SOC Engineer (Incident Response)
- Binance seeks a talented security engineer experienced in Data Loss Prevention (DLP) and incident response, with a preference for backgrounds in fintech, crypto, or high-security environments. The role requires creativity in developing custom solutions, utilizing automation, and adapting defenses against evolving threats including those influenced by recent advancements in AI/DDoS technology.
Responsibilities:
- Design, implement, and refine DLP solutions spanning network, endpoint, and cloud platforms.
- Develop data classification frameworks for safeguarding sensitive assets such as wallets, trading algorithms, and customer PII.
- Create and manage DLP policies to hinder data exfiltration while minimizing false-positive alerts.
- Monitor, analyze, and refine alerts and incidents for ongoing enhancement.
- Take the lead in investigating DLP incidents and insider threats; proactively engage in threat hunting and forensic analysis of data breaches.
- Integrate DLP monitoring into broader SOC operations and incident handling procedures.
- Contribute to building customized DLP tools and integrations, like macOS Swift endpoint protection and Unix socket monitoring.
- Craft automation scripts, APIs, regexes, and integrations to bolster detection and response capabilities.
- Explore advanced AI/ML-driven methodologies for anomaly detection and response streamlining.
- Ensure compliance with crypto and financial regulations such as AML, KYC, GDPR, and CCPA.
- Support scrutinies and regulatory assessments pertaining to data security.
- Identify and mitigate data loss risks across various systems including trading platforms, onboarding systems, and blockchain infrastructures.
Requirements:
- Minimum of 4 years in a SOC or security operations role with a focus on incident response.
- Demonstrated experience in DLP design, implementation, and monitoring.
- Proficient in programming languages (e.g., macOS Swift, Unix socket, scripting).
- Proven hands-on experience in threat discovery, forensic analysis, and APT detection.
- Familiarity with SIEM, EDR, and cloud security architectures.
- Knowledge of encryption, tokenization, and data classification methodologies.
Nice-to-have:
4+ years of experience in a SOC or security operations role emphasizing incident response.
Demonstrated expertise in designing, deploying, and monitoring DLP solutions.
Proficiency in programming languages such as macOS Swift and Unix socket programming.
Hands-on experience in threat hunting, forensic analysis, and APT detection.
Familiarity with SIEM, EDR, and cloud security frameworks.
Knowledge of encryption, tokenization, and data classification techniques.
Join Binance for the opportunity to shape the future within the leading blockchain ecosystem, collaborate with exceptional talents globally in a user-centric organization, tackle stimulating and fast-paced projects in an innovative environment, thrive in a results-driven workplace with room for career growth and continuous learning, competitive compensation, and benefits, as well as a work-from-home arrangement (subject to business team requirements fluctuations). Binance upholds equal employment practices, recognizing diversity as integral to its success. Upon application submission, applicants acknowledge and consent to the Candidate Privacy Notice. Binance may use AI tools for segments of the hiring process but final hiring decisions are made by humans, contact for further processing information.
