DLP & Incident Response Engineer
Binance, a prominent global blockchain ecosystem known for its role as the world's largest cryptocurrency exchange, is seeking a security engineer proficient in Data Loss Prevention (DLP) and incident response, particularly in fintech, crypto, or high-security sectors. This role involves creating and implementing custom solutions, utilizing automation, and staying ahead of emerging threats like those stemming from recent AI advancements.
Roles and Responsibilities
- Design, implement, and optimize DLP solutions spanning network, endpoint, and cloud environments.
 - Develop and enhance data classification systems for sensitive assets such as wallets, trading algorithms, and customer PII.
 - Create effective DLP policies to prevent data breaches while minimizing false positives.
 - Monitor, analyze, and improve alerts and incident responses continually.
 - Lead investigations into DLP incidents and insider threats.
 - Engage in threat hunting and forensic analysis of data exfiltration attempts.
 - Incorporate DLP monitoring into broader SOC workflows and incident response strategies.
 - Develop custom DLP tools and integrations like macOS Swift endpoint protection and Unix socket monitoring.
 - Craft automation scripts, APIs, regexes, and integrations to bolster detection and response capabilities.
 - Research AI-based methods for anomaly detection and response efficiency.
 - Ensure compliance with crypto and financial regulations like AML, KYC, GDPR, and CCPA.
 - Support audits and regulatory evaluations relating to data security.
 - Evaluate and address data loss risks throughout trading platforms, onboarding systems, and blockchain infrastructure.
 
Requirements
- Minimum of 4 years in a SOC or security operations role focusing on incident response.
 - Demonstrated expertise in DLP design, implementation, and monitoring.
 - Proficient in programming languages like macOS Swift, Unix socket programming, and scripting.
 - Hands-on experience in threat hunting, forensic analysis, and APT detection.
 - Familiarity with SIEM, EDR, and cloud security infrastructures.
 - Understanding of encryption, tokenization, and data classification methodologies.
 
Nice-to-Have
- Over 4 years in a SOC or security operations role centered on incident response.
 - Established background in DLP design, deployment, and monitoring.
 - Strong programming skills in macOS Swift, Unix socket programming, and scripting.
 - Practical experience in threat hunting, forensic analysis, and APT detection.
 - Knowledge of SIEM, EDR, and cloud security architectures.
 - Familiarity with encryption, tokenization, and data classification techniques.
 
Binance offers a dynamic environment where you can shape the future alongside top-tier talent in a flat organizational structure. Benefit from autonomy, tackle stimulating projects, and experience a results-driven culture allowing for career growth and continuous learning. Competitive compensation and a work-from-home option add to the inclusive ethos of Binance as an equal opportunity employer.

