Staff Engineer, Security Platform Development
OKX
Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
5,724 open development roles across 572 companies are on ApplySarthi right now, most of them in Bengaluru (390), Hyderabad (138), Delhi NCR (65).
- Software Development Engineer, AWS SecurityAmazon Development Centre (London) Limited
- Principal ATE Test Development EngineerMarvell
- Business Development ManagerAbbott
- Sr. Developer - Application Development P 4BGenpact · bengaluru
- Engineer, Test Engineering - Product DevelopmentAnalogdevices · bengaluru
What development roles keep asking for: AWS (15%), Java (14%), C++ (13%) — counted across their open postings here.
CI/CD jobs · Java jobs · LLMs jobs · Microservices jobs
OKX has 342 open roles listed here.
- Deputy Money Laundering Reporting Officer, Eurasia
- Senior/Lead Product Manager - Professional Trading Tools & Experience
- Senior/Staff Engineer - Web3 - Onchain Data
- Software Engineer, Mobile(iOS)
- Deputy General Counsel, Head of Americas Legal
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for development roles keep coming back to AWS, Java, C++. Practise those questions before you sit with OKX.
Questions you are likely to be asked
- Why do you want to join OKX?
- What is your experience with Java? Tell me one thing you learned the hard way.
- How do you decide what to monitor, and what should wake someone up at night?
- How would you cut the cloud bill of a system without hurting it?
- How do you keep secrets and access safe in your infrastructure?
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Staff Engineer, Security Platform Development at OKX interview free →Who We Are
About the Opportunity
This is a role for someone with real depth in security, broad coverage across the stack, and the engineering muscle to ship. Just as important is the ability to drive adoption — security that lands in complex, fast-moving business environments rather than sitting in a policy document.
What You’ll Be Doing
- Architect and build our end-to-end DevSecOps platform and the SDKs/Agents behind our security products, covering code, build, artifacts, images, deployment, and runtime.
- Lead runtime protection through RASP and Java Agent — bytecode instrumentation, runtime hooking, and detection/interception engines using ASM, ByteBuddy, and Instrumentation, with continuous tuning for performance, stability, and compatibility.
- Integrate and productise scanning capabilities across SAST, DAST, IAST, SCA, code scanning, and image scanning. You'll embed tools like SonarQube and Coverity deep into CI/CD and close the loop from detection through blocking, remediation, and re-test.
- Go deep on application security offence and defence — designing detection, remediation, hardening, and counter-measures for XSS, SQL injection, SSRF, deserialisation, command execution, authentication/authorisation flaws, and API security.
- Bring AI-native security engineering to life. Apply LLMs and AI Agents to vulnerability analysis, rule generation, false-positive attribution, remediation guidance, security knowledge capture, and engineering automation — and build a coherent view of the architecture, mechanics, and security implications.
- Embed as the security technical expert inside engineering teams, driving security standards, onboarding specifications, release gates, risk tiering, and remediation mechanisms that measurably lift the security baseline and delivery quality.
- Partner across engineering, architecture, SRE, QA, and business teams on priority projects, solving the genuinely hard security problems and turning the solutions into reusable platform capability and repeatable practice.
What We Look For In You
- Strong computer science and security fundamentals — deep understanding of operating systems, networking, compilers and the JVM, distributed systems, application security, cloud-native security, and supply chain security. Both breadth and depth.
- Expert-level Java, with hands-on depth in the JVM, ClassLoader, Java Agent, ASM, ByteBuddy, bytecode instrumentation, and performance profiling and tuning. Plus working proficiency in Python or Go.
- Substantial production experience with RASP, SAST, DAST, IAST, SCA, image security, and code scanning — enough to design a capability, integrate the engine, build the platform around it, and take it to scale independently.
- Real offensive and defensive experience. You understand the root causes, exploitation paths, detection logic, bypass techniques, and fixes for common web, API, and microservices vulnerabilities — and can design from both the attacker's and defender's point of view.
- Fluency with LLMs and AI Agents, including a considered view on model capability limits, agent architecture, tool calling, context engineering, evaluation methods, and how AI is reshaping both security engineering and the attack surface.
- Strong engineering execution paired with product instinct — able to lead the design and delivery of security products, platform modules, and SDKs/Agents while balancing security outcomes against performance overhead, integration cost, and long-term operability.
- Exceptional ownership, cross-team communication, and the persistence to move security governance, rule enforcement, and remediation through to a clear result.
Nice to Haves
- Security engineering experience at a top-tier internet company, cloud provider, or leading security vendor
- You've led the build of a DevSecOps platform, application security platform, RASP, code scanning platform, or cloud-native security platform
- Background in security product development, SDK/Agent engineering, vulnerability research, red team exercises, or purple team work
- Shipped AI + Security work — security copilots, intelligent rule generation, automated analysis, or remediation recommendation systems
Perks & Benefits
- Competitive total compensation package
- L&D programs and Education subsidy for employees' growth and development
- Various team building programs and company events
- Wellness and meal allowances
- Comprehensive healthcare schemes for employees and dependants
- More that we love to tell you along the process!
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- Affiliate BD Manager (Taiwan)OKX
- Affiliate ManagerOKX
- Affiliate Business Development Manager, CISOKX
- Affiliate Business Development Manager - MENAOKX
- Affiliate Business Development Manager, Northeast AsiaOKX
- Affiliate Business Development Manager, PolandOKX
- Compliance Head & MLRO, IndonesiaOKX
- Compliance Head & MLRO, PakistanOKX
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on greenhouse · posted 2026-08-04. ApplySarthi collects openings and links to application pages; the role is advertised by OKX, not by us.