Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. We are trusted by 300+ million people in 100+ countries for our industry-leading security, user fund transparency, trading engine speed, deep liquidity, and an unmatched portfolio of digital-asset products. Binance offerings range from trading and finance to education, research, payments, institutional services, Web3 features, and more. We leverage the power of digital assets and blockchain to build an inclusive financial ecosystem to advance the freedom of money and improve financial access for people around the world.We’re looking for a security engineer with hands-on experience in Data Loss Prevention (DLP) and incident response, ideally within fintech, crypto, or high-security environments. The role goes beyond using commercial tools you’ll also design and build custom solutions, leverage automation, and adapt to emerging threats, including those driven by recent LLM/AI advancements.
Responsibilities
- Design, deploy, and optimize DLP solutions across network, endpoint, and cloud.
- Build and refine data classification schemes for sensitive assets (wallets, trading algorithms, customer PII).
- Configure DLP policies to prevent data exfiltration while minimizing false positives.
- Monitor, analyze, and tune alerts and incidents for continuous improvement.
- Lead investigations of DLP incidents and insider threats,Â
- Conduct threat hunting and forensic analysis of data exfiltration attempts.
- Integrate DLP monitoring into broader SOC workflows and incident response playbooks.
- Build custom DLP tools and integrations (e.g., macOS Swift endpoint protection, Unix socket monitoring).
- Develop automation scripts, APIs, regexes and integrations to enhance detection and response.
- Explore AI/LLM-driven methods for anomaly detection and response efficiency.
- Ensure controls align with crypto and financial regulations (AML, KYC, GDPR, CCPA).
- Support audits and regulatory reviews related to data protection.
- Assess and mitigate data loss risks across trading platforms, onboarding systems, and blockchain infrastructure.
Requirements
- 4+ years in a SOC or security operations role with incident response focus.
- Proven experience with DLP design, deployment, and monitoring.
- Strong programming skills (macOS Swift, Unix socket programming, scripting).
- Hands-on threat hunting, forensic analysis, and APT detection experience.
- Familiarity with SIEM, EDR, and cloud security architectures.
- Knowledge of encryption, tokenization, and data classification methods.
Nice-to-have
- 4+ years in a SOC or security operations role with incident response focus.
- Proven experience with DLP design, deployment, and monitoring.
- Strong programming skills (macOS Swift, Unix socket programming, scripting).
- Hands-on threat hunting, forensic analysis, and APT detection experience.
- Familiarity with SIEM, EDR, and cloud security architectures.
- Knowledge of encryption, tokenization, and data classification methods.
Listed in: Crypto Jobs, Full Time Web3 Jobs, Developer Crypto Jobs, Research Crypto Jobs, Trading Crypto Jobs, Exchange Web3 Jobs.
Let employer know that you found this job on CryptoJobsList. This helps us get more companies to post web3 jobs here!
SOC Engineer (Incident Response) at Binance: FAQ
Where is the SOC Engineer (Incident Response) role at Binance based?
The SOC Engineer (Incident Response) role at Binance is based in Taiwan, Taipei / Hong Kong / Asia. Check the job description for any remote or hybrid options.
What skills are required for the SOC Engineer (Incident Response) role at Binance?
This SOC Engineer (Incident Response) role is associated with the following skills and technologies:
- Full Time
- Developer
- Research
- Trading
- Exchange
Read the full job description above for the complete list of requirements.
Is the SOC Engineer (Incident Response) role at Binance full-time or contract?
Binance is hiring this SOC Engineer (Incident Response) as a full time position.
How do I apply for the SOC Engineer (Incident Response) role at Binance?
You can apply for the SOC Engineer (Incident Response) role at Binance directly on this page using the Apply button. Taiwan, Taipei / Hong Kong / Asia candidates are welcome. Applications submitted through CryptoJobsList reach the employer directly.
