5 months ago
Hong Kong, Hong Kong or Singapore, SingaporeMid Level
Responsibilities
- Design and implement a multi-agent code auditing engine for vulnerability detection, malicious code identification, and sensitive information leakage.
- Develop agent planning, execution, critique, tool-invocation, state-synchronization, evaluation, and iteration mechanisms using RAG and related agent technologies.
- Integrate security auditing into DevSecOps workflows through GitLab CI/CD, Tekton, and Jenkins plugins for audit-on-commit functionality.
- Build LLM application protections for prompt injection, jailbreaks, sensitive-information leakage, compliance, tool sandboxing, and anomalous behavior.
- Develop agent workflows for alert classification, contextual correlation, false-positive filtering, threat-intelligence retrieval, and SOAR integration.
- Create human-machine intervention mechanisms and agent behavior auditing to provide production observability, traceability, and intervenability aligned with OWASP Top 10 Risks for LLMs.
- Construct highly available and scalable agent services for concurrent scanning-task scheduling and fault tolerance.
- Standardize detection APIs and build rule-management, result-visualization, and false-positive-feedback systems.
Requirements
- At least three years of backend development experience with proficiency in Python, Go, or Java.
- Hands-on production experience deploying LLM agents and addressing agent architecture, hallucination handling, and tool-invocation fault tolerance.
- Hands-on AI security experience covering prompt injection, jailbreaking, malicious agent injection, and tool misuse, with implementable defenses.
- Production project experience with at least one of LangChain, LlamaIndex, AutoGen, CrewAI, or LangGraph.
- Proficiency with Docker and Kubernetes and expertise in microservices architecture design and deployment.
- Preferred experience with SAST/SCA tools or CodeQL, Semgrep, or SonarQube.
- Preferred experience with LLM fine-tuning using SFT or LoRA, or local deployment and optimization of Llama 3, Qwen, or DeepSeek.
- Preferred open-source agent projects on GitHub or contributions to mainstream LLM frameworks.
- Preferred CTF awards or experience submitting CVE/CNVD vulnerabilities.
Benefits
- L&D programs and education subsidy
- Team-building programs and company events
- Wellness and meal allowances
- Comprehensive healthcare schemes for employees and dependants
Tech Stack
Categories
About OKX
OKX builds a global cryptocurrency exchange and Web3 wallet used by retail and institutional traders for spot, derivatives, and DeFi access, with developer APIs. Its business model centers on trading and financing fees, plus wallet and on-chain services. Founded in 2017 and privately held, OKX publishes monthly proof-of-reserves and operates as part of the OKG group serving crypto markets worldwide.
