Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SOC Engineer (Incident Response & Python Automation) (SIEM, SOAR, AWS, Python): Designing and maintaining SOC security platforms, detection tooling, and Python-based automation for SIEM, EDR, AWS, and internal security systems with an accent on incident response, detection engineering, and cloud security integrations. Focus on building detection use cases, automating alert investigation, and handling containment and post-incident analysis in an on-call SOC environment.
Location: Remote in Asia
Company
Binance operates a global blockchain ecosystem covering cryptocurrency exchange, trading and finance, payments, institutional services, and Web3 products.
What you will do
- Design, develop, and maintain SOC security platforms and tooling focused on SIEM, SOAR, and security automation.
- Develop Python services, scripts, workflows, APIs, and integrations with SIEM, EDR, AWS, and internal security platforms.
- Build and maintain AWS security services using EC2, S3, Lambda, IAM, and CloudWatch.
- Support SIEM operations and detection engineering, including log ingestion, parsing, normalization, correlation, and rule development.
- Develop threat models and detection use cases based on attack scenarios and real-world incidents.
- Participate in SOC on-call rotation and incident response, covering triage, investigation, containment, and post-incident analysis.
Requirements
- Hands-on Python development experience.
- Hands-on AWS experience, particularly with EC2, S3, Lambda, IAM, and CloudWatch.
- Experience building production-quality services, automation, APIs, or internal security tools.
- Practical SIEM experience covering security monitoring, log analysis, and alert investigation.
- Understanding of SOC operations, incident response, security threats, detections, threat models, and SIEM use cases.
- Familiarity with EDR, security telemetry, REST APIs, Git, Docker, and Linux, plus strong troubleshooting and communication skills.
Nice to have
- 4+ years of experience in SOC or security operations with an incident response focus.
- Experience with DLP design, deployment, monitoring, threat hunting, forensic analysis, or APT detection.
- Strong programming skills involving macOS Swift, Unix socket programming, or scripting.
- Knowledge of SIEM, EDR, cloud security architectures, encryption, tokenization, and data classification.
- Golang or Java experience.
Culture & Benefits
- Remote work arrangement for the Asia region; the arrangement may vary depending on business needs.
- Work in a global, user-centric organization with a flat structure.
- Autonomy on fast-paced blockchain and security projects.
- Career growth and continuous learning opportunities.
- Competitive salary and company benefits.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Senior Detection and Response Engineer (Fintech)
170 000 - 225 000$
4 дня назад
Senior Detection and Response Engineer
200 000 - 240 000$
4 дня назад
Senior SOC Analyst, Security Operations (AWS/Elastic)
6 дней назад
Security Engineer (Fintech)
5 дней назад
Senior Incident Response Analyst (CrowdStrike)
5 дней назад