SOC Engineer (Incident Response)

Binance

United States

Remote

USD 120,000 - 180,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Work-from-home options
Equal opportunity employer
Career growth opportunities

Job summary

Binance is seeking a hands-on security engineer with DLP and incident response experience to design and implement scalable security tooling. The role emphasizes automation, custom solutions, and threat detection in a fintech/crypto environment.

You will work across SIEM, EDR, and cloud services, contribute to detection engineering, and participate in on-call rotations, applying data protection techniques to protect user assets.

Qualifications

  • 4+ years in a SOC or security operations role with incident response focus.
  • Proven experience with DLP design, deployment, and monitoring.
  • Strong programming skills (macOS Swift, Unix socket programming, scripting).
  • Hands-on threat hunting, forensic analysis, and APT detection experience.
  • Familiarity with SIEM, EDR, and cloud security architectures.
  • Knowledge of encryption, tokenization, and data classification methods.

Responsibilities

  • Design, develop, and maintain security automation and SOC tooling (SIEM/EDR integrations).
  • Automate alert enrichment, correlation, response, and investigations workflows.
  • Build API-based integrations with security tools and cloud platforms (AWS).
  • Support and optimize SIEM ingestion, alerting, and investigations.
  • Contribute to detection engineering: log parsing, normalization, detection logic.
  • Assist incident response: triage, containment, eradication, post-incident analysis.
  • Participate in SOC on-call rotation and incident response duties.
  • Collaborate with SOC analysts to scale engineering solutions and CI/CD pipelines.

Skills

DLP design
Incident response
Swift
Unix sockets
Scripting
Threat hunting
Forensic analysis
APT detection
SIEM
EDR
Cloud security
Data encryption
Data tokenization
Data classification

Education

Job description

Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. We are trusted by 300+ million people in 100+ countries for our industry-leading security, user fund transparency, trading engine speed, deep liquidity, and an unmatched portfolio of digital-asset products. Binance offerings range from trading and finance to education, research, payments, institutional services, Web3 features, and more. We leverage the power of digital assets and blockchain to build an inclusive financial ecosystem to advance the freedom of money and improve financial access for people around the world.

We’re looking for a security engineer with hands‑on experience in Data Loss Prevention (DLP) and incident response, ideally within fintech, crypto, or high‑security environments. The role goes beyond using commercial tools you’ll also design and build custom solutions, leverage automation, and adapt to emerging threats, including those driven by recent LLM/AI advancements.

Responsibilities
  • Design, develop, and maintain security automation and SOC tooling, including integrations with SIEM, EDR, cloud services, and internal security platforms
  • Develop services, scripts, and pipelines to automate alert enrichment, correlation, response, and investigation workflows

Build and maintain API-based integrations with security tools, AWS services, and internal systems

Support and enhance SIEM platforms for ingestion, alerting, and investigation

Participate in security detection engineering, including log parsing, data normalization, and detection logic implementation

Assist in security incident response, including triage, investigation, containment, eradication, and post-incident analysis

Take part in SOC on-call rotation / shift duty, responding to security alerts and incidents as required


Work closely with SOC analysts to translate operational needs into scalable engineering solutions, debug, troubleshoot, and optimize existing security automation, CI/CD pipelines, and platform components etc.

Requirements
  • 4+ years in a SOC or security operations role with incident response focus.
  • Proven experience with DLP design, deployment, and monitoring.
  • Strong programming skills (macOS Swift, Unix socket programming, scripting).
  • Hands‑on threat hunting, forensic analysis, and APT detection experience.
  • Familiarity with SIEM, EDR, and cloud security architectures.
  • Knowledge of encryption, tokenization, and data classification methods.
Nice-to-have
  • 4+ years in a SOC or security operations role with incident response focus.
  • Proven experience with DLP design, deployment, and monitoring.
  • Strong programming skills (macOS Swift, Unix socket programming, scripting).
  • Hands‑on threat hunting, forensic analysis, and APT detection experience.
  • Familiarity with SIEM, EDR, and cloud security architectures.
  • Knowledge of encryption, tokenization, and data classification methods.
Why Binance

Shape the future with the world’s leading blockchain ecosystem

Collaborate with world-class talent in a user-centric global organization with a flat structure

Tackle unique, fast-paced projects with autonomy in an innovative environment

Thrive in a results-driven workplace with opportunities for career growth and continuous learning

Competitive salary and company benefits

Work-from-home arrangement (the arrangement may vary depending on the work nature of the business team)

Binance is committed to being an equal opportunity employer. We believe that having a diverse workforce is fundamental to our success.

By submitting a job application, you confirm that you have read and agree to our Candidate Privacy Notice.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Security Engineer
SOC Security Engineer

Binance • United States

Remote
USD 140,000 - 210,000
Competitive salary
Work-from-home arrangement
Security Engineer — Incident Response & DLP Automation
Security Engineer — Incident Response & DLP Automation

Binance • United States

Remote
USD 120,000 - 180,000
Work-from-home options
Equal opportunity employer
Career growth opportunities
Risk Operations Agent (AMER. US Timezone) - 8-months Contract
Risk Operations Agent (AMER. US Timezone) - 8-months Contract

Binance • United States

Remote
USD 110,000 - 170,000
Data Analytics Manager (Risk/Fraud/KYC)
Data Analytics Manager (Risk/Fraud/KYC)

Binance • United States

Remote
USD 140,000 - 210,000
Work-from-home arrangement
Remote SOC Automation Engineer
Remote SOC Automation Engineer

Binance • United States

Remote
USD 140,000 - 210,000
Competitive salary
Work-from-home arrangement
Security Engineer Manager (Fully Remote)
Security Engineer Manager (Fully Remote)

Binance • United States

Remote
USD 180,000 - 240,000
Remote work
Competitive benefits
International Operations - P2P
International Operations - P2P

Crypto Pro Network • New Jersey

On-site
USD 80,000 - 120,000
P2P Growth Operations Manager (CIS)
P2P Growth Operations Manager (CIS)

Binance • United States

Remote
USD 90,000 - 135,000
Work-from-home arrangement
Binance Accelerator Program - Software Engineer (Cryptography)
Binance Accelerator Program - Software Engineer (Cryptography)

Binance • United States

Remote
USD 30,000 - 42,000
Competitive salary
Work-from-home arrangement
Company benefits
Manager / Sr. Manager, SecOps & Cyber Defense
Manager / Sr. Manager, SecOps & Cyber Defense

Bullish, Inc. • New York (NY)

On-site
USD 185,000 - 235,000