OKX - Senior/Staff Engineer, Security Platform Development
Requirements
• Background from top-tier Internet companies, cloud providers, or leading cybersecurity vendors; • top-tier Internet companies, cloud providers, or leading cybersecurity vendors • Experience leading DevSecOps platforms, application security platforms, RASP systems, code scanning platforms, or cloud-native security platforms; • DevSecOps platforms, application security platforms, RASP systems, code scanning platforms, or cloud-native security platforms • Strong experience in security product development, SDK/Agent development, vulnerability research, penetration testing, red/blue team exercises, or incident response; • security product development, • /Agent development, vulnerability research, penetration testing, red/blue team exercises, or incident response • Hands-on experience in AI + Security initiatives such as security copilots, intelligent rule generation, automated vulnerability analysis, or remediation recommendation systems. • AI + Security
Responsibilities
• Lead the architecture and core development of the company’s end-to-end DevSecOps platform, security products, and SDKs/Agents, covering code, build, artifacts, images, deployment, and runtime security. • end-to-end DevSecOps platform, security products, and SDKs/Agents • Own the design and development of RASP / Java Agent runtime protection, leveraging ASM, ByteBuddy, and Java Instrumentation for bytecode enhancement, runtime hooks, detection and blocking engines, while continuously improving performance, stability, and compatibility. • RASP / Java Agent runtime protection • ASM, ByteBuddy, and Java Instrumentation • Build and integrate SAST, DAST, IAST, SCA, code security scanning, and image security scanning into CI/CD workflows, and drive deep integration of tools such as SonarQube and Coverity to form a closed loop of scanning, gating, remediation, and re-validation. • SAST, DAST, IAST, SCA, code security scanning, and image security scanning • SonarQube • and Coverity • Drive core application security protection and offensive/defensive capabilities across scenarios such as XSS, SQL injection, SSRF, deserialization, command execution, authentication/authorization flaws, privilege escalation, and API security. • injection, SSRF, deserialization, command execution, authentication/authorization flaws, privilege escalation, and API security • Advance AI-Native Security Engineering by applying LLMs and AI Agents to vulnerability analysis, rule generation, false-positive reduction, remediation suggestions, security knowledge management, and workflow automation, while building deep understanding of their architecture, principles, and security implications. • AI-Native Security Engineering • LLMs and AI Agents • Partner closely with business engineering teams to drive security standards, integration rules, quality gates, risk classification, remediation workflows, and overall security governance adoption. • Collaborate with engineering, architecture, operations, QA, and business stakeholders to solve complex security problems and turn them into scalable product capabilities, engineering solutions, and governance mechanisms. • What We Look For In You • Strong fundamentals in computer science and security, with deep understanding of operating systems, networking, compilers/JVM internals, distributed systems, application security, cloud-native security, and software supply chain security, with both breadth and depth in security technologies. • operating systems, networking, compilers/ • internals, distributed systems, application security, cloud-native security, and software supply chain security • breadth and depth • Expert-level Java proficiency, especially in JVM internals, ClassLoader, Java Agent, ASM, ByteBuddy, bytecode instrumentation, profiling, and performance tuning; proficient in Python or Golang as well. • Expert-level Java proficiency • internals, • ClassLoader • , Java Agent, ASM, ByteBuddy, bytecode instrumentation, profiling, and performance tuning • Python or Golang • Proven hands-on experience with RASP, SAST, DAST, IAST, SCA, image security, and code security scanning, with the ability to independently design, integrate, and productionize security capabilities. • RASP, SAST, DAST, IAST, SCA, image security, and code security scanning • Strong offensive and defensive security experience, with deep understanding of vulnerability root causes, exploitation techniques, detection logic, bypass methods, and remediation strategies in web, API, and microservice environments. • offensive and defensive security experience • Strong practical experience with LLMs and AI Agents, plus deep understanding of model architecture, agent design, tool invocation, context engineering, evaluation methods, and the impact of AI on both security engineering and attacker capabilities. • LLMs and AI Agents • Strong engineering and product mindset, capable of leading the design and implementation of security products, platform modules, and SDKs/Agents while balancing security effectiveness, performance overhead, integration cost, and operability. • security effectiveness, performance overhead, integration cost, and operability • Strong ownership, communication skills, and cross-functional influence, with a proven ability to drive business teams on security governance, policy adoption, and remediation outcomes.
Benefits
• L&D programs and education subsidy for employees' growth and development • Various team building programs and company events • Wellness and meal allowances • Comprehensive healthcare schemes for employees and dependants • More that we love to tell you along the process! • All official OKX vacancies are published on this website. While roles may appear on selected third-party platforms from time to time, information on other sites may be inaccurate or outdated. If in doubt, please apply directly through our official careers website. • If in doubt, please apply directly through our official careers website. • Information collected and processed as part of the recruitment process of any job application you choose to submit is subject to OKX's Candidate Privacy Notice.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT