We’re looking for a security engineer with hands-on experience in Data Loss Prevention (DLP) and incident response, ideally within fintech, crypto, or high-security environments. The role goes beyond using commercial tools you’ll also design and build custom solutions, leverage automation, and adapt to emerging threats, including those driven by recent LLM/AI advancements.
Responsibilities
Design, develop, and maintain security automation and SOC tooling, including integrations with SIEM, EDR, cloud services, and internal security platforms
Develop services, scripts, and pipelines to automate alert enrichment, correlation, response, and investigation workflows
Build and maintain API-based integrations with security tools, AWS services, and internal systems
Support and enhance SIEM platforms for ingestion, alerting, and investigation
Participate in security detection engineering, including log parsing, data normalization, and detection logic implementation
Assist in security incident response, including triage, investigation, containment, eradication, and post-incident analysis
Take part in SOC on-call rotation / shift duty, responding to security alerts and incidents as required
Work closely with SOC analysts to translate operational needs into scalable engineering solutions, debug, troubleshoot, and optimize existing security automation, CI/CD pipelines, and platform components etc.
Requirements
4+ years in a SOC or security operations role with incident response focus.
Proven experience with DLP design, deployment, and monitoring.
Strong programming skills (macOS Swift, Unix socket programming, scripting).
Hands-on threat hunting, forensic analysis, and APT detection experience.
Familiarity with SIEM, EDR, and cloud security architectures.
Knowledge of encryption, tokenization, and data classification methods.
Nice-to-have
4+ years in a SOC or security operations role with incident response focus.
Proven experience with DLP design, deployment, and monitoring.
Strong programming skills (macOS Swift, Unix socket programming, scripting).
Hands-on threat hunting, forensic analysis, and APT detection experience.
Familiarity with SIEM, EDR, and cloud security architectures.
Knowledge of encryption, tokenization, and data classification methods.