SOC Engineer (Incident Response) (Web3)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
SOC Engineer (Incident Response) (Cybersecurity): Designing and optimizing DLP solutions and incident response workflows for a global blockchain ecosystem with an accent on custom tool development and data exfiltration prevention. Focus on building custom macOS/Unix endpoint protections, conducting deep forensic analysis, and integrating AI-driven anomaly detection.
Location: Remote (Must be based in Asia)
Company
is a leading global blockchain ecosystem and the world’s largest cryptocurrency exchange by trading volume and registered users.
What you will do
- Design, deploy, and optimize DLP solutions across network, endpoint, and cloud environments.
- Create and refine data classification schemes for sensitive assets such as wallets and trading algorithms.
- Lead investigations into DLP incidents and insider threats using threat hunting and forensic analysis.
- Develop custom security tools and integrations using macOS Swift and Unix socket programming.
- Automate detection and response processes via scripts, APIs, and AI/LLM-driven anomaly detection.
- Ensure data protection controls align with global financial regulations including AML, KYC, GDPR, and CCPA.
Requirements
- 4+ years of experience in a SOC or security operations role with a focus on incident response.
- Proven experience in the design, deployment, and monitoring of DLP solutions.
- Strong programming skills in macOS Swift, Unix socket programming, and general scripting.
- Hands-on experience with threat hunting, forensic analysis, and APT detection.
- Familiarity with SIEM, EDR, and cloud security architectures.
- Must be based in Asia.
Culture & Benefits
- Opportunity to shape the future of the world’s leading blockchain ecosystem.
- Collaboration with world-class talent in a global organization with a flat structure.
- High level of autonomy in an innovative, fast-paced, and results-driven environment.
- Competitive salary and comprehensive company benefits.
- Flexible work-from-home arrangements.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →