Verified current Job

SOC Engineer (Incident Response & Python Automation)

Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. We are trusted by 300+ million people in

Job Remote Full source details
Binance Taipei, Asia · Taiwan, Taipei, Hong Kong, UAE, Abu Dhabi Source published Jun 1, 2026 Verified 7 hours ago
✓ 100% verification score · Source: Api Lever Co Opportunities · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull-time: Remote
Work modeRemote / location-flexible

Overview

Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. We are trusted by 300+ million people in

Full job description

Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. We are trusted by 300+ million people in 100+ countries for our industry-leading security, user fund transparency, trading engine speed, deep liquidity, and an unmatched portfolio of digital-asset products. Binance offerings range from trading and finance to education, research, payments, institutional services, Web3 features, and more. We leverage the power of digital assets and blockchain to build an inclusive financial ecosystem to advance the freedom of money and improve financial access for people around the world.

Design, develop, and maintain SOC security platforms and tooling, with a primary focus on SIEM, SOAR, and security automation. Develop Python-based services, scripts, automation workflows, and security integrations with SIEM, EDR, AWS, and internal security platforms. Build and maintain AWS-based security services and integrations, including EC2, S3, Lambda, IAM, and CloudWatch. Support SIEM operations and detection engineering, including log ingestion, parsing, normalization, correlation, and detection rule development. Develop detection use cases and common security threat models, based on attack scenarios and real-world security incidents. Participate in SOC on-call rotation and incident response, including alert triage, investigation, containment, and post-incident analysis. Work with SOC analysts and security teams to improve security automation, detection coverage, and platform capabilities.

Hands-on Python development experience is required. Experience with Golang or Java is a plus. Hands-on experience with AWS, particularly EC2, S3, Lambda, IAM, and CloudWatch. Experience developing production-quality services, automation, APIs, or internal security tools. Practical experience using SIEM platforms for security monitoring, log analysis, and alert investigation. Good understanding of SOC operations and Incident Response (IR), including alert triage and security incident investigation. Understanding of common security threats and experience developing security detections / threat models / SIEM use cases. Familiarity with EDR, security telemetry, REST APIs, Git, Docker, and Linux. Strong problem-solving, troubleshooting, and communication skills.

4+ years in a SOC or security operations role with incident response focus. Proven experience with DLP design, deployment, and monitoring. Strong programming skills (macOS Swift, Unix socket programming, scripting). Hands-on threat hunting, forensic analysis, and APT detection experience. Familiarity with SIEM, EDR, and cloud security architectures. Knowledge of encryption, tokenization, and data classification methods.

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v3

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Api Lever Co Opportunities ↗

Browse current Job and Scholarship listings from Api Lever Co Opportunities →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books