SOC Engineer (Incident Response)

    Asia && Taiwan, Taipei && Hong Kong
    Full-Time
    Mid (3-6 yrs)
    Engineering & Development
    Posted on June 1, 2026
    We’re looking for a security engineer with hands-on experience in Data Loss Prevention (DLP) and incident response, ideally within fintech, crypto, or high-security environments. The role goes beyond using commercial tools you’ll also design and build custom solutions, leverage automation, and adapt to emerging threats, including those driven by recent LLM/AI advancements.
    Responsibilities
  1. Design, develop, and maintain security automation and SOC tooling, including integrations with SIEM, EDR, cloud services, and internal security platforms
  2. Develop services, scripts, and pipelines to automate alert enrichment, correlation, response, and investigation workflows
  3. Build and maintain API-based integrations with security tools, AWS services, and internal systems
  4. Support and enhance SIEM platforms for ingestion, alerting, and investigation
  5. Participate in security detection engineering, including log parsing, data normalization, and detection logic implementation
  6. Assist in security incident response, including triage, investigation, containment, eradication, and post-incident analysis
  7. Take part in SOC on-call rotation / shift duty, responding to security alerts and incidents as required
  8. Work closely with SOC analysts to translate operational needs into scalable engineering solutions, debug, troubleshoot, and optimize existing security automation, CI/CD pipelines, and platform components etc.
  9. Requirements
  10. 4+ years in a SOC or security operations role with incident response focus.
  11. Proven experience with DLP design, deployment, and monitoring.
  12. Strong programming skills (macOS Swift, Unix socket programming, scripting).
  13. Hands-on threat hunting, forensic analysis, and APT detection experience.
  14. Familiarity with SIEM, EDR, and cloud security architectures.
  15. Knowledge of encryption, tokenization, and data classification methods.
  16. Nice-to-have
  17. 4+ years in a SOC or security operations role with incident response focus.
  18. Proven experience with DLP design, deployment, and monitoring.
  19. Strong programming skills (macOS Swift, Unix socket programming, scripting).
  20. Hands-on threat hunting, forensic analysis, and APT detection experience.
  21. Familiarity with SIEM, EDR, and cloud security architectures.
  22. Knowledge of encryption, tokenization, and data classification methods.
  23. Company:  Binance

    Operates the world's largest cryptocurrency exchange, offering trading, staking, and blockchain ecosystem services to 270M+ users globally.
    5001-10000 employees
    Finance & Fintech
    HQ: None (Global)