Senior SOC Engineer
Liminal is an institutional digital-asset custody and wallet-infrastructure company. It provides MPC and multi-signature wallet infrastructure, custodial storage, staking, compliance tooling, and transaction automation for organizations managing digital assets.
Funding history
About Liminal
Liminal provides institutional-grade digital-asset custody and wallet infrastructure. Its platform includes API-driven wallet management, MPC and multi-signature wallets, cold custody, white-label custody solutions, institutional staking, HSM-based vaults, automation, and transaction-policy controls. Liminal serves institutions including crypto exchanges, OTC and brokerage firms, Web3 businesses, hedge funds, family offices, market makers, asset managers, and corporate treasuries, with compliance integrations for KYC, KYT, AML/CFT, and Travel Rule workflows.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You investigate and respond to security incidents across cloud, application, infrastructure, and blockchain environments. You design and improve detections, build monitoring use cases with Elastic and Datadog, conduct threat hunting, translate intelligence into actionable detections, improve AWS and blockchain telemetry, automate investigations and response, and drive remediation after incidents.
Requirements
- 5-7 years of experience in Security Operations, Detection Engineering, Incident Response, Threat Hunting, or Security Engineering
- Hands-on experience with SIEM, security monitoring, and log analysis
- Experience with Elastic, Elasticsearch, Kibana, and Datadog
- Strong understanding of Incident Response and MITRE ATT&CK
- Experience building and tuning security detections
- Understanding of AWS, Linux, networking, and cloud security
- Strong scripting and automation skills in Python, Bash, or similar
- Ability to independently handle security incidents
- Experience with Web3, blockchain, cryptocurrency, or digital asset security is an advantage
- Experience with AWS security services is an advantage
- Experience with threat hunting, SOAR, EDR/XDR, Sigma, YARA, or Suricata is an advantage
- Security certifications such as GCIH, GCIA, GCFA, Security+, CySA+, or equivalent are an advantage
Responsibilities
- Investigate and respond to security incidents across cloud, applications, infrastructure, and blockchain environments
- Design, develop, and improve security detections and monitoring use cases
- Build and tune detections using Elastic and Datadog
- Conduct proactive threat hunting based on threat intelligence and attacker TTPs
- Translate threat intelligence into actionable detections, IOCs, and response capabilities
- Improve security visibility and telemetry across AWS and blockchain infrastructure
- Develop automation for alert enrichment, investigation, and incident response
- Perform root-cause analysis and drive remediation after security incidents
- Work with Engineering, DevOps, Platform, and Security teams to strengthen security posture
