368,657open jobs
9,442companies
50,883added this week
Browse all
Location
In office (Hong Kong)
Seniority
Staff
Overview
Company
Impact
Profile match

OKX

OKX is a global cryptocurrency exchange and digital asset platform. It offers spot, margin, futures, and options trading, plus a Web3 wallet, DeFi access, and NFT features. The company has positioned itself as a broad crypto ecosystem for both beginners and advanced traders.

OKX will be prioritising applicants who have a current right to work in Singapore, and do not require OKX's sponsorship of a visa.

Who We Are

At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom.

OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves. 

Across our multiple offices globally, we are united by our core principles: We Before Me, Do the Right Thing, and Get Things Done. These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er.

OKX is part of OKG, a group that brings the value of Blockchain to users around the world, through our leading products OKX, OKX Wallet, OKLink and more.

About The Opportunity

As a Technical Expert, you will lead the development of the company’s core security engineering and DevSecOps capabilities, with a strong focus on security product development, platform engineering, andSDK/Agent development. The ideal candidate should demonstrate deep security expertise, broad technical coverage, strong hands-on engineering capability, and exceptional influence in driving security governance across business teams.

What You’ll Be Doing 

  • Lead the architecture and core development of the company’s end-to-end DevSecOps platform, security products, and SDKs/Agents, covering code, build, artifacts, images, deployment, and runtime security.

  • Own the design and development of RASP / Java Agent runtime protection, leveraging ASM, ByteBuddy, and Java Instrumentation for bytecode enhancement, runtime hooks, detection and blocking engines, while continuously improving performance, stability, and compatibility.

  • Build and integrate SAST, DAST, IAST, SCA, code security scanning, and image security scanning into CI/CD workflows, and drive deep integration of tools such as SonarQubeand Coverity to form a closed loop of scanning, gating, remediation, and re-validation.

  • Drive core application security protection and offensive/defensive capabilities across scenarios such as XSS,SQLinjection, SSRF, deserialization, command execution, authentication/authorization flaws, privilege escalation, and API security.

  • Advance AI-Native Security Engineering by applying LLMs and AI Agents to vulnerability analysis, rule generation, false-positive reduction, remediation suggestions, security knowledge management, and workflow automation, while building deep understanding of their architecture, principles, and security implications.

  • Partner closely with business engineering teams to drive security standards, integration rules, quality gates, risk classification, remediation workflows, and overall security governance adoption.

  • Collaborate with engineering, architecture, operations, QA, and business stakeholders to solve complex security problems and turn them into scalable product capabilities, engineering solutions, and governance mechanisms.

What We Look For In You 

  • Strong fundamentals in computer science and security, with deep understanding of operating systems, networking, compilers/JVMinternals, distributed systems, application security, cloud-native security, and software supply chain security, with both breadth and depth in security technologies.

  • Expert-level Java proficiency, especially in JVMinternals,ClassLoader, Java Agent, ASM, ByteBuddy, bytecode instrumentation, profiling, and performance tuning; proficient in Python or Golang as well.

  • Proven hands-on experience with RASP, SAST, DAST, IAST, SCA, image security, and code security scanning, with the ability to independently design, integrate, and productionize security capabilities.

  • Strong offensive and defensive security experience, with deep understanding of vulnerability root causes, exploitation techniques, detection logic, bypass methods, and remediation strategies in web, API, and microservice environments.

  • Strong practical experience with LLMs and AI Agents, plus deep understanding of model architecture, agent design, tool invocation, context engineering, evaluation methods, and the impact of AI on both security engineering and attacker capabilities.

  • Strong engineering and product mindset, capable of leading the design and implementation of security products, platform modules, and SDKs/Agents while balancing security effectiveness, performance overhead, integration cost, and operability.

  • Strong ownership, communication skills, and cross-functional influence, with a proven ability to drive business teams on security governance, policy adoption, and remediation outcomes.

Preferred Qualifications

  • Background from top-tier Internet companies, cloud providers, or leading cybersecurity vendors;

  • Experience leading DevSecOps platforms, application security platforms, RASP systems, code scanning platforms, or cloud-native security platforms;

  • Strong experience in security product development,SDK/Agent development, vulnerability research, penetration testing, red/blue team exercises, or incident response;

  • Hands-on experience in AI + Security initiatives such as security copilots, intelligent rule generation, automated vulnerability analysis, or remediation recommendation systems.

Perks & Benefits 

  • Competitive total compensation package

  • L&D programs and education subsidy for employees' growth and development
  • Various team building programs and company events

  • Wellness and meal allowances
  • Comprehensive healthcare schemes for employees and dependants
  • More that we love to tell you along the process!

Notice:

All official OKXvacancies are published on this website.While roles may appear on selected third-party platforms from time to time, information on other sites may be inaccurate or outdated. If in doubt, please apply directly through our official careers website.

Information collected and processed as part of the recruitment process of any job application you choose to submit is subject to OKX's Candidate Privacy Notice.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Hong Kong
Mobile Engineer 1 day ago
$18k – $59k per year (Estimated) • In office • 7+ years exp • Mumbai
Java
Kotlin
Objective-C
Swift
Frontend
GraphQL
DevOps
CI/CD
Git
Management
Confluence
Jira
Apply
$20k – $50k per year (Estimated) • In office • Full-Time • Tomsk
C++
Go
Java
Kotlin
Databases
Apache Kafka
ClickHouse
ElasticSearch
DevOps
Jaeger
Kubernetes
Prometheus
SLI/SLO/SLA
Apply
$20k – $50k per year (Estimated) • In office • Full-Time • Perm
C++
Go
Java
Kotlin
Databases
Apache Kafka
ClickHouse
ElasticSearch
DevOps
Jaeger
Kubernetes
Prometheus
SLI/SLO/SLA
Apply
$11k – $25k per year (Estimated) • In office • Full-Time • 2+ years exp • Perm
Go
Java
Kotlin
SQL
Databases
Apache Kafka
PostgreSQL
DevOps
GitLab
QA
Postman
Swagger
Apply
$11k – $25k per year (Estimated) • In office • Full-Time • 2+ years exp • Tomsk
Go
Java
Kotlin
SQL
Databases
Apache Kafka
PostgreSQL
DevOps
GitLab
QA
Postman
Swagger
Apply
$165k – $344k per year (Estimated) • In office • 5+ years exp • Singapore
JavaScript
Kotlin
Swift
TypeScript
AI/ML
Claude
Claude Code
OpenAI Codex
Apply
In office • Internship • 3+ years exp • Bachelor's Degree • Hong Kong
Apply
$158k – $363k per year (Estimated) • In office • Internship • 3+ years exp • Bachelor's Degree • Singapore
Apply
$143k – $257k per year • In office • New York
DevOps
SLI/SLO/SLA
Apply
In office • 8+ years exp • Hong Kong
Java
Kotlin
Objective-C
Swift
Mobile
Adjust
AppsFlyer SDK
Apply
In office • 5+ years exp • Bachelor's Degree • Hong Kong
Apply
In office • Hong Kong
DevOps
AWS
Azure
GCP
Apply
In office • Hong Kong
Databases
Databricks
DevOps
AWS
Azure
GCP
Apply
In office • 3+ years exp • Hong Kong
Java
Node JS
Python
SQL
JavaScript
AI/ML
BERT
Fine-tuning
Hadoop
LangChain
LangGraph
LLM
RAG
Spark
Edge AI
Knowledge Graph
AI Agents
Google ADK
Frontend
React.js
DevOps
AWS
Azure
CI/CD
Docker
GCP
Git
Kubernetes
Cybersecurity
GDPR
Apply
In office • 3+ years exp • Hong Kong
Java
Node JS
Python
SQL
JavaScript
AI/ML
AI Agents
BERT
Edge AI
Fine-tuning
Google ADK
Hadoop
Knowledge Graph
LangChain
LangGraph
LLM
RAG
Spark
Frontend
React.js
DevOps
AWS
Azure
CI/CD
Docker
GCP
Git
Kubernetes
Cybersecurity
GDPR
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.