Senior SOC Engineer
Liminal provides institutional digital-asset custody and wallet infrastructure. Its platform offers MPC and multisig wallets, custody, staking, compliance, transaction governance, automation, and APIs for banks, exchanges, fintechs, and other digital-asset businesses.
Funding history
About Liminal
Liminal is an institutional crypto custody and wallet infrastructure company. It provides Wallet-as-a-Service, managed and self-custody solutions, MPC and multisig wallet technology, cold custody, institutional staking, HSM Vault, transaction screening, compliance integrations, policy-based governance, automation, and REST APIs through Liminal Express. Its clients include exchanges, OTC and brokerage firms, Web3 platforms, hedge funds, family offices, market makers, private equity and venture capital firms, banks, and other enterprises building on digital assets.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
Liminal Custody is seeking a Senior Security Operations Engineer to protect critical cloud, application, and blockchain infrastructure through incident response, detection engineering, threat intelligence, threat hunting, and security automation.
Requirements
- 5–7 years of experience in Security Operations, Detection Engineering, Incident Response, Threat Hunting, or Security Engineering.
- Strong hands-on experience with SIEM, security monitoring, and log analysis.
- Experience with Elastic, Elasticsearch, Kibana, and Datadog.
- Strong understanding of Incident Response and MITRE ATT&CK.
- Experience building and tuning security detections.
- Good understanding of AWS, Linux, networking, and cloud security.
- Strong scripting and automation skills in Python, Bash, or similar.
- Strong analytical and investigative mindset with the ability to independently handle security incidents.
- Experience with Web3, blockchain, cryptocurrency, or digital asset security is an advantage.
- Experience with AWS security services is an advantage.
- Experience with threat hunting, SOAR, EDR/XDR, Sigma, YARA, or Suricata is an advantage.
- Security certifications such as GCIH, GCIA, GCFA, Security+, CySA+, or equivalent are an advantage.
Responsibilities
- Investigate and respond to security incidents across cloud, applications, infrastructure, and blockchain environments.
- Design, develop, and continuously improve security detections and monitoring use cases.
- Build and tune detections using Elastic and Datadog.
- Conduct proactive threat hunting based on threat intelligence and attacker TTPs.
- Translate threat intelligence into actionable detections, IOCs, and response capabilities.
- Improve security visibility and telemetry across AWS and blockchain infrastructure.
- Develop automation for alert enrichment, investigation, and incident response.
- Perform root-cause analysis and drive remediation following security incidents.
- Work closely with Engineering, DevOps, Platform, and Security teams to strengthen security posture.
