DLP & Incident Response Engineer
Binance, a prominent global blockchain ecosystem known for its role as the world's largest cryptocurrency exchange, is seeking a security engineer proficient in Data Loss Prevention (DLP) and incident response, particularly in fintech, crypto, or high-security sectors. This role involves creating and implementing custom solutions, utilizing automation, and staying ahead of emerging threats like those stemming from recent AI advancements.
Roles and Responsibilities
- Design, implement, and optimize DLP solutions spanning network, endpoint, and cloud environments.
- Develop and enhance data classification systems for sensitive assets such as wallets, trading algorithms, and customer PII.
- Create effective DLP policies to prevent data breaches while minimizing false positives.
- Monitor, analyze, and improve alerts and incident responses continually.
- Lead investigations into DLP incidents and insider threats.
- Engage in threat hunting and forensic analysis of data exfiltration attempts.
- Incorporate DLP monitoring into broader SOC workflows and incident response strategies.
- Develop custom DLP tools and integrations like macOS Swift endpoint protection and Unix socket monitoring.
- Craft automation scripts, APIs, regexes, and integrations to bolster detection and response capabilities.
- Research AI-based methods for anomaly detection and response efficiency.
- Ensure compliance with crypto and financial regulations like AML, KYC, GDPR, and CCPA.
- Support audits and regulatory evaluations relating to data security.
- Evaluate and address data loss risks throughout trading platforms, onboarding systems, and blockchain infrastructure.
Requirements
- Minimum of 4 years in a SOC or security operations role focusing on incident response.
- Demonstrated expertise in DLP design, implementation, and monitoring.
- Proficient in programming languages like macOS Swift, Unix socket programming, and scripting.
- Hands-on experience in threat hunting, forensic analysis, and APT detection.
- Familiarity with SIEM, EDR, and cloud security infrastructures.
- Understanding of encryption, tokenization, and data classification methodologies.
Nice-to-Have
- Over 4 years in a SOC or security operations role centered on incident response.
- Established background in DLP design, deployment, and monitoring.
- Strong programming skills in macOS Swift, Unix socket programming, and scripting.
- Practical experience in threat hunting, forensic analysis, and APT detection.
- Knowledge of SIEM, EDR, and cloud security architectures.
- Familiarity with encryption, tokenization, and data classification techniques.
Binance offers a dynamic environment where you can shape the future alongside top-tier talent in a flat organizational structure. Benefit from autonomy, tackle stimulating projects, and experience a results-driven culture allowing for career growth and continuous learning. Competitive compensation and a work-from-home option add to the inclusive ethos of Binance as an equal opportunity employer.
