Responsibilities
- Design, develop, and maintain SOC security platforms and tooling, with a primary focus on SIEM, SOAR, and security automation.
- Develop Python-based services, scripts, automation workflows, and security integrations with SIEM, EDR, AWS, and internal security platforms.
- Build and maintain AWS-based security services and integrations, including EC2, S3, Lambda, IAM, and CloudWatch.
- Support SIEM operations and detection engineering, including log ingestion, parsing, normalization, correlation, and detection rule development.
- Develop detection use cases and common security threat models, based on attack scenarios and real-world security incidents.
- Participate in SOC on-call rotation and incident response, including alert triage, investigation, containment, and post-incident analysis.
- Work with SOC analysts and security teams to improve security automation, detection coverage, and platform capabilities.
Requirements
- Hands-on Python development experience is required. Experience with Golang or Java is a plus.
- Hands-on experience with AWS, particularly EC2, S3, Lambda, IAM, and CloudWatch.
- Experience developing production-quality services, automation, APIs, or internal security tools.
- Practical experience using SIEM platforms for security monitoring, log analysis, and alert investigation.
- Good understanding of SOC operations and Incident Response (IR), including alert triage and security incident investigation.
- Understanding of common security threats and experience developing security detections / threat models / SIEM use cases.
- Familiarity with EDR, security telemetry, REST APIs, Git, Docker, and Linux.
- Strong problem-solving, troubleshooting, and communication skills.
Skills Required
- Hands-on programming experience in Python, Golang, or Java
- Experience writing production-quality code and working with RESTful APIs (auth, pagination, rate limiting, error handling)
- Experience with Git-based version control and collaborative development workflows
- Practical experience with AWS services (IAM, EC2, S3, Lambda, CloudWatch), CI/CD pipelines, and Docker/containerization
- Hands-on experience in or closely with a Security Operations Center (SOC); familiarity with SIEM platforms and EDR solutions
- Experience developing or extending security platforms, internal security tools, and security automation
- Solid Linux fundamentals and debugging skills
- Ability to participate in SOC on-call rotation/shift duty and support incident response workflows
Binance Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Binance and has not been reviewed or approved by Binance.
-
Career-Linked Recognition & Rewards — Performance-linked bonuses can be sizable in favorable crypto cycles, lifting total compensation. Attractive packages in engineering and specialized roles indicate strong rewards for in-demand skills.
-
Flexible Benefits — Remote-first flexibility and work-from-anywhere options add meaningful value to the overall rewards package. Flexible schedules and location independence are presented as core perks.
-
Retirement Support — Binance.US includes a 401(k) as part of its benefits. This provides a conventional retirement pillar alongside cash and bonus components.
Binance Insights
What We Do
Binance is the world’s leading blockchain and cryptocurrency infrastructure provider with a financial product suite that includes the largest digital asset exchange by volume. Trusted by millions worldwide, the Binance platform is dedicated to increasing the freedom of money for users, and features an unmatched portfolio of crypto products and offerings, including: trading and finance, education, data and research, social good, investment and incubation, decentralization and infrastructure solutions, and more. For more information, visit: https://www.binance.com






