Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. We are trusted by over 280 million people in 100+ countries for our industry-leading security, user fund transparency, trading engine speed, deep liquidity, and an unmatched portfolio of digital-asset products. Binance offerings range from trading and finance to education, research, payments, institutional services, Web3 features, and more. We leverage the power of digital assets and blockchain to build an inclusive financial ecosystem to advance the freedom of money and improve financial access for people around the world.
We are looking for a SOC Security Development Engineer to join our Security Operations team.
This role focuses on security platform development, automation, and engineering integration with internal tools while also actively participating in incident response and SOC on-call operations.
The ideal candidate has strong hands-on programming skills, solid understanding of SOC workflows, and practical experience integrating and extending security platforms such as SIEM, EDR, and cloud-based security services through APIs and custom development.
Responsibilities
- Design, develop, and maintain security automation and SOC tooling, including integrations with SIEM, EDR, cloud services, and internal security platforms
- Develop services, scripts, and pipelines to automate alert enrichment, correlation, response, and investigation workflows
- Build and maintain API-based integrations with security tools, AWS services, and internal systems
- Support and enhance SIEM platforms for ingestion, alerting, and investigation
- Participate in security detection engineering, including log parsing, data normalization, and detection logic implementation
- Assist in security incident response, including triage, investigation, containment, eradication, and post-incident analysis
- Take part in SOC on-call rotation / shift duty, responding to security alerts and incidents as required
Work closely with SOC analysts to translate operational needs into scalable engineering solutions, debug, troubleshoot, and optimize existing security automation, CI/CD pipelines, and platform components etc.
Requirements
- Programming & Engineering Skills: Strong hands-on programming experience in one or more languages, such as: Python (preferred), Golang, Java.
- Experience writing production-quality code, not just ad-hoc scripts, solid experience with RESTful APIs, including authentication, pagination, rate limiting, and error handling, familiarity with modern IDEs (VS Code, IntelliJ, PyCharm) and debugging techniques
- Experience with Git-based version control and collaborative development workflows, Cloud, CI/CD & Containerization, practical experience working with AWS environments, including common services such as IAM, EC2, S3, Lambda, and CloudWatch, experience building, deploying, and maintaining Docker-based applications
- Security & SOC Knowledge: Hands-on experience working in or closely with a Security Operations Center (SOC), like experience using SIEM platforms and familiarity with EDR solutions, understanding of common security telemetry sources
- Platform & System Skills, experience developing or extending security platforms or internal security tools, solid Linux fundamentals
Why Binance
• Shape the future with the world’s leading blockchain ecosystem
• Collaborate with world-class talent in a user-centric global organization with a flat structure
• Tackle unique, fast-paced projects with autonomy in an innovative environment
• Thrive in a results-driven workplace with opportunities for career growth and continuous learning
• Competitive salary and company benefits
• Work-from-home arrangement (the arrangement may vary depending on the work nature of the business team)
Binance is committed to being an equal opportunity employer. We believe that having a diverse workforce is fundamental to our success.