investigation, containment, and post-incident analysis.

Requirements

  • Hands-on Python development experience.
  • Hands-on AWS experience, particularly with EC2, S3, Lambda, IAM, and CloudWatch.
  • Experience building production-quality services, automation, APIs, or internal security tools.
  • Practical SIEM experience covering security monitoring, log analysis, and alert investigation.
  • Understanding of SOC operations, incident response, security threats, detections, threat models, and SIEM use cases.
  • Familiarity with EDR, security telemetry, REST APIs, Git, Docker, and Linux, plus strong troubleshooting and communication skills.

Nice to have

  • 4+ years of experience in SOC or security operations with an incident response focus.
  • Experience with DLP design, deployment, monitoring, threat hunting, forensic analysis, or APT detection.
  • Strong programming skills involving macOS Swift, Unix socket programming, or scripting.
  • Knowledge of SIEM, EDR, cloud security architectures, encryption, tokenization, and data classification.
  • Golang or Java experience.

Culture & Benefits

  • Remote work arrangement for the Asia region; the arrangement may vary depending on business needs.
  • Work in a global, user-centric organization with a flat structure.
  • Autonomy on fast-paced blockchain and security projects.
  • Career growth and continuous learning opportunities.
  • Competitive salary and company benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →