OKX is hiring a

Security Engineer, New Grad

San Jose, United States
If you are interested in more than one Supernova role, please apply to your first preference. We will still consider you for all opportunities.
 
Who We Are
 
At OKX, we believe that the future will be reshaped by Crypto, ultimately contributing to every individual's freedom. OKX began as a crypto exchange giving millions of people access to crypto trading and over time becoming among the largest platforms in the world. In recent years, we have developed one of the most connected Web3 wallets used by millions to access decentralized crypto applications (dApps). OKX is a trusted brand by hundreds of large institutions seeking access to crypto markets on a reliable platform that seamlessly connects with global banking and payments. In the last year, OKX has expanded into new markets including Australia, Brazil, Netherlands, Singapore and Turkey, with plans to launch in the US, Belgium and the UAE.

We are deeply committed to shaping a fairer, more transparent and accessible society through blockchain technology. This is why we publish proof of reserves monthly, and continue to ship new innovative security features.
  •  

About OKX Graduate Program (Supernova)
The Supernova Program is a 3-year Career Accelerator Program that aims to fast-track, high performing graduates into technical experts and future leaders mainly in the fields of Product Engineering, Product Management, and Product Design. We firmly believe in the power of the new era. Join us to achieve your narrative around crypto.
 
As a graduate Security Engineer, you will put in your utmost efforts to secure the OKX platform with millions of daily active users. You will work cross-functionally with design, product, and other engineering teams to identify and assess security risks, design and develop advanced security protective mechanisms and products or deliver high-quality thorough security operations and reinforcements. This is an opportunity to learn the full security life cycle of crypto and Web3 platforms and work along with a top-class security team fighting against worldwide security threats.
 

What You’ll Be Doing

  • Designing, developing, and maintaining high-performance backend systems and procedures to support the requirements of client security projects, regulatory, compliance, and infrastructure security best practices.
  • Conducting security audits and vulnerability assessments, vulnerability scanning, and code reviews.
  • Conducting routine checks and tests to ensure that all known vulnerabilities are detected and patched.
  • Maintaining high-quality technical and organizational documentation. Upholding technology best practices and code reviews with peers. Improving efficiency in cross-office/time zone collaboration.
  • Collaborate with team members and functional stakeholders to meet control requirements to demonstrate organizational security compliance
  • Communicate and bridge the gap between external regulatory, audit requirements and internal stakeholder operations.
  • Providing help and consulting to developers on secure coding practices.
  • Optional directions include but are not limited to web security, network security, host and terminal security, data security, threat intelligence, SoC/SIEM/SOAR, Client Security, DevSecOps, etc., respecting personal interests and development intentions.

What We Look For In You

  • Bachelors degree in Computer Science, Technology, Networking, MIS, Engineering, Mathematics, related technical and logical disciplines, or self-taught enthusiasts.
  • Solid basic knowledge of security attack and defense, understanding common vulnerability principles and attack techniques, familiar with the best practices and common solutions of the defense side.
  • Wholistic risk assessment skills to break down complex infrastructural and procedural issues to its basic principles for effective and controllable solutions.
  • Compliance first mindset. Ability to lead by example for internal and external stakeholders. Highlight organizational best practices and embrace our We Before Me principle.
  • Analytical with a positive problem-solving mindset, a proactive team player who embodies a growth mindset, flexible, and comfortable in navigating ambiguity with a global mindset.

Nice to Haves

  • Comfortable with the cloud-based Linux environment. Knowledgeable in distributed architecture. Understanding of kubernetes or container orchestration architecture. Or familiar with daily developing tools such as npm, gulp, webpack, git.
  • Possessing relevant tech stack skillset for the respective specialization - relational databases, OS, network computers, MIS operations, networking protocols, encryption, Identity and Access Management, Change Management/SDLC, cloud service architecture.
  • AliCloud and AWS knowledge and certifications are a strong plus.
  • Familiarity with security risk management and compliance frameworks (i.e. ISO 27001, NIST CSF, SOC 2 Common Criteria, CSA STAR).
  • Security and IT risk certifications from recognized bodies such as ISACA, ISC2, CompTIA, CSA (i.e CISA, CISSP, CCSP, CCSK) are a strong plus.
  • Experience in intrusion detection capability development, and control maintenance, security emergency response, and other related work.
  • Experience in CTF competitions and achieving good results.
Early in the application process, we will be collecting your specialization preference(s). This will be taken into consideration during the interview process to align your skills and interests, where possible. We encourage you to remain open to different parts of the platform. This is particularly beneficial towards your self-development in overall architecture in the long term. 

Perks & Benefits 

  • Competitive total compensation package
  • L&D programs and Education subsidy for employees' growth and development
  • Various team building programs and company events

OKX Statement

The salary range for this position is $125,000-$155,000. The salary offered depends on a variety of factors, including job-related knowledge, skills, experience, and market location. In addition to the salary, a performance bonus and long-term incentives may be provided as part of the compensation package, as well as a full range of medical, financial, and/or other benefits, dependent on the position offered. Applicants should apply via OKX internal or external careers site.
 
OKX is committed to equal employment opportunities regardless of race, color, genetic information, creed, religion, sex, sexual orientation, gender identity, lawful alien status, national origin, age, marital status, and non-job related physical or mental disability, or protected veteran status. Pursuant to the San Francisco Fair Chance Ordinance, we will consider employment-qualified applicants with arrest and conviction records.
Apply for this job

Please mention you found this job on AI Jobs. It helps us get more startups to hire on our site. Thanks and good luck!

Get hired quicker

Be the first to apply. Receive an email whenever similar jobs are posted.

Ace your job interview

Understand the required skills and qualifications, anticipate the questions you may be asked, and study well-prepared answers using our sample responses.

Security Engineer Q&A's
Report this job
Apply for this job