Binance
AI

DLP Incident Response Engineer

Binance · Argentina, Buenos Aires · $126k - $156k

Actively hiring Posted 6 months ago
Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. We are trusted by over 280 million people in 100+ countries for our industry-leading security, user fund transparency, trading engine speed, deep liquidity, and an unmatched portfolio of digital-asset products. Binance offerings range from trading and finance to education, research, payments, institutional services, Web3 features, and more. We leverage the power of digital assets and blockchain to build an inclusive financial ecosystem to advance the freedom of money and improve financial access for people around the world.

We’re looking for a security engineer with hands-on experience in Data Loss Prevention (DLP) and incident response, ideally within fintech, crypto, or high-security environments. The role goes beyond using commercial tools you’ll also design and build custom solutions, leverage automation, and adapt to emerging threats, including those driven by recent LLM/AI advancements.

Responsibilities

    • Design, deploy, and optimize DLP solutions across network, endpoint, and cloud.
    • Build and refine data classification schemes for sensitive assets (wallets, trading algorithms, customer PII).
    • Configure DLP policies to prevent data exfiltration while minimizing false positives.
    • Monitor, analyze, and tune alerts and incidents for continuous improvement.
    • Lead investigations of DLP incidents and insider threats, 
    • Conduct threat hunting and forensic analysis of data exfiltration attempts.
    • Integrate DLP monitoring into broader SOC workflows and incident response playbooks.
    • Build custom DLP tools and integrations (e.g., macOS Swift endpoint protection, Unix socket monitoring).
    • Develop automation scripts, APIs, regexes and integrations to enhance detection and response.
    • Explore AI/LLM-driven methods for anomaly detection and response efficiency.
    • Ensure controls align with crypto and financial regulations (AML, KYC, GDPR, CCPA).
    • Support audits and regulatory reviews related to data protection.
    • Assess and mitigate data loss risks across trading platforms, onboarding systems, and blockchain infrastructure.

Requirements

    • 4+ years in a SOC or security operations role with incident response focus.
    • Proven experience with DLP design, deployment, and monitoring.
    • Strong programming skills (macOS Swift, Unix socket programming, scripting).
    • Hands-on threat hunting, forensic analysis, and APT detection experience.
    • Familiarity with SIEM, EDR, and cloud security architectures.
    • Knowledge of encryption, tokenization, and data classification methods.

Nice-to-have

    • 4+ years in a SOC or security operations role with incident response focus.
    • Proven experience with DLP design, deployment, and monitoring.
    • Strong programming skills (macOS Swift, Unix socket programming, scripting).
    • Hands-on threat hunting, forensic analysis, and APT detection experience.
    • Familiarity with SIEM, EDR, and cloud security architectures.
    • Knowledge of encryption, tokenization, and data classification methods.
Why Binance
• Shape the future with the world’s leading blockchain ecosystem
• Collaborate with world-class talent in a user-centric global organization with a flat structure
• Tackle unique, fast-paced projects with autonomy in an innovative environment
• Thrive in a results-driven workplace with opportunities for career growth and continuous learning
• Competitive salary and company benefits
• Work-from-home arrangement (the arrangement may vary depending on the work nature of the business team)

Binance is committed to being an equal opportunity employer. We believe that having a diverse workforce is fundamental to our success.
By submitting a job application, you confirm that you have read and agree to our Candidate Privacy Notice.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Tags & focus areas

Used for matching and alerts on DevFound
Engineer Blockchain Crypto
Common Questions

Frequently asked questions

Quick answers about how DevFound's AI matching, resumes, and referrals work.

DevFound's AI Copilot ingests your profile, goals, and live job data to deliver curated matches in seconds. Every match includes a resume variant, suggested referrals, and interview prep so you can act immediately. The more feedback you provide, the sharper the Copilot becomes.

AI-led job searches shrink the hours spent sifting through boards and formatting resumes. DevFound pairs automation with your personal outreach, so you reserve energy for interviews and negotiation. Traditional networking still matters, but AI gives you a lift before you even send a message.

Modern AI roles expect comfort with production-grade code, data fluency, and practical ML tooling. The strongest candidates pair deep technical chops with storytelling—translating model impact to product, GTM, and exec partners. Continuous learning keeps you ahead as stacks evolve.

DevFound rewards active seekers. Keep your profile fresh, respond to match quality prompts, and enable alerts so you never miss a role. The AI prioritizes companies and teams that align with your feedback, accelerating both introductions and interview invites.

High-density tech hubs continue to host the deepest AI talent pools, yet distributed teams are catching up fast. Use DevFound filters to hone in on onsite, hybrid, or fully remote roles and watch openings expand across time zones.

DevFound aggregates thousands of remote AI openings and flags the nuances—core hours, async culture, and visa needs—up front. The Copilot also recommends how to position your distributed work experience so hiring managers know you can thrive on a remote team.