Senior SOC Engineer

Liminal provides institutional digital-asset custody and wallet infrastructure. Its platform offers MPC and multisig wallets, custody, staking, compliance, transaction governance, automation, and APIs for banks, exchanges, fintechs, and other digital-asset businesses.

Distributed

Funding history

About Liminal

Liminal is an institutional crypto custody and wallet infrastructure company. It provides Wallet-as-a-Service, managed and self-custody solutions, MPC and multisig wallet technology, cold custody, institutional staking, HSM Vault, transaction screening, compliance integrations, policy-based governance, automation, and REST APIs through Liminal Express. Its clients include exchanges, OTC and brokerage firms, Web3 platforms, hedge funds, family offices, market makers, private equity and venture capital firms, banks, and other enterprises building on digital assets.

View jobs by Liminal

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

Liminal Custody is seeking a Senior Security Operations Engineer to protect critical cloud, application, and blockchain infrastructure through incident response, detection engineering, threat intelligence, threat hunting, and security automation.

Requirements

  • 5–7 years of experience in Security Operations, Detection Engineering, Incident Response, Threat Hunting, or Security Engineering.
  • Strong hands-on experience with SIEM, security monitoring, and log analysis.
  • Experience with Elastic, Elasticsearch, Kibana, and Datadog.
  • Strong understanding of Incident Response and MITRE ATT&CK.
  • Experience building and tuning security detections.
  • Good understanding of AWS, Linux, networking, and cloud security.
  • Strong scripting and automation skills in Python, Bash, or similar.
  • Strong analytical and investigative mindset with the ability to independently handle security incidents.
  • Experience with Web3, blockchain, cryptocurrency, or digital asset security is an advantage.
  • Experience with AWS security services is an advantage.
  • Experience with threat hunting, SOAR, EDR/XDR, Sigma, YARA, or Suricata is an advantage.
  • Security certifications such as GCIH, GCIA, GCFA, Security+, CySA+, or equivalent are an advantage.

Responsibilities

  • Investigate and respond to security incidents across cloud, applications, infrastructure, and blockchain environments.
  • Design, develop, and continuously improve security detections and monitoring use cases.
  • Build and tune detections using Elastic and Datadog.
  • Conduct proactive threat hunting based on threat intelligence and attacker TTPs.
  • Translate threat intelligence into actionable detections, IOCs, and response capabilities.
  • Improve security visibility and telemetry across AWS and blockchain infrastructure.
  • Develop automation for alert enrichment, investigation, and incident response.
  • Perform root-cause analysis and drive remediation following security incidents.
  • Work closely with Engineering, DevOps, Platform, and Security teams to strengthen security posture.