Full-Time

Security Operations Analyst

Level 2

Keyrock

Keyrock

201-500 employees

Liquidity provision through algorithmic trading

No salary listed

London, UK + 11 more

More locations: California, USA | Paris, France | Jackson Township, NJ, USA | Madrid, Spain | Brandon, FL, USA | Springfield, IL, USA | Milan, Metropolitan City of Milan, Italy | New York, NY, USA | Berlin, Germany | Dublin, Ireland | Sant Cugat del Vallès, Barcelona, Spain

Remote

Category
IT & Security (1)
Required Skills
ServiceNow
JIRA
Splunk
Requirements
  • 2–5+ years of SOC / incident response / security operations experience (or equivalent hands-on experience in a fast-paced production environment).
  • Strong ability to investigate across cloud security operations, endpoint security, identity, and core network fundamentals.
  • Proficiency with at least one SIEM and common SOC tooling (e.g., Splunk/Elastic/Sentinel; CrowdStrike/Defender; Jira/ServiceNow).
  • Ability to write clear incident documentation: timelines, scope, impact, containment actions, and recommended remediations.
  • Comfort operating in an on-call or shift environment (depending on coverage model).
Responsibilities
  • Take escalations from L1 and independently investigate complex, multi-signal alerts (identity compromise, cloud control-plane abuse, endpoint persistence, lateral movement, suspicious automation, data exfiltration).
  • Perform deep log/telemetry analysis across SIEM, EDR, cloud logs, IAM signals, network telemetry, email security, and SaaS audit trails.
  • Build and validate hypotheses, pivot across data sources, and produce clear incident timelines and scope assessments.
  • Serve as technical incident lead for defined incident types/severities (or co-lead with IR), driving containment and eradication steps within authorized bounds.
  • Execute and improve response playbooks for key scenarios (phishing/BEC, credential theft, token/key compromise, suspicious API activity, ransomware indicators, insider risk signals).
  • Coordinate evidence collection and preservation to support legal/compliance needs and potential third-party investigations.
  • Enrich investigations with threat intel (IOCs, TTPs) and map observed behavior to frameworks (e.g., ATT&CK) to improve detection fidelity.
  • Maintain watchlists and detection logic for priority threats relevant to cloud-first financial and digital-asset operations.
  • Tune SIEM correlation rules, EDR policies, and alert thresholds to reduce false positives and increase signal quality.
  • Propose and implement new detections for emerging techniques (identity + cloud abuse, OAuth/app consent attacks, API key leakage, CI/CD pipeline tampering).
  • Improve runbooks and automate repetitive enrichment steps (SOAR workflows, scripts, queries).
  • Provide mentorship and real-time guidance to L1 analysts; improve escalation quality through coaching and feedback.
  • Manage shift handovers for active investigations and ensure high-quality case documentation.
  • Contribute to SOC metrics (MTTD, MTTR, false-positive rate, escalation accuracy) and continuous improvement efforts.
Desired Qualifications
  • Detection engineering experience: correlation rules, Sigma/KQL/SPL, alert pipelines, SOAR automation.
  • DFIR fundamentals: triage acquisition, volatile vs. non-volatile evidence, endpoint artifact analysis.
  • Container/Kubernetes logging and runtime security exposure.
  • Practical scripting (Python/Bash) for analysis and automation.
  • Digital-asset ecosystem exposure and 24/7 trading operations familiarity.
  • Certifications (optional): GCIH, GCIA, GCED, SC-200, AWS Security Specialty, or equivalent.

Keyrock provides liquidity solutions for digital asset markets by using algorithmic trading and market making on both centralized and decentralized exchanges. Its tech places buy and sell orders automatically to tighten spreads and improve market liquidity, serving B2B clients such as crypto exchanges and blockchain projects. The system works by running proprietary algorithms that continuously quote prices and trade sizes, aiming to offer the best prices while minimizing market impact. Keyrock differentiates itself by operating across multiple venue types (CEXs and DEXs) and focusing on liquidity provision for its clients rather than just executing trades for themselves, enabling partners to run more efficient, better-funded markets. The company’s goal is to enable more liquid and efficient digital asset markets and to generate revenue by charging fees based on trading volume or assets under management, reflecting the value it adds to client ecosystems.

Company Size

201-500

Company Stage

Series B

Total Funding

$77.7M

Headquarters

City of Brussels, Belgium

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Series C funding from SC Ventures values Keyrock at $1.1B as of 2026.
  • Grown from 3 to 170+ employees since 2017 across 36 countries.
  • Launched US entity in 2026 to expand global digital asset services.

What critics are saying

  • Wintermute captures Keyrock's institutional clients on 100+ exchanges within 6-12 months.
  • SEC enforces against wash trading, suspending Keyrock on Binance and slashing 40% volume in 3-9 months.
  • Ripple launches in-house market making for XRP partners, reclaiming clients in 6-12 months.

What makes Keyrock unique

  • Keyrock integrates market making, OTC, options, and asset management across 80+ exchanges.
  • Acquired Fija Finance in 2026 to add DeFi yield vaults via smart contracts.
  • Acquired Turing Capital for $27.8M, launching institutional asset management division.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Keyrock who can refer or advise you

Benefits

Flexible Work Hours

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

-1%
Keyrock
Mar 31st, 2026
Keyrock Secures Series C Funding From SC Ventures - Keyrock

Keyrock has secured Series C funding led by SC Ventures, valuing the company at $1.1B

Munich Startup
Feb 24th, 2026
Keyrock acquires Munich fintech Fija Finance after 2023 seed investment

Keyrock has acquired Munich-based fintech startup Fija Finance, following a 2023 seed investment and accelerator programme participation. Fija Finance specialises in providing financial institutions with technology to generate yields from cryptocurrency holdings through decentralised finance strategies. The acquisition centres on Fija Finance's vault technology, which uses smart-contract-based capital pools to automatically manage digital assets according to defined strategies. The Munich startup's infrastructure will be integrated into Keyrock's core business, giving it access to a larger customer base and additional regulatory infrastructure. Fija Finance CEO Christoph Scholze said the merger would enable the company to scale its technology within a strong digital asset liquidity provider. Financial terms and details about the Munich location's future were not disclosed.

The Cryptonomist
Oct 9th, 2025
Rhuna Raises $2M to Revolutionize Entertainment

Rhuna, a platform revolutionizing payments in entertainment, closed a $2 million seed funding round led by Aptos Labs with investors like Acc Ventures and CoinMarketCap Labs. Rhuna supports wallet-native payments and identity management, processing over $90 million for 2 million users. It has been used in 165 events, including UNTOLD. The funding will enhance its infrastructure and expand globally, focusing on Asia, Europe, and North America.

Phemex
Sep 17th, 2025
Keyrock Acquires Turing Capital for $27.8 Million | Phemex News

Keyrock acquires Turing Capital for $27.8M, expanding into asset management. CEO Jorge Schnura to lead new division, enhancing services for institutional c

ZyCrypto
Jun 18th, 2025
Bitvault Secures $2M From GSR, Gemini, And Auros To Power Bitcoin-Backed Stablecoin Ecosystem

BitVault, a pioneering DeFi protocol offering Bitcoin-backed infrastructure, has raised $2 million in a pre-seed funding round.