SOC Security Development Engineer developing security automation and SOC tooling for Binance. Join the Security Operations team focusing on engineering integration and incident response.
Responsibilities
Design, develop, and maintain security automation and SOC tooling, including integrations with SIEM, EDR, cloud services, and internal security platforms
Develop services, scripts, and pipelines to automate alert enrichment, correlation, response, and investigation workflows
Build and maintain API-based integrations with security tools, AWS services, and internal systems
Support and enhance SIEM platforms for ingestion, alerting, and investigation
Participate in security detection engineering, including log parsing, data normalization, and detection logic implementation
Assist in security incident response, including triage, investigation, containment, eradication, and post-incident analysis
Take part in SOC on-call rotation / shift duty, responding to security alerts and incidents as required
Work closely with SOC analysts to translate operational needs into scalable engineering solutions, debug, troubleshoot, and optimize existing security automation, CI/CD pipelines, and platform components etc.
Requirements
Programming & Engineering Skills: Strong hands-on programming experience in one or more languages, such as: Python (preferred), Golang, Java.
Experience writing production-quality code, not just ad-hoc scripts, solid experience with RESTful APIs, including authentication, pagination, rate limiting, and error handling, familiarity with modern IDEs (VS Code, IntelliJ, PyCharm) and debugging techniques
Experience with Git-based version control and collaborative development workflows, Cloud, CI/CD & Containerization, practical experience working with AWS environments, including common services such as IAM, EC2, S3, Lambda, and CloudWatch, experience building, deploying, and maintaining Docker-based applications
Security & SOC Knowledge: Hands-on experience working in or closely with a Security Operations Center (SOC), like experience using SIEM platforms and familiarity with EDR solutions, understanding of common security telemetry sources
Platform & System Skills, experience developing or extending security platforms or internal security tools, solid Linux fundamentals
Benefits
Competitive salary and company benefits
Work-from-home arrangement (the arrangement may vary depending on the work nature of the business team)
Account Cybersecurity Lead providing cybersecurity governance and oversight at Capgemini. Leading client relationships, security management systems, and risk compliance oversight.
Cybersecurity Risk Coordinator at Globo ensuring operational security across digital content. Analyzing risks and developing strategies to enhance business resilience.
Senior SAP Security Specialist managing SAP Security responsibilities and projects. Collaborating on security tools and conducting workshops in Hamburg.
Sales Account Manager for Cyber Security and Awareness role at HvS - Consulting GmbH. Providing holistic consulting on Cyber Security services and managing client relationships.
Security Engineer at PRC - Saltillo safeguarding IT infrastructure from cyber threats. Collaborating with IT teams to design and maintain security controls in a hybrid work environment.
Information Security Manager leading cyber security initiatives at NVISO, enhancing clients’ security posture and managing a team of consultants in Germany.
Cybersecurity Assessment Expert at IT - Strat managing A&A of information systems for U.S. federal clients. Ensuring compliance with DOD cybersecurity policies and standards in complex IT environments.
Senior Security Engineer responsible for deploying and maintaining endpoint security solutions. Collaborating across teams to enhance security posture and supporting incident response activities.
Administrative support role within MAHLE's Thermal and Fluid Systems unit, assisting the team with various operational tasks and employee interactions.