Security Engineer
22 hours ago
Who We Are At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom. OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves. Across our multiple offices globally, we are united by our core principles: We Before Me, Do the Right Thing, and Get Things Done. These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er. OKX is part of OKG, a group that brings the value of Blockchain to users around the world, through our leading products OKX, OKX Wallet, OKLink and more. Responsibilities: Security Risk Discovery & Assessment Security Architecture Review: Conduct comprehensive security architecture assessments for new and existing systems using Threat Modeling methodologies to identify structural vulnerabilities before they go live. AI & MCP Security Assessment: Evaluate the security posture of Artificial Intelligence implementations, specifically focusing on MCP integrations, LLM interactions, and AI Agent permissions to prevent prompt injection, unauthorized data access, and excessive agency. Access Control Assessment: Evaluate permission control mechanisms across enterprise systems to identify over-provisioning and control deficiencies. Cloud Infrastructure Review: Audit cloud platform configurations and overall architecture to detect potential security vulnerabilities. Data Flow Analysis: Evaluate technical safeguards during critical data flows to uncover leakage risks. System Review: Conduct comprehensive system security reviews and design robust security hardening solutions. Technical Governance & Solution Design AI Governance Framework: Design security standards and guardrails for AI adoption, ensuring that MCP servers, AI clients, and data connectors adhere to strict authentication and authorization policies. Remediation Framework Design: Design technical remediation plans and long-term governance frameworks based on identified issues. IAM Optimization: Design optimization paths for IAM systems based on the Principle of Least Privilege (PoLP). Data Protection Strategy: Formulate technical control strategies for sensitive data across its entire lifecycle. Tool Evaluation: Evaluate and integrate security technologies into the overall security architecture. Remediation Drive & Verification Cross-Functional Collaboration: Work with technical teams to drive effective implementation of security remediations. Verification Testing: Design and execute technical verification tests (e.g., penetration testing) to confirm remediation effectiveness. Tracking Mechanism: Establish a tracking mechanism for security improvements and potential regression risks. Continuous Review & Reporting: Regularly review projects and consolidate results into strategic reports. Requirements: Education & Experience Bachelor's degree or higher in Computer Science, Information Security, or related fields. 5+ years of experience in security technology or operations, with a strong background in security governance and architecture. Familiarity with large-scale enterprise IT environments, multi-cloud/hybrid cloud models, and modern AI technology stacks. Technical Competencies Architecture & Threat Modeling: Proficiency in performing Security Architecture Reviews and Threat Modeling (e.g., STRIDE, PASTA); ability to dissect complex microservices and distributed systems. AI Security Knowledge: Deep understanding of AI/LLM security risks (e.g., OWASP Top 10 for LLM), including secure design of MCP, RAG (Retrieval-Augmented Generation) architectures, and AI Agent sandboxing. Cloud Security: Proficient in cloud security architecture (AWS, Alibaba Cloud). IAM Knowledge: Strong understanding of identity protocols (RBAC, OAuth, ABAC) and their integration. Data Security: Technical knowledge of DLP, encryption, and data masking best practices. Automation & Tools: Capability in Python/Shell scripting and familiarity with security tools (SIEM, WAF, etc.). Soft Skills: Analytical Thinking: Outstanding problem discovery skills for both traditional and emerging (AI) systems. Communication: Ability to articulate technical security requirements to cross-functional teams. Project Management: Excellent ability to coordinate resources and drive remediation projects. Business Acumen: Ability to balance security requirements with business innovation. Drive & Resilience: Proactive, patient, and capable of maintaining efficiency under pressure. Perks & Benefits Competitive total compensation package. L&D programs and Education subsidy for employees' growth and development. Various team building programs and company events. Wellness and meal allowances. Comprehensive healthcare schemes for employees and dependants . More that we love to tell you along the process Notice : All official OKX vacancies are posted on this site. We are not affiliated with other third-party job boards except Linkedin.com , listings on other sites may be inaccurate or outdated. This is the only source of truth for applications. Information collected and processed as part of the recruitment process of any job application you choose to submit is subject to OKX 's Candidate Privacy Notice .
-
hong kong, Hong Kong SAR China Technology Excellence Technical Lead Engineer Full timeTechnology Excellence Technical Lead Engineer Technology Excellence Technical Lead Engineer View all jobs Add expected salary to your profile for insights Main Content Technology Excellence Technical Lead / Engineer, Information Technology Group Responsibilities Agile Project Leadership Act as Scrum Master: Facilitate Agile ceremonies, manage backlogs, and...
-
Security Engineer, Product Security
1 week ago
hong kong, Hong Kong SAR China Chainlink Labs Full timeJoin to apply for the Security Engineer, Product Security role at Chainlink Labs Join to apply for the Security Engineer, Product Security role at Chainlink Labs Get AI-powered advice on this job and more exclusive features. About UsChainlink Labs is the primary contributing developer of Chainlink, the decentralized computing platform powering the verifiable...
-
(Senior) Security Engineer, Security Engineering
2 weeks ago
Hong Kong Island, Hong Kong SAR China Crypto.com Full time(Senior) Security Engineer, Security Engineering & Threat Intelligence We are looking for an intermediate level security engineer to join our Global Cybersecurity Services Team. As part of our modern cybersecurity operating model, the role will be engaged in enhancing our security technology stack, building AI driven security automation workflows and...
-
Senior Security Engineer
2 weeks ago
Hong Kong Island, Hong Kong SAR China Grvt Full timeOverview Be among the first 25 applicants. You will join the GRVT Site Reliability Engineering (SRE) team, which operates across three tightly integrated verticals: DevSecOps (cloud infrastructure, incident response, platform stability) Test Engineering (end-to-end testing, regression pipelines, feature assurance) Security Engineering (penetration testing,...
-
Security Engineer
1 week ago
Hong Kong, Hong Kong SAR China Meliora Full timeWe are currently supporting a globally leading hedge fund to help them improve their security posture by hiring a product security engineer. This is an individual contributor role and we are looking for someone extremely technical and hands on. We can relocate for this role. Candidate expertise required: Deep understanding in cyber security and software...
-
IT Security Engineering Security Manager
1 day ago
hong kong, Hong Kong SAR China One Advisors Full timeResponsibilities Lead the design, engineering, and optimization of security controls across applications, platforms, and cloud environments (on-premises and cloud). Develop and execute cybersecurity strategies aligned with business objectives, compliance requirements, and risk management frameworks. Collaborate with application development, infrastructure,...
-
Senior Security Engineer
1 week ago
Hong Kong Island, Hong Kong SAR China EXIO (HK) LIMITED Full timeThe Senior Security Engineer will lead the implementation and optimization of security solutions across EXIO’s crypto exchange platform. This role focuses on advanced security operations, including Data Loss Prevention (DLP) , Identity and Access Management (IAM) , and Security Information and Event Management (SIEM) , while mentoring junior team members...
-
Junior Security Engineer
1 week ago
Hong Kong Island, Hong Kong SAR China EXIO (HK) LIMITED Full timeThe Junior Security Engineer will support daily security operations, including monitoring, incident response, and maintenance of DLP, IAM, and SIEM systems. This role is ideal for candidates eager to grow in cybersecurity and gain hands-on experience in a fast-paced crypto exchange environment. Key Responsibilities Assist in configuring and maintaining DLP,...
-
Network Security Engineer
1 week ago
hong kong, Hong Kong SAR China Qube Research & Technologies Full timeJoin to apply for the Network Security Engineer role at Qube Research & Technologies Qube Research & Technologies (QRT) is a global quantitative and systematic investment manager, operating in all liquid asset classes across the world. We are a technology and data driven group implementing a scientific approach to investing. Combining data, research,...
-
Information Security Engineer – Associate
7 days ago
hong kong, Hong Kong SAR China Hong Kong Exchanges and Clearing Limited (HKEX) Full timeInformation Security Engineer – Associate - Security Services - IT Join to apply for the Information Security Engineer – Associate - Security Services - IT role at Hong Kong Exchanges and Clearing Limited (HKEX). Job Summary The Information Security Engineer is part of the Information Security function, playing a key role in enhancing the organization...