Назад
13 дней назад

Staff Engineer, Security Platform Development (Cybersecurity)

Тип работы
fulltime
Грейд
lead
Английский
c1
Страна
Singapore/China
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Engineer, Security Platform Development (Cybersecurity): Architecting and building an end-to-end DevSecOps platform and security SDKs/Agents to embed protection into the software delivery lifecycle with an accent on runtime protection (RASP) and JVM bytecode instrumentation. Focus on integrating AI-native security engineering via LLMs and automating vulnerability analysis and remediation.

Location: Hong Kong, Singapore

Company

OKX is a leading crypto exchange and developer of OKX Wallet, providing millions of users and institutions access to crypto trading and decentralized applications.

What you will do

  • Architect and build an end-to-end DevSecOps platform including SDKs and Agents for code, build, and runtime stages.
  • Lead runtime protection efforts using RASP and Java Agents via bytecode instrumentation (ASM, ByteBuddy).
  • Productize scanning capabilities across SAST, DAST, IAST, and SCA within CI/CD pipelines.
  • Design offensive and defensive countermeasures for XSS, SQL injection, SSRF, and API security.
  • Implement AI-native security using LLMs and AI Agents for vulnerability analysis and automation.
  • Act as the security technical expert within engineering teams to drive standards and release gates.

Requirements

  • Expert-level Java with deep knowledge of JVM, ClassLoader, and bytecode instrumentation.
  • Working proficiency in Python or Go.
  • Substantial production experience with RASP, SAST, DAST, IAST, and SCA tools.
  • Strong fundamentals in OS, networking, compilers, and distributed systems.
  • Practical experience with offensive and defensive application security for web and APIs.
  • Fluency with LLMs, AI agent architecture, and context engineering.

Nice to have

  • Security engineering experience at a top-tier internet company, cloud provider, or leading security vendor.
  • Previous leadership in building DevSecOps or cloud-native security platforms.
  • Background in vulnerability research or red/purple team exercises.
  • Experience shipping AI-driven security tools, such as security copilots or automated remediation systems.

Culture & Benefits

  • Competitive total compensation package.
  • L&D programs and education subsidies for employee growth.
  • Comprehensive healthcare schemes for employees and dependents.
  • Wellness and meal allowances.
  • Regular team building programs and company events.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →