SOC Engineer (Incident Response) (Crypto)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
SOC Engineer (Incident Response) (Crypto): Design, deploy, and optimize DLP solutions across network, endpoint, and cloud, while leading incident investigations and threat hunting in a high-security blockchain environment with an accent on custom tools, automation, and AI/LLM-driven anomaly detection. Focus on building data classification schemes, forensic analysis of exfiltration attempts, and integrating DLP into SOC workflows for regulatory compliance.
Location: Argentina, Buenos Aires / Remote (work-from-home arrangement, may vary by team)
Company
Leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users.
What you will do
- Design, deploy, and optimize DLP solutions across network, endpoint, and cloud environments.
- Build data classification schemes and configure policies to prevent data exfiltration with minimal false positives.
- Monitor, analyze, and tune DLP alerts; lead investigations of incidents and insider threats.
- Conduct threat hunting, forensic analysis, and integrate DLP into SOC workflows and playbooks.
- Develop custom tools, automation scripts, APIs, and explore AI/LLM methods for detection.
- Ensure alignment with crypto/financial regulations and support audits.
Requirements
- 4+ years in SOC or security operations with incident response focus
- Proven experience with DLP design, deployment, and monitoring
- Strong programming skills (macOS Swift, Unix socket programming, scripting)
- Hands-on threat hunting, forensic analysis, and APT detection
- Familiarity with SIEM, EDR, and cloud security architectures
- Knowledge of encryption, tokenization, and data classification
Nice to have
- Experience in fintech, crypto, or high-security environments
Culture & Benefits
- Collaborate with world-class talent in a flat, user-centric global organization
- Autonomy on fast-paced, innovative projects in a results-driven environment
- Opportunities for career growth and continuous learning
- Competitive salary and company benefits
- Work-from-home arrangement (may vary by team)
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →