
Key Responsibilities
- Own the end-to-end incident response lifecycle - including detection, analysis, triage, containment, remediation, recovery, root cause analysis, and reporting.
- Design, build, and enhance core SOC platforms such as SIEM, SOAR, EDR, and Threat Intelligence Platforms (TIP) to improve detection fidelity and response automation.
- Research, collect, and operationalize internal and external threat intelligence to strengthen our detection and response playbooks.
- Partner with IT, cloud, and application security teams to investigate security issues, harden defenses, and support continuous improvement.
- Participate in on-call rotations or flexible schedules to handle critical incidents and ensure 24/7 SOC coverage.
Qualifications & Requirements
- Bachelor degree in computer science or similar discipline.
- Minimum of 3 years of professional experience as a SOC Analyst, threat hunter or a similar comparable role dealing with security incident response or security engineering.
- Solid operational knowledge of cybersecurity tools including but not limited to SIEM, EDR, TIP and IPS/IDS solutions.
- Experienced in any of the following programming languages: Python, Node.js, Java.
- Possession of 1 or more of the following certifications: GCIH, CEH, OSCP, CISSP.
About Amber Group
Amber Group, founded in 2017 by Michael Wu, Thomas Zhu, Tiantian Kullander and colleagues in Hong Kong and Singapore, operates as a global digital asset market maker, liquidity provider and wealth platform. Its services span OTC trading, electronic market making, structured products and Amber Premium for high-net-worth clients, with coverage across spot, derivatives and DeFi. Headquartered in Singapore with offices in Hong Kong, Seoul and London, Amber combines quantitative trading, risk systems and 24/7 operations. The firm emphasizes risk discipline, treasury management and institutional-grade execution across centralized and decentralized venues. Backed by leading investors, Amber navigated market cycles to focus on sustainable liquidity provision. Expect a markets-driven culture that values quantitative rigor, operational discipline and reliable service in volatile crypto conditions.