Coins.ph
Senior SOC Engineer
CN · Hybrid · Full-time Employee
Apply on the employer’s site ↗See how well you match this job
You apply directly with the employer. ROLIVA does not submit applications from this page and is not the employer.
Role details
- Employer posted
- Added to ROLIVA
- Last checked
- SourceCoins.ph careers page
Does the apply link above not work?
About the employer
- EmployerCoins.ph
- Open roles on ROLIVA120 open roles
- Where this posting comes fromListed on the employer’s own careers site: jobs.lever.co
About the role
Description from the employer’s posting. Check the employer’s page for the current version.
Join the Pioneer Crypto Brand in the Philippines!
Coins is the most established crypto brand in The Philippines and has gained the trust of more than 18 million users. Through the easy-to-use mobile app, users can buy and sell a variety of different cryptocurrencies and access a wide range of financial services.
Coins is fully regulated by the Bangko Sentral ng Pilipinas (BSP) and is the first ever crypto-based company in Asia to hold both Virtual Currency and Electronic Money Issuer licenses from a central bank.
We are actively seeking a highly skilled and experienced Senior SOC Engineer with expertise in cryptocurrency exchange security operations. This pivotal role is instrumental in ensuring the security of our digital assets and customer funds by leading comprehensive security monitoring, incident response, and threat analysis activities. Given the unique challenges of operating a cryptocurrency exchange, this position requires deep understanding of blockchain security, digital wallet protection, and financial crime prevention, with particular emphasis on threat intelligence analysis and insider threat detection.
Key Responsibilities: Security Operations Center Management Lead security monitoring operations for cryptocurrency exchange infrastructure, trading platforms, and digital wallet systems Oversee real-time analysis of security events, alerts, and anomalies across blockchain networks, trading engines, and customer-facing applications Coordinate incident response activities for security breaches, suspicious trading activities, and potential fraud attempts Manage and optimize SIEM platforms, security orchestration tools, and automated response systems Develop and maintain security playbooks specific to cryptocurrency exchange operations and digital asset protection Insider & Threat Intelligence Analysis Monitor dark web marketplaces, criminal forums, and threat actor communications for indicators targeting cryptocurrency businesses Conduct tactical, operational, and strategic threat assessments specific to digital asset platforms Develop threat intelligence feeds and indicators of compromise (IoCs) relevant to cryptocurrency security Collaborate with external threat intelligence providers and cryptocurrency security communities Design and implement comprehensive insider threat detection programs tailored to cryptocurrency exchange environments Analyze user behavior patterns to identify potential malicious insider activities or account compromises Conduct investigations into suspicious employee activities, unauthorized access attempts, and data exfiltration Incident Response & Forensics Lead incident response efforts for security breaches, fund theft attempts, and system compromises Conduct digital forensics investigations on cryptocurrency-related security incidents Coordinate with law enforcement, regulatory bodies, and external security firms during major incidents Develop and maintain incident response procedures specific to cryptocurrency exchange operations Create post-incident reports and recommendations for security improvements Required Qualifications: Technical Skills Experience: Minimum 5+ years in SOC operations, preferably in financial services or cryptocurrency exchanges Certifications : CISSP, GCIH, GCFA, GNFA, GCTI, CEH, or equivalent security certifications required SIEM Expertise : Advanced proficiency with SIEM platforms (Sumo Logic, Splunk, QRadar, Sentinel, etc.) Threat Intelligence : Experience with threat intelligence platforms (MISP, ThreatConnect, Anomali) and frameworks (MITRE ATT&CK, Diamond Model) Programming/Scripting : Proficiency in Python, PowerShell, or similar languages for automation and analysis Cloud Security : Experience securing cloud infrastructure (AWS, Azure, GCP) and container environments Preferred Qualifications: Additional certifications: CISSP, CISM, GCTI, GCFA, CEH, or cryptocurrency-specific certifications Experience with insider threat analysis tools and methodologies (Securonix, Exabeam, Splunk UBA, Microsoft Sentinel UEBA) Background in behavioral analytics, user activity monitoring, and privileged access management Join the Coins Team Now!
Meaningful Collaborations - The successful candidate will work cross-functionally with other relevant teams to carry out implementations that will improve and create an impact on customer experience.
Scalable Growth - Be part of a fast-growing organization with the vision to expand its territories outside APAC which will provide opportunities for career advancement.
A Space For Bright Ideas - Let your bright ideas be converted into meaningful changes! Coins culture welcomes new ideas backed up by data to create an impact.
Staying safe while you apply
- Never pay to apply, interview or accept an offer — ROLIVA never asks you for payment to apply to a job.
- Apply only through the official button above, on the employer’s own site, and check that a recruiter’s email uses that employer’s own domain rather than a free email address.
- Be cautious of an offer made with no real interview, or pressure to decide quickly or share financial details early.
Does something look wrong with this listing? Use “Report broken link” above, or read ROLIVA’s full job-safety guidance ↗.
Preparing for this role with ROLIVA
- Check the fit.
Compare the requirements with the experience you have confirmed, including gaps.
- Prepare honestly.
Build interview stories and application drafts from your own evidence.
- Keep track.
Save the role and record your own application status and follow-ups.