
Staff Engineer, Security Platform Development
Job description
About the role
You architect and deliver core security platform capabilities that underpin the trust and safety of OKX's global crypto infrastructure. You own the design, implementation, and operation of critical security services, identity systems, and fraud detection pipelines that protect users and assets at scale. You translate complex security requirements into robust, scalable, and maintainable software solutions across distributed systems. You collaborate closely with product, risk, and infrastructure teams to ensure security controls are integrated seamlessly without compromising performance or user experience. You lead technical design discussions, code reviews, and best practices for security engineering across the organization. You mentor engineers on secure coding patterns, threat modeling, and operational readiness for security incidents. You drive the evolution of the security platform to support new products, regulatory requirements, and emerging threat landscapes.
Key facts
What you'll do
Design and evolve a platform for security services, including identity, authentication, authorization, and cryptographic operations across the OKX ecosystem.
Implement scalable systems for fraud detection, risk scoring, and anomaly monitoring that process high-volume transaction and behavioral data with low latency.
Partner with product and risk stakeholders to define security requirements, acceptance criteria, and metrics for new features and trading workflows.
Lead the development of secure APIs and SDKs that enable internal teams and external partners to integrate security controls consistently and efficiently.
Build observability, alerting, and incident response tooling for security platforms to ensure timely detection, investigation, and remediation of threats.
Collaborate with infrastructure and platform teams to harden runtime environments, enforce least-privilege access, and manage secrets and keys securely.
Define and operationalize security guardrails, including policy-as-code, automated compliance checks, and secure deployment pipelines for cloud-native services.
Analyze adversarial tactics, techniques, and procedures to proactively strengthen platform defenses, reduce attack surfaces, and improve detection accuracy.
Work with cross-functional teams to establish security standards, reference architectures, and reusable components that accelerate safe development across OKX.
Contribute to disaster recovery, business continuity, and resilience testing for security-critical systems to ensure continuity under failure conditions.
Engage with the broader security community through knowledge sharing, documentation, and internal training on emerging threats and defensive practices.
Drive measurable improvements in security outcomes by correlating platform telemetry with risk indicators and user impact metrics.
Requirements
You hold a Bachelor's or Master's degree in Computer Science, Information Security, or a related technical field, or equivalent practical experience.
You have 8+ years of professional software engineering experience, with a strong track record of delivering secure, scalable, and reliable systems.
You possess deep programming expertise in at least one modern language such as Java, Go, Python, or TypeScript, and experience building distributed systems.
You have hands-on experience with cloud platforms, container orchestration, and infrastructure as code, including designing systems that operate reliably at scale.
You demonstrate strong knowledge of security fundamentals, including cryptography, authentication protocols, access control models, and secure network design.
You are fluent in security concepts such as threat modeling, vulnerability assessment, secure development lifecycle, and incident response processes.
You have experience designing and operating identity and access management systems, including integrations with enterprise identity providers and multi-factor authentication.
You show a proven ability to translate ambiguous problems into well-defined technical solutions while balancing trade-offs between security, usability, and performance.
Nice to have
Experience with blockchain, cryptocurrency, or financial services platforms is preferred.
Knowledge of security and privacy regulations relevant to digital assets and cross-border operations is beneficial.
Familiarity with fraud detection systems, machine learning pipelines for risk, or data platform experience is a plus.
Contributions to open source security projects or public technical writing on security topics are valued.
Practical notes
This is a full-time position based in Hong Kong, Hong Kong SAR or Singapore.
Travel may be required within the region for team collaboration, security reviews, or business purposes.
Visa sponsorship may be considered for eligible candidates based on role and location requirements.