Security Specialist

6 days ago


Hong Kong, Central and Western District, Hong Kong SAR China OKX Full time

Who We Are

At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom.

OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves.

Across our multiple offices globally, we are united by our core principles: We Before MeDo the Right Thing, and Get Things Done. These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er.

OKX is part of OKG, a group that brings the value of Blockchain to users around the world, through our leading products OKX, OKX Wallet, OKLink and more.


About the Opportunity

What You'll Be Doing

  • Manage vulnerabilities discovered by SAST and DAST, complete the closed loop, and improve the overall security of the company.
  • Integrate security requirements according to business scenarios, optimize vulnerability scanning and repair processes, and improve processing efficiency.
  • Reproduce vulnerabilities in complex environments, optimize various SOPs at vulnerability management and security coding levels, and complete implementation.
  • Develop and maintain SAST, DAST, IAST scanning rules and suppression rules, including but not limited to Fortify, CodeQL, Xray, AWVS, etc
  • Perform comprehensive code audits to improve vulnerability coverage, accuracy, etc., to ensure code security and compliance.
  • Provide technical guidance and support to team members on security best practices

What We Look For In You

  • At least 5 years of experience in DevSecOps or related fields.
  • Proficient in the principles and practices of SAST, DAST, and IAST.
  • Have rich experience in using various scanning engines for code auditing and scanning rule development.
  • Have a deep understanding of microservice structure, familiar with vulnerability reproduction in microservice rack/RPC scenarios.
  • Understand service link(service-to-service invocation chains) tracing technology .
  • Able to reproduce and resolve complex environmental vulnerabilities identified by SAST, DAST, and IAST.
  • Solid Java and/or Golang development skills.
  • Excellent problem-solving skills and attention to detail.
  • Good communication and teamwork skills.

Nice to have

  • Familiar with application layer and Cloud Native architecture, as well as related security governance work.
  • Possess certification in relevant safety disciplines.
  • Have experience in developing open source security tools, or have participated in the development and optimization of vulnerability scanning engines and governance platforms.
  • Familiar with common web application architecture and its security bugs, with solid experience in vulnerability reproduction and vulnerability repair


Perks & Benefits 

  • Competitive total compensation package
  • L&D programs and education subsidy for employees' growth and development
  • Various team building programs and company events
  • Wellness and meal allowance
  • Comprehensive healthcare schemes for employees and dependants
  • More that we love to tell you along the process


  • Hong Kong, Central and Western District, Hong Kong SAR China Pentastic Security Limited Full time

    Job Description:The successful candidate will be responsible for conducting thorough vulnerability assessments, identifying potential security risks, and implementing effective mitigation strategies. This will involve collaborating closely with our team to ensure seamless integration with existing security protocols.Key Responsibilities:Vulnerability...


  • Hong Kong, Central and Western District, Hong Kong SAR China Centurion Information Security Full time

    Job SummaryCenturion Information Security is a leading provider of information security consulting services. We are currently seeking a highly skilled Penetration Testing Specialist to join our team.Key ResponsibilitiesConduct penetration testing and vulnerability assessments to identify potential security risks and recommend remediation strategies.Develop...


  • Hong Kong, Central and Western District, Hong Kong SAR China Cisco Systems, Inc. Full time

    Cisco Systems, Inc. is seeking a highly motivated and experienced Technical Security Sales Specialist to join our team. As a Technical Security Sales Specialist, you will play a critical role in driving the success of our security solutions by identifying and capitalizing on new business opportunities.Your primary responsibility will be to work closely with...


  • Hong Kong, Central and Western District, Hong Kong SAR China Millennium Full time

    Equity Finance and Securities Lending SpecialistThe Millennium is seeking an experienced Equity Finance and Securities Lending Specialist to join its Portfolio Finance team in Hong Kong. In this role, you will work closely with Portfolio Managers to optimize equity finance and securities lending strategies.You will be responsible for developing and...


  • Hong Kong, Central and Western District, Hong Kong SAR China Wizlynx Malaysia Sdn Bhd Full time

    Job Description:We are seeking a highly skilled Cyber Security Consultant to join our team in Hong Kong. As a Red Team Specialist, you will play a pivotal role in our cybersecurity department, focusing on emulating threat actors to assess and enhance the security of enterprise networks.Your mission is to penetrate, identify vulnerabilities, and simulate...


  • Hong Kong, Central and Western District, Hong Kong SAR China MIGSO-PCUBED Full time

    We are looking for a skilled Information Security Specialist to join our team at MIGSO-PCUBED. In this role, you will be responsible for deploying and maintaining our SIEM infrastructure, ensuring the detection and reaction to cyber threats. You will work closely with our Production Infrastructure & Observability team and will be part of the Production CSIRT...


  • Hong Kong, Central and Western District, Hong Kong SAR China Bank Of China (Hong Kong) Limited Full time

    About Bank Of China (Hong Kong) LimitedWe are a leading financial institution committed to providing innovative solutions for our customers.Job Description:Cyber Security Specialist - Threat ManagementWe are seeking a highly skilled Cyber Security Specialist - Threat Management to join our team. As a key member of our cyber security team, you will be...


  • Hong Kong, Central and Western District, Hong Kong SAR China Pentastic Security Limited Full time

    Company OverviewPentastic Security Limited is a leading provider of cybersecurity solutions, dedicated to helping individuals and organizations protect themselves against the ever-evolving threat landscape.


  • Hong Kong, Central and Western District, Hong Kong SAR China Bloombase Full time

    Bloombase is seeking a highly skilled professional to join our team as a Data Security Specialist. As a member of our team, you will be responsible for designing and developing next-generation data encryption security software products and solutions for data-center, server-side, cloud infrastructure.You will interact with Bloombase's partner hardware,...


  • Hong Kong, Central and Western District, Hong Kong SAR China Pentastic Security Limited Full time

    Key ResponsibilitiesConduct vulnerability assessments, penetration testing, and source code reviews to identify areas for improvement.Collaborate with clients to understand their needs and develop effective solutions.Analyze data and provide actionable recommendations to enhance security measures.We value teamwork, analytical skills, and effective...


  • Hong Kong, Central and Western District, Hong Kong SAR China Mass Transit Railway Full time

    Mass Transit Railway's vision is to provide a safe, efficient, and convenient transportation system for the public.Job RequirementsTo succeed as a Station Security and Compliance Specialist, you will need to possess excellent communication and interpersonal skills, as well as the ability to work effectively in a team environment.You will be required to...


  • Hong Kong, Central and Western District, Hong Kong SAR China BIXIN Full time

    Company OverviewBIXIN is a deemed-to-be-licensed VASP regulated by the Securities and Futures Commission (SFC) of Hong Kong, providing innovative solutions in blockchain and fintech.Job DescriptionWe are looking for a talented Network Protection Specialist to lead our network security efforts, ensuring the integrity and confidentiality of our data.The ideal...


  • Hong Kong, Central and Western District, Hong Kong SAR China TRON DAO Full time

    Cyber Security Engineer Job DescriptionTRON DAO seeks a highly skilled Cyber Security Engineer to join our team. As a key member of our security operations team, you will be responsible for the daily operation and maintenance of security devices, including firewalls, intrusion detection/prevention systems (IDS/IPS), WAF, SIEM, etc.Responsibilities:Conduct...


  • Hong Kong, Central and Western District, Hong Kong SAR China HKT Full time

    We are seeking a highly motivated and experienced Cloud Security Engineer to join HKT IT Cloud Technology team.Responsibilities:Cloud Security Architecture & Design:Design and implement secure cloud architectures, including network segmentation, access control, and data protection strategies.Develop and maintain security standards and best practices for...


  • Hong Kong, Central and Western District, Hong Kong SAR China Bank of Communications Co., Ltd. London Branch Full time

    Company Overview:The Bank of Communications Co., Ltd. London Branch is a leading financial institution with a strong commitment to IT security. We strive to maintain the highest standards of data protection and privacy, ensuring that our customers' information remains secure.We are looking for an experienced IT security professional who shares our passion...


  • Hong Kong, Central and Western District, Hong Kong SAR China ConnectedGroup Full time

    Job SummaryWe are seeking a skilled professional to assist in developing and managing cyber security policies and business continuity plans.The ideal candidate will have extensive knowledge in cyber security operations and incident response, as well as hands-on experience with vulnerability scanning and penetration testing.The selected individual will be...


  • Hong Kong, Central and Western District, Hong Kong SAR China Crypto Full time

    Crypto.com is a leading cryptocurrency platform that offers a comprehensive suite of financial services to its users. We are committed to delivering exceptional customer experiences and are seeking a highly skilled DevOps and Cloud Engineer to join our team.In this role, you will be responsible for designing and implementing secure cloud architectures,...


  • Hong Kong, Central and Western District, Hong Kong SAR China ThreatBook Full time

    About ThreatBookWe are a forward-thinking company that delivers cutting-edge network security solutions. We are looking for a skilled Technical Solutions Architect to join our team.Job Overview:Design and deliver secure network solutions that meet client needs, using analysis and proposal development.Work closely with sales personnel to understand client...


  • Hong Kong, Central and Western District, Hong Kong SAR China Shenendehowa Central School District Full time

    Job Overview:Shenendehowa Central School District is seeking a culturally proficient individual to join our team as a part-time security officer. The successful candidate will be responsible for managing campus traffic, conducting regular patrols and inspections, and implementing security measures consistent with best practices.Salary and Benefits:The...


  • Hong Kong, Central and Western District, Hong Kong SAR China Hong Kong Exchanges and Clearing Limited Full time

    Company Introduction:We're home to Asia's most dynamic and vibrant capital markets.Connecting capital, ideas, inspiration and innovation for deeper, more diverse and liquid global capital markets; providing greater choice and opportunity for our customers, each and every day.HKEX is a purpose-driven company. Our commitment to the long-term development of our...