2 months ago
Hong Kong, Hong Kong or Singapore, SingaporeStaff+
Responsibilities
- Architect and build an end-to-end DevSecOps platform and the SDKs and agents supporting security products across code, builds, artifacts, images, deployment, and runtime.
- Lead runtime protection using RASP and Java Agents, including bytecode instrumentation, runtime hooking, detection, interception, performance tuning, stability, and compatibility.
- Integrate SonarQube, Coverity, and other scanning capabilities across SAST, DAST, IAST, SCA, code scanning, and image scanning, connecting detection to blocking, remediation, and retesting.
- Design application security detection, remediation, hardening, and countermeasures for XSS, SQL injection, SSRF, deserialization, command execution, authentication and authorization flaws, and API security issues.
- Apply LLMs and AI Agents to vulnerability analysis, rule generation, false-positive attribution, remediation guidance, security knowledge capture, and engineering automation.
- Embed as a security technical expert within engineering teams by establishing security standards, onboarding specifications, release gates, risk tiers, and remediation mechanisms.
- Partner with engineering, architecture, SRE, QA, and business teams to solve complex security problems and turn solutions into reusable platform capabilities.
Requirements
- Strong computer science and security fundamentals across operating systems, networking, compilers, the JVM, distributed systems, application security, cloud-native security, and supply chain security.
- Expert-level Java experience with the JVM, ClassLoader, Java Agent, ASM, ByteBuddy, bytecode instrumentation, performance profiling, and tuning.
- Working proficiency in Python or Go.
- Production experience designing and scaling RASP, SAST, DAST, IAST, SCA, image security, and code-scanning capabilities.
- Offensive and defensive experience with web, API, and microservices vulnerabilities, including detection, exploitation, bypasses, and remediation.
- Fluency with LLMs and AI Agents, including agent architecture, tool calling, context engineering, evaluation methods, and model limitations.
- Ability to lead security product, platform, SDK, and agent design and delivery while balancing security outcomes, performance, integration cost, and operability.
- Strong ownership, cross-team communication, and persistence in driving security governance, enforcement, and remediation.
- Preferred experience at a top-tier internet company, cloud provider, or security vendor.
- Preferred experience building DevSecOps, application security, RASP, code-scanning, or cloud-native security platforms.
- Background in security product development, SDK or agent engineering, vulnerability research, red-team exercises, or purple-team work is preferred.
- Preferred experience shipping AI and security products such as security copilots, intelligent rule generation, automated analysis, or remediation recommendation systems.
Benefits
- Learning and development programs and an education subsidy.
- Team-building programs and company events.
- Wellness and meal allowances.
- Comprehensive healthcare coverage for employees and dependants.
- Competitive total compensation package.
About OKX
OKX builds a global cryptocurrency exchange and Web3 wallet used by retail and institutional traders for spot, derivatives, and DeFi access, with developer APIs. Its business model centers on trading and financing fees, plus wallet and on-chain services. Founded in 2017 and privately held, OKX publishes monthly proof-of-reserves and operates as part of the OKG group serving crypto markets worldwide.
