Senior / Staff Software Engineer - DevSecOps Security Expert

2 weeks ago


Singapore Tbwa ChiatDay Inc Full time

Senior / Staff Software Engineer - DevSecOps Security Expert
Who We Are
At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom. OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves. Across our multiple offices globally, we are united by our core principles:
We Before Me ,
Do the Right Thing , and
Get Things Done . These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er.
About the Opportunity
This role offers the opportunity to lead vulnerability management efforts from a security and compliance perspective, ensuring a complete governance lifecycle. You will analyze the scope and priority of vulnerabilities, develop scanning and suppression rules for SAST, DAST, and IAST, and contribute to the accuracy and efficiency of detection processes. In complex scenarios, you will reproduce vulnerabilities and establish standardized SOPs for vulnerability handling and secure coding practices. Additionally, you will focus on governing existing business operations to enhance overall security capabilities and ensure sustainable improvements.
What You’ll Be Doing
Govern security vulnerabilities discovered by SAST and DAST, complete the remediation process, and enhance overall enterprise security.
Integrate security requirements based on business scenarios, optimize vulnerability scanning and remediation processes, and improve handling efficiency.
Reproduce vulnerabilities in complex environments and optimize various SOPs for vulnerability handling and secure coding practices to ensure successful implementation.
Develop and maintain scanning rules and suppression rules for SAST, DAST, and IAST, including but not limited to Fortify, CodeQL, Xray, AWVS, etc.
Perform comprehensive code audits to improve vulnerability coverage, accuracy, and ensure code security and compliance.
Provide technical guidance and support to team members on security best practices.
What We Look For In You
Minimum 5 years of experience in DevSecOps or related fields.
Proficient in the principles and practices of SAST, DAST, and IAST.
Extensive experience using various scanning engines for code auditing and developing scanning rules.
Deep understanding of microservices architecture, with familiarity in reproducing vulnerabilities in microservice and RPC environments.
Knowledge of service chain tracking technologies.
Able to reproduce and resolve complex environment vulnerabilities identified by SAST, DAST, and IAST.
Strong development skills in Java and/or Golang.
Excellent problem-solving abilities and attention to detail.
Strong communication and teamwork skills.
Nice to Haves
Familiarity with application layer and cloud-native architecture, as well as related security governance.
Relevant security certifications.
Experience developing open-source security tools or involvement in the development and optimization of vulnerability scanning engines and governance platforms.
Familiarity with common web application architectures and their security vulnerabilities, with solid experience in vulnerability reproduction and remediation.
Apply for this job
* indicates a required field
First Name *
Last Name *
Email *
Phone *
Location (City) *
Resume/CV *
Education
School Select...
Degree Select...
Start date year
End date year
Are you legally authorized to work in the advertised location for this role? * Select...
Please indicate if you are a Singapore Citizen, Permanent Resident, or if you require a work pass to work and reside in Singapore. For work pass holders, kindly also specify which pass you are currently holding, if applicable. * Select...
Which company are you currently employed or last employed with? *
What is your notice period to your current employer? * Select...
#J-18808-Ljbffr


  • OKX | Senior

    3 days ago


    Singapore OKX Full time

    Senior / Staff Software Engineer - DevSecOps Security Expert (Developer)Company: OKX Buy BTC, ETH, XRP and more on OKX, a leading crypto exchange – explore Web3, invest in DeFi and NFTs. Register now and experience the future of finance. Who We Are At OKX, we believe that the future will be reshaped by Crypto, ultimately contributing to every...

  • OKX | Senior

    3 days ago


    Singapore OKX Full time

    Senior / Staff Software Engineer - DevSecOps Security Expert (Operations)Who We Are At OKX, we believe that the future will be reshaped by Crypto, ultimately contributing to every individual's freedom. OKX began as a crypto exchange giving millions of people access to crypto trading and over time becoming among the largest platforms in the world. In...


  • Singapore Tbwa ChiatDay Inc Full time

    Senior / Staff Software Engineer - DevSecOps Security Expert (Developer)Who We Are At OKX, we believe that the future will be reshaped by Crypto, ultimately contributing to every individual's freedom. OKX began as a crypto exchange giving millions of people access to crypto trading and over time becoming among the largest platforms in the world. In...


  • Singapore minden.ai Full time

    minden.ai is a technology venture founded by Temasek in strategic partnership with DFI Retail Group and coalition partners Breadtalk Group, DBS Bank, PAssion Card, Mandai Wildlife Group, Singtel, Great Eastern, FoodPanda and GoJek. We are on a mission to redefine how brands engage with their customers through the power of machine learning and artificial...


  • Singapore Abnormal Security Corporation Full time

    About the Role Abnormal Security is looking for a Staff Software Engineer to act as a technical lead for the APAC leg of the Multi-Product Platform division. We are responsible for demonstrating Abnormal’s value to our customers & providing them with a smooth journey, from demo to post-purchase. At Abnormal, we keep our customers—ranging from Global...


  • Singapore Secur Solutions Group Full time

    (Only Singaporean will be considered)Job Description: The DevSecOps Engineer works along with the Project teams to onboard new squads in the DevOps environment. DevSecOps Engineers will guide them for continuous integration, continuous deployment and continuous testing. DevSecOps Engineer works closely with the development team and operation team to create...

  • DevSecOps Engineer

    3 weeks ago


    Singapore RAPSYS TECHNOLOGIES PTE. LTD. Full time

    Roles & ResponsibilitiesDEVSECOPS ENGINEER RESPONSIBILITY • Develop automation and processes to enable teams to deploy, manage scale and monitor their applications in data centers and in cloud • System troubleshooting and problem solving across platform and application domains, expect to participate in on-call escalations to...

  • DevSecOps Engineer

    3 weeks ago


    Singapore RAPSYS TECHNOLOGIES PTE. LTD. Full time

    Roles & ResponsibilitiesDEVSECOPS ENGINEER RESPONSIBILITY • Develop automation and processes to enable teams to deploy, manage scale and monitor their applications in data centers and in cloud • System troubleshooting and problem solving across platform and application domains, expect to participate in on-call escalations to...

  • DevSecOps Engineer

    2 weeks ago


    Singapore HORIZON GLOBAL SERVICES PTE. LTD. Full time

    Roles & ResponsibilitiesResponsibilities: Lead the planning, implementation, and management of secure system architecture. Oversee the development and optimization of automation systems to address system bottlenecks and ensure maximum service availability. Manage advanced CI/CD pipelines and automate integration and deployment in enterprise environments. ...

  • DevSecOps Engineer

    2 weeks ago


    Singapore HORIZON GLOBAL SERVICES PTE. LTD. Full time

    Roles & ResponsibilitiesResponsibilities: Lead the planning, implementation, and management of secure system architecture. Oversee the development and optimization of automation systems to address system bottlenecks and ensure maximum service availability. Manage advanced CI/CD pipelines and automate integration and deployment in enterprise environments. ...


  • Singapore PERSOLKELLY SINGAPORE PTE. LTD. Full time

    Job SummaryWe are seeking an experienced Senior Software Development Engineer to lead our AI infrastructure team. As a key member of our engineering department, you will design, develop, and deploy scalable and secure AI infrastructure solutions.Key ResponsibilitiesDevelop and maintain large-scale software systems for AI infrastructure deployment and...


  • Singapore MAESTRO HUMAN RESOURCE PTE. LTD. Full time

    Job Description:Are you a motivated and experienced software developer looking to take your career to the next level? Do you have a passion for delivering high-quality, secure, and scalable applications?We are seeking a talented Senior Software Engineer to join our team at Maestro HR in AMK. As a key member of our development team, you will play a crucial...

  • Senior Engineer

    4 weeks ago


    Singapore Cannon Security Products Full time

    OKX will be prioritising applicants who have a current right to work in Singapore, and do not require OKX's sponsorship of a visa Who We Are At OKX, we believe the future will be reshaped by technology. Founded in 2017, we are revolutionising world systems through our cutting-edge digital asset exchange, Web3 portal and blockchain ecosystems. We reshape...


  • Singapore ACTIVATE INTERACTIVE PTE LTD Full time

    Company OverviewActivate Interactive Pte Ltd is a leading technology consultancy headquartered in Singapore with a presence in Malaysia and Indonesia. We empower our clients with quality, cost-effective, and impactful end-to-end application development, like mobile and web applications, and cloud technology that remove technology roadblocks and increase...


  • Singapore GIC Private Limited Full time

    AVP, Cyber Security Engineering (DevSecOps & Cloud Security), COO Office Location: Singapore, SG Job Function: Chief Operating Officer’s Office Job Type: Permanent GIC is one of the world’s largest sovereign wealth funds. With over 2,000 employees across 11 locations around the world, we invest in more than 40 countries globally across asset classes and...


  • Singapore Perx Technologies Pte. Ltd Full time

    About Perx: Perx Technologies introduces the world’s first intelligent, autonomous loyalty and customer engagement solution. Headquartered in Singapore, the platform synergizes gamification, behavioral science, and AI to support brands in elevating customer actions and interactions using data-driven experiences. By designing customized, incentive-driven...


  • Singapore DEXIAN SINGAPORE PTE. LTD. Full time

    Roles & ResponsibilitiesOur client is a leading security solutions provider based in Singapore, with years of experience delivering secure, reliable, and cutting-edge solutions. Specializing in end-to-end services, the company offers complete turn-key solutions, from design and development to integration, testing, commissioning, and post-implementation...

  • DevSecOps Engineer

    3 weeks ago


    Singapore IBM SINGAPORE PTE LTD Full time

    Roles & Responsibilities• Work along with the Project teams to onboard new squads in the DevOps environment.• Guiding the continuous integration, continuous deployment and continuous testing.• Work closely with the development team and operation team to create DevOps strategy and toolset that suits the individual squads.• Setup, deploy and maintain...

  • DevSecOps Engineer

    3 weeks ago


    Singapore IBM SINGAPORE PTE LTD Full time

    Roles & Responsibilities• Work along with the Project teams to onboard new squads in the DevOps environment.• Guiding the continuous integration, continuous deployment and continuous testing.• Work closely with the development team and operation team to create DevOps strategy and toolset that suits the individual squads.• Setup, deploy and maintain...


  • Singapore RECRUIT EXPERT PTE. LTD. Full time

    Job Title:Senior Automation and Security Systems EngineerAbout the Role:We are seeking an experienced Senior Automation and Security Systems Engineer to join our team at RECRUIT EXPERT PTE. LTD.Job Description:The successful candidate will be responsible for leading project management, implementation, and maintenance services of security systems, including...