Staff Engineer, Security Platform Development

OKX

United States

On-site

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive total compensation package
L&D programs and Education subsidy for
Team building programs and company

Job summary

OKX is seeking a Staff Engineer to own the build-out of security engineering and DevSecOps capabilities, embedding protection into how code is written, built, shipped, and run.

You will architect and implement end-to-end platform components, runtime protection, and scanning integrations, while applying AI-native approaches and collaborating across engineering to raise the security baseline and delivery quality.

Qualifications

  • Deep understanding of operating systems, networking, compilers and the JVM, distributed systems, application security, cloud-native security, and supply chain security.

Responsibilities

  • Architect and build end-to-end DevSecOps platform with SDKs/Agents.
  • Lead runtime protection using RASP and Java Agent, including bytecode instrumentation.
  • Integrate scanning across SAST, DAST, IAST, SCA, and image scanning within CI/CD.
  • Design detection, remediation, hardening, and counter-measures for web/API/microservices vulnerabilities.
  • Apply LLMs and AI Agents to vulnerability analysis, remediation guidance, and automation.
  • Embed security as a technical expert inside engineering teams, driving standards and gates.
  • Partner with engineering, architecture, SRE, QA, and business on priority security projects.

Skills

Expert-level Java
JVM internals
Python or Go
Security fundamentals
RASP/ SAST/ DAST/ IAST
Security product design
Performance tuning
Security ownership

Tools

ASM
ByteBuddy
Instrumentation

Job description

Who We Are

At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom.

OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves.

Across our multiple offices globally, we are united by our core principles: We Before Me, Do the Right Thing, and Get Things Done. These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er. OKX is part of OKG, a group that brings the value of Blockchain to users around the world, through our leading products OKX, OKX Wallet, OKLink and more.

About the Opportunity

As a Staff Engineer, you'll own the build-out of our security engineering and DevSecOps capabilities: designing and developing the security products, platform services, and SDKs/Agents that embed protection directly into how code is written, built, shipped, and run.

What You’ll Be Doing
  • Architect and build our end-to-end DevSecOps platform and the SDKs/Agents behind our security products, covering code, build, artifacts, images, deployment, and runtime.
  • Lead runtime protection through RASP and Java Agent — bytecode instrumentation, runtime hooking, and detection/interception engines using ASM, ByteBuddy, and Instrumentation, with continuous tuning for performance, stability, and compatibility.
  • Integrate and productise scanning capabilities across SAST, DAST, IAST, SCA, code scanning, and image scanning. You'll embed tools like SonarQube and Coverity deep into CI/CD and close the loop from detection through blocking, remediation, and re-test.
  • Go deep on application security offence and defence — designing detection, remediation, hardening, and counter-measures for XSS, SQL injection, SSRF, deserialisation, command execution, authentication/authorisation flaws, and API security.
  • Bring AI-native security engineering to life. Apply LLMs and AI Agents to vulnerability analysis, rule generation, false-positive attribution, remediation guidance, security knowledge capture, and engineering automation — and build a coherent view of the architecture, mechanics, and security implications.
  • Embed as the security technical expert inside engineering teams, driving security standards, onboarding specifications, release gates, risk tiering, and remediation mechanisms that measurably lift the security baseline and delivery quality.
  • Partner across engineering, architecture, SRE, QA, and business teams on priority projects, solving the genuinely hard security problems and turning the solutions into reusable platform capability and repeatable practice.
What We Look For In You
  • Strong computer science and security fundamentals — deep understanding of operating systems, networking, compilers and the JVM, distributed systems, application security, cloud-native security, and supply chain security. Both breadth and depth.
  • Expert-level Java, with hands‑on depth in the JVM, ClassLoader, Java Agent, ASM, ByteBuddy, bytecode instrumentation, and performance profiling and tuning. Plus working proficiency in Python or Go.
  • Substantial production experience with RASP, SAST, DAST, IAST, SCA, image security, and code scanning — enough to design a capability, integrate the engine, build the platform around it, and take it to scale independently.
  • Real offensive and defensive experience. You understand the root causes, exploitation paths, detection logic, bypass techniques, and fixes for common web, API, and microservices vulnerabilities — and can design from both the attacker’s and defender’s point of view.
  • Fluency with LLMs and AI Agents, including a considered view on model capability limits, agent architecture, tool calling, context engineering, evaluation methods, and how AI is reshaping both security engineering and the attack surface.
  • Strong engineering execution paired with product instinct — able to lead the design and delivery of security products, platform modules, and SDKs/Agents while balancing security outcomes against performance overhead, integration cost, and long‑term operability.
  • Exceptional ownership, cross‑team communication, and the persistence to move security governance, rule enforcement, and remediation through to a clear result.
Nice to Haves
  • Security engineering experience at a top‑tier internet company, cloud provider, or leading security vendor
  • You've led the build of a DevSecOps platform, application security platform, RASP, code scanning platform, or cloud‑native security platform
  • Background in security product development, SDK/Agent engineering, vulnerability research, red team exercises, or purple team work
  • Shipped AI + Security work — security copilots, intelligent rule generation, automated analysis, or remediation recommendation systems
Perks & Benefits
  • Competitive total compensation package
  • L&D programs and Education subsidy for employees' growth and development
  • Various team building programs and company events
  • Wellness and meal allowances
  • Comprehensive healthcare schemes for employees and dependants
  • More that we love to tell you along the process!
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Engineer Vulnerability Scanner
Senior Engineer Vulnerability Scanner

Framework Ventures • United States

Remote
USD 120,000 - 150,000
Competitive total compensation package
L&D programs and education subsidy
Various team building programs
+2
Senior Engineer Security Middleware Platm
Senior Engineer Security Middleware Platm

Framework Ventures • Sterling (VA)

On-site
USD 120,000 - 180,000
Competitive total compensation
Comprehensive insurance for employees'
Staff Software Engineer, Security
Staff Software Engineer, Security

XOXO AI Inc. • San Francisco (CA)

On-site
USD 250,000 - 500,000
Health benefits
Dental benefits
Vision benefits
Security Engineer Data Endpoint Security
Security Engineer Data Endpoint Security

Framework Ventures • United States

Remote
USD 90,000 - 120,000
Competitive total compensation package
L&D programs
Wellness and meal allowance
+1
Staff Security Platform Engineer (DevSecOps)
Staff Security Platform Engineer (DevSecOps)

OKX • United States

On-site
USD 180,000 - 240,000
Competitive total compensation package
L&D programs and Education subsidy for
Team building programs and company
Security Operations Engineer
Security Operations Engineer

Framework Ventures • Boston (MA)

On-site
USD 120,000 - 180,000
Total compensation
Education subsidy
Team events
+2
Staff Software Engineer, Security
Staff Software Engineer, Security

XOXO AI • Home (KS)

On-site
USD 250,000 - 500,000
Health insurance
Dental insurance
Vision insurance
Software Engineer, Security
Software Engineer, Security

XOXO AI • Home (KS)

On-site
USD 250,000 - 500,000
Equity 1-5%
On-site at SF
Comprehensive benefits
Americas CISO: Strategic Security & Regulation Leader
Americas CISO: Strategic Security & Regulation Leader

Okg-7 • New York (NY)

On-site
USD 250,444 - 375,666
L&D programs and Education subsidy for
Team building programs and company
Wellness and meal allowances
+1
Product Security Engineer
Product Security Engineer

GoMining • United States

Hybrid
USD 120,000 - 190,000
Courses & conferences support (up to )
Remote or hybrid format with flexible,
Paid time off and holidays