Stop applying to jobs that are already dead.
Every listing verified, aged honestly, expired when filled.

All listings

Binance via Lever

SOC Engineer (Incident Response & Python Automation)

Level not stated Asia
still open verified 1d ago posted 106d ago checked just now
Apply at jobs.lever.co

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 1d ago — checked against the employer's own applicant tracking system, which is the company answering directly.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 106d ago

The date the source published, not the day we noticed it (2026-06-01). Last seen at its source just now.

Is it remote?

Marked remote on the employer's board

Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.

Who may apply?

Asia

The description states no restriction of its own. This is the source's own tag.

Pay not stated

Similar roles pay A$2,062–3,050/mo

Middle 50% of 11 listings that do state pay — Engineering · all levels · Asia · AUD/month. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.

Skills named in the ad

AWSDockerGitGoIncident ManagementJavaLinuxPythonRESTSIEMTroubleshooting

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. We are trusted by 300+ million people in 100+ countries for our industry-leading security, user fund transparency, trading engine speed, deep liquidity, and an unmatched portfolio of digital-asset products. Binance offerings range from trading and finance to education, research, payments, institutional services, Web3 features, and more. We leverage the power of digital assets and blockchain to build an inclusive financial ecosystem to advance the freedom of money and improve financial access for people around the world.

Responsibilities

  • Design, develop, and maintain SOC security platforms and tooling, with a primary focus on SIEM, SOAR, and security automation.
  • Develop Python-based services, scripts, automation workflows, and security integrations with SIEM, EDR, AWS, and internal security platforms.
  • Build and maintain AWS-based security services and integrations, including EC2, S3, Lambda, IAM, and CloudWatch.
  • Support SIEM operations and detection engineering, including log ingestion, parsing, normalization, correlation, and detection rule development.
  • Develop detection use cases and common security threat models, based on attack scenarios and real-world security incidents.
  • Participate in SOC on-call rotation and incident response, including alert triage, investigation, containment, and post-incident analysis.
  • Work with SOC analysts and security teams to improve security automation, detection coverage, and platform capabilities.
  • Requirements

  • Hands-on Python development experience is required. Experience with Golang or Java is a plus.
  • Hands-on experience with AWS, particularly EC2, S3, Lambda, IAM, and CloudWatch.
  • Experience developing production-quality services, automation, APIs, or internal security tools.
  • Practical experience using SIEM platforms for security monitoring, log analysis, and alert investigation.
  • Good understanding of SOC operations and Incident Response (IR), including alert triage and security incident investigation.
  • Understanding of common security threats and experience developing security detections / threat models / SIEM use cases.
  • Familiarity with EDR, security telemetry, REST APIs, Git, Docker, and Linux.
  • Strong problem-solving, troubleshooting, and communication skills.
  • Nice-to-have

  • 4+ years in a SOC or security operations role with incident response focus.
  • Proven experience with DLP design, deployment, and monitoring.
  • Strong programming skills (macOS Swift, Unix socket programming, scripting).
  • Hands-on threat hunting, forensic analysis, and APT detection experience.
  • Familiarity with SIEM, EDR, and cloud security architectures.
  • Knowledge of encryption, tokenization, and data classification methods.
  • Why Binance
    • Shape the future with the world’s leading blockchain ecosystem
    • Collaborate with world-class talent in a user-centric global organization with a flat structure
    • Tackle unique, fast-paced projects with autonomy in an innovative environment
    • Thrive in a results-driven workplace with opportunities for career growth and continuous learning
    • Competitive salary and company benefits
    • Work-from-home arrangement (the arrangement may vary depending on the work nature of the business team)

    Binance is committed to being an equal opportunity employer. We believe that having a diverse workforce is fundamental to our success.
    By submitting a job application, you confirm that you have read and agree to our Candidate Privacy Notice.
    Apply at jobs.lever.co