SOC Engineer (Incident Response)

BinanceSingaporeOn-siteFull-timeMid level, 2–5 yearsListed 3 months ago

Apply now

About this role

We’re looking for a security engineer with hands-on experience in Data Loss Prevention (DLP) and incident response, ideally within fintech, crypto, or high-security environments. The role goes beyond using commercial tools you’ll also design and build custom solutions, leverage automation, and adapt to emerging threats, including those driven by recent LLM/AI advancements.

Responsibilities

- Design, deploy, and optimize DLP solutions across network, endpoint, and cloud.

- Build and refine data classification schemes for sensitive assets (wallets, trading algorithms, customer PII).

- Configure DLP policies to prevent data exfiltration while minimizing false positives.

- Monitor, analyze, and tune alerts and incidents for continuous improvement.

- Lead investigations of DLP incidents and insider threats,

- Conduct threat hunting and forensic analysis of data exfiltration attempts.

- Integrate DLP monitoring into broader SOC workflows and incident response playbooks.

- Build custom DLP tools and integrations (e.g., macOS Swift endpoint protection, Unix socket monitoring).

- Develop automation scripts, APIs, regexes and integrations to enhance detection and response.

- Explore AI/LLM-driven methods for anomaly detection and response efficiency.

- Ensure controls align with crypto and financial regulations (AML, KYC, GDPR, CCPA).

- Support audits and regulatory reviews related to data protection.

- Assess and mitigate data loss risks across trading platforms, onboarding systems, and blockchain infrastructure.

Requirements

- 4+ years in a SOC or security operations role with incident response focus.

- Proven experience with DLP design, deployment, and monitoring.

- Strong programming skills (macOS Swift, Unix socket programming, scripting).

- Hands-on threat hunting, forensic analysis, and APT detection experience.

- Familiarity with SIEM, EDR, and cloud security architectures.

- Knowledge of encryption, tokenization, and data classification methods.

Nice-to-have

- 4+ years in a SOC or security operations role with incident response focus.

- Proven experience with DLP design, deployment, and monitoring.

- Strong programming skills (macOS Swift, Unix socket programming, scripting).

- Hands-on threat hunting, forensic analysis, and APT detection experience.

- Familiarity with SIEM, EDR, and cloud security architectures.

- Knowledge of encryption, tokenization, and data classification methods.

Why Binance
• Shape the future with the world’s leading blockchain ecosystem
• Collaborate with world-class talent in a user-centric global organization with a flat structure
• Tackle unique, fast-paced projects with autonomy in an innovative environment
• Thrive in a results-driven workplace with opportunities for career growth and continuous learning
• Competitive salary and company benefits
• Work-from-home arrangement (the arrangement may vary depending on the work nature of the business team)

Binance is committed to being an equal opportunity employer. We believe that having a diverse workforce is fundamental to our success.
By submitting a job application, you confirm that you have read and agree to our Candidate Privacy Notice.