Responsibilities
- Design, develop, and maintain SOC security platforms and tooling, with a primary focus on SIEM, SOAR, and security automation.
- Develop Python-based services, scripts, automation workflows, and security integrations with SIEM, EDR, AWS, and internal security platforms.
- Build and maintain AWS-based security services and integrations, including EC2, S3, Lambda, IAM, and CloudWatch.
- Support SIEM operations and detection engineering, including log ingestion, parsing, normalization, correlation, and detection rule development.
- Develop detection use cases and common security threat models, based on attack scenarios and real-world security incidents.
- Participate in SOC on-call rotation and incident response, including alert triage, investigation, containment, and post-incident analysis.
- Work with SOC analysts and security teams to improve security automation, detection coverage, and platform capabilities.
Requirements
- Hands-on Python development experience is required. Experience with Golang or Java is a plus.
- Hands-on experience with AWS, particularly EC2, S3, Lambda, IAM, and CloudWatch.
- Experience developing production-quality services, automation, APIs, or internal security tools.
- Practical experience using SIEM platforms for security monitoring, log analysis, and alert investigation.
- Good understanding of SOC operations and Incident Response (IR), including alert triage and security incident investigation.
- Understanding of common security threats and experience developing security detections / threat models / SIEM use cases.
- Familiarity with EDR, security telemetry, REST APIs, Git, Docker, and Linux.
- Strong problem-solving, troubleshooting, and communication skills.
Nice-to-have
- 4+ years in a SOC or security operations role with incident response focus.
- Proven experience with DLP design, deployment, and monitoring.
- Strong programming skills (macOS Swift, Unix socket programming, scripting).
- Hands-on threat hunting, forensic analysis, and APT detection experience.
- Familiarity with SIEM, EDR, and cloud security architectures.
- Knowledge of encryption, tokenization, and data classification methods.
Binance is committed to being an equal opportunity employer. We believe that having a diverse workforce is fundamental to our success.By submitting a job application, you confirm that you have read and agree to our Candidate Privacy Notice.