WorkaemКарьерная платформа
  • Вакансии
  • Компании
  • Зарплаты
  • Что спрашивают
  • Сервисы
  • Блог
  • Работодателям
Workaem

Карьерная платформа для IT-специалистов: вакансии напрямую с карьерных страниц 300+ компаний, из телеграм-каналов, с международных площадок и от работодателей напрямую. Разбор условий, детектор мёртвых вакансий, AI-инструменты для резюме. Базовые функции бесплатны.

Подпишись, присылаем лучшие вакансии недели
Или читай канал в телеграме
Соискателям
Все вакансииЗа границейУдалёнка в долларахКомпании с РУ основателямиЗарплатыОфферыВозможностиСоветыСоздать резюмеТренировка интервью
По технологиям
Вакансии PythonВакансии JavaScriptВакансии ReactВакансии JavaВакансии GoВакансии Docker
По профессиям
РазработкаДизайнQA / ТестированиеАналитикаProduct / Project ManagerМаркетинг
Работодателям
Разместить вакансиюТарифыБаза кандидатовСвязаться с нами
Кабинет
РегистрацияВойтиЛичный кабинетМои откликиСохранённыеУведомления
Компания
О проектеПредложенияКонтактыБлогКонфиденциальностьУсловия использования
© 2026 Workaem. Все права защищены.КонфиденциальностьУсловияОферта
Made by IT, for IT 💛
Staff Engineer, Security Platform Development
ВердиктОписаниеИнструментыКомпания
  1. Главная
  2. /
  3. Вакансии
  4. /
  5. Staff Engineer, Security Platform Development

Okx·Hong Kong, Hong Kong SAR; Singapore, Singapore·4 авг.

Staff Engineer, Security Platform Development

🏢 ОфисSeniorПолная занятость
Зарплата не указана
Вилки нет, про деньги придётся договариваться с нуля.
Нажмите на сигнал, чтобы увидеть, на чём он основан

Наша компания

At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom. OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves. Across our multiple offices globally, we are united by our core principles: We Before Me, Do the Right Thing, and Get Things Done. These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er. OKX is part of OKG, a group that brings the value of Blockchain to users around the world, through our leading products OKX, OKX Wallet, OKLink and more.

Чем предстоит заниматься

As a Staff Engineer, you'll own the build-out of our security engineering and DevSecOps capabilities: designing and developing the security products, platform services, and SDKs/Agents that embed protection directly into how code is written, built, shipped, and run
This is a role for someone with real depth in security, broad coverage across the stack, and the engineering muscle to ship. Just as important is the ability to drive adoption — security that lands in complex, fast-moving business environments rather than sitting in a policy document
Architect and build our end-to-end DevSecOps platform and the SDKs/Agents behind our security products, covering code, build, artifacts, images, deployment, and runtime
Lead runtime protection through RASP and Java Agent — bytecode instrumentation, runtime hooking, and detection/interception engines using ASM, ByteBuddy, and Instrumentation, with continuous tuning for performance, stability, and compatibility
Integrate and productise scanning capabilities across SAST, DAST, IAST, SCA, code scanning, and image scanning. You'll embed tools like SonarQube and Coverity deep into CI/CD and close the loop from detection through blocking, remediation, and re-test
Go deep on application security offence and defence — designing detection, remediation, hardening, and counter-measures for XSS, SQL injection, SSRF, deserialisation, command execution, authentication/authorisation flaws, and API security
Bring AI-native security engineering to life. Apply LLMs and AI Agents to vulnerability analysis, rule generation, false-positive attribution, remediation guidance, security knowledge capture, and engineering automation — and build a coherent view of the architecture, mechanics, and security implications
Embed as the security technical expert inside engineering teams, driving security standards, onboarding specifications, release gates, risk tiering, and remediation mechanisms that measurably lift the security baseline and delivery quality
Partner across engineering, architecture, SRE, QA, and business teams on priority projects, solving the genuinely hard security problems and turning the solutions into reusable platform capability and repeatable practice

Наши требования

Strong computer science and security fundamentals — deep understanding of operating systems, networking, compilers and the JVM, distributed systems, application security, cloud-native security, and supply chain security. Both breadth and depth
Expert-level Java, with hands-on depth in the JVM, ClassLoader, Java Agent, ASM, ByteBuddy, bytecode instrumentation, and performance profiling and tuning. Plus working proficiency in Python or Go
Substantial production experience with RASP, SAST, DAST, IAST, SCA, image security, and code scanning — enough to design a capability, integrate the engine, build the platform around it, and take it to scale independently
Real offensive and defensive experience. You understand the root causes, exploitation paths, detection logic, bypass techniques, and fixes for common web, API, and microservices vulnerabilities — and can design from both the attacker's and defender's point of view
Fluency with LLMs and AI Agents, including a considered view on model capability limits, agent architecture, tool calling, context engineering, evaluation methods, and how AI is reshaping both security engineering and the attack surface
Strong engineering execution paired with product instinct — able to lead the design and delivery of security products, platform modules, and SDKs/Agents while balancing security outcomes against performance overhead, integration cost, and long-term operability
Exceptional ownership, cross-team communication, and the persistence to move security governance, rule enforcement, and remediation through to a clear result
Security engineering experience at a top-tier internet company, cloud provider, or leading security vendor
You've led the build of a DevSecOps platform, application security platform, RASP, code scanning platform, or cloud-native security platform
Background in security product development, SDK/Agent engineering, vulnerability research, red team exercises, or purple team work
Shipped AI + Security work — security copilots, intelligent rule generation, automated analysis, or remediation recommendation systems

Мы предлагаем

Competitive total compensation package
L&D programs and Education subsidy for employees' growth and development
Various team building programs and company events
Wellness and meal allowances
Comprehensive healthcare schemes for employees and dependants
More that we love to tell you along the process!

Дополнительно

All official OKX vacancies are published on this website. While roles may appear on selected third-party platforms from time to time, information on other sites may be inaccurate or outdated. If in doubt, please apply directly through our official careers website
Information collected and processed as part of the recruitment process of any job application you choose to submit is subject to OKX's Candidate Privacy Notice
O
Okx
Hong Kong, Hong Kong SAR; Singapore, Singapore

ГрейдSenior
ЗанятостьПолная занятость
РегионСингапур
ФорматОфис
ИсточникСкрыто
Опубликовано4 авг.
Все вакансии компании

AI-помощник

под эту вакансию
Войди, чтобы AI оценил твоё соответствие вакансии и написал сопроводительное письмо
Мы против мошенников на площадке: если тебя просят заплатить, продиктовать код или установить непонятное приложение, прекращай общение и сразу пиши нам (чат с основателем или форма обратной связи).