Tbwa Chiat/Day Inc | Senior

4 days ago


Singapore Tbwa ChiatDay Inc Full time

Senior / Staff Software Engineer - DevSecOps Security Expert (Developer)
Who We Are
At OKX, we believe that the future will be reshaped by Crypto, ultimately contributing to every individual's freedom.
OKX began as a crypto exchange giving millions of people access to crypto trading and over time becoming among the largest platforms in the world. In recent years, we have developed one of the most connected Web3 wallets used by millions to access decentralized crypto applications (dApps).
OKX is a trusted brand by hundreds of large institutions seeking access to crypto markets on a reliable platform that seamlessly connects with global banking and payments. In the last year, OKX has expanded into new markets including Australia, Brazil, Netherlands, Singapore and Turkey, with plans to launch in the US, Belgium and the UAE.
We are deeply committed to shaping a fairer, more transparent and accessible society through blockchain technology. This is why we publish proof of reserves monthly, and continue to ship new innovative security features.
About the Opportunity
This opportunity focuses on supporting the development and iteration of the DevSecOps DAST scanning engine within security products, with a goal of enhancing scanning efficiency, detection rates, and coverage. You will analyze the scope and priority of identified vulnerabilities, develop and optimize scanning and suppression rules, and ensure accurate and reliable detection. Additionally, you will play a key role in governing existing business operations to strengthen security management and drive continuous improvement.
What You’ll Be Doing
Develop and maintain the DevSecOps DAST scanning engine.
Write and optimize DAST scanning rules based on complex application scenarios, verify vulnerabilities identified by the DAST scanning engine, and ensure the accuracy of vulnerability scanning and reproduction.
Analyze the scope and priority of identified vulnerabilities, formulate false positive suppression rules, and improve the accuracy of vulnerability identification.
Continuously iterate the DAST engine, optimize the scanning process, improve scanning efficiency and detection rate, and enhance scanning coverage.
Collaborate with development, operations, and security teams to support vulnerability remediation and security improvements, providing recommendations for security hardening.
Provide technical support and training to team members, promoting best practices in security governance.
What We Look For In You
Minimum 5 years of experience in DevSecOps or related fields.
Familiar with the principles and practical applications of DAST, capable of handling the development and construction of the scanning engine.
Solid proficiency in Golang and/or Java, able to write automation scripts to support vulnerability scanning, remediation, and engine optimization.
Proficient with DAST tools (such as AWVS, Xray, Burp Suite, etc.) for vulnerability scanning, and able to customize scanning rules for specific business needs.
Able to analyze and address false positives and false negatives in the DAST scanning engine.
Deep understanding of microservices architecture, with familiarity in vulnerability reproduction in microservice and RPC environments.
Familiar with common web application vulnerabilities (such as SQL injection, XSS, CSRF, file upload vulnerabilities, etc.), their principles, and remediation measures.
Familiar with the DevSecOps process, able to integrate DAST tools and scanning engines into CI/CD pipelines.
Strong problem analysis skills and technical documentation writing abilities, capable of analyzing vulnerability reports and providing feasible remediation solutions.
Good communication and teamwork skills, with the ability to collaborate closely with cross-functional teams to implement security initiatives.
Nice to Haves
Experience with other security testing tools and methodologies.
Relevant security certifications.
Familiarity with containerization technologies and cloud-native architectures, with practical experience in DAST scanning in cloud environments.
Experience in DAST engine development is a plus.
Apply for this job
* indicates a required field
First Name *
Last Name *
Email *
Phone *
Location (City) *
Resume/CV *
Enter manually
Accepted file types: pdf, doc, docx, txt, rtf
Education
School Select...
Degree Select...
Start date year
End date year
Do you have any tech experience working in a Java environment like Springboot, Spring Cloud in any part of your career? * Select...
Are you legally authorized to work in the advertised location for this role? * Select...
Please indicate if you are a Singapore Citizen, Permanent Resident, or if you require a work pass to work and reside in Singapore. For work pass holders, kindly also specify which pass you are currently holding, if applicable. * Select...
Which company are you currently employed or last employed with? *
What is your notice period to your current employer? * Select...
#J-18808-Ljbffr



  • Singapore Tbwa ChiatDay Inc Full time

    GenScript Biotech Corporation (Stock Code: 1548.HK) is a global biotechnology group. Founded in 2002, GenScript has an established global presence across North America, Europe, the Greater China, and Asia Pacific. GenScript's businesses encompass four major categories based on its leading gene synthesis technology, including operation as a Life Science...


  • Singapore Tbwa ChiatDay Inc Full time

    GenScript Biotech Corporation (Stock Code: 1548.HK) is a global biotechnology group. Founded in 2002, GenScript has an established global presence across North America, Europe, the Greater China, and Asia Pacific. GenScript's businesses encompass four major categories based on its leading gene synthesis technology, including operation as a Life Science...


  • Singapore Tbwa ChiatDay Inc Full time

    Senior Client Services Account Executive Nucleus Global is a leading healthcare communications group with employees around the globe. Our clients are top global pharmaceutical companies, scientific societies and non-governmental organisations. We place the highest value on the scientific knowledge and expertise of our employees in the belief that good...


  • Singapore Tbwa ChiatDay Inc Full time

    Recruiter, Sales (Contractor) - Australia or Singapore GitLab is an open core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create the software that powers our world. When everyone can contribute, consumers become...


  • Singapore Tbwa ChiatDay Inc Full time

    FalconX is a pioneering team of operators, investors, and builders committed to revolutionizing institutional access to the crypto markets. Operating at the intersection of traditional finance and cutting-edge technology, FalconX addresses the industry's foremost challenges: Navigating the digital asset market can be complex and fragmented, with limited...


  • Singapore Tbwa ChiatDay Inc Full time

    About DKatalis DKatalis is a financial technology company with multiple offices in the APAC region. In our quest to build a better financial world, one of our key goals is to create an ecosystem linked financial services business. DKatalis is built and backed by experienced and successful entrepreneurs, bankers, and investors in Singapore and Indonesia who...


  • Singapore Tbwa ChiatDay Inc Full time

    About GenScript GenScript Biotech Corporation (Stock Code: 1548.HK) is a global biotechnology group. Founded in 2002, GenScript has an established global presence across North America, Europe, the Greater China, and Asia Pacific. GenScript's businesses encompass four major categories based on its leading gene synthesis technology, including operation as...


  • Singapore Tbwa ChiatDay Inc Full time

    Please note that we will only be able to accept candidates who have the appropriate rights and documentation for employment in Singapore. Who we are. Axi is a leading global provider of margin and deliverable Foreign Exchange, Contracts for Difference (CFDs), and Financial Spread betting. Our business has evolved into a world-class, multifaceted brokerage...


  • Singapore Tbwa ChiatDay Inc Full time

    Orkes is a platform for developers to build durable, distributed event driven applications. Based on the popular open source orchestration engine Conductor, Orkes lets developers focus on faster go to market with applications, scaling them to handle billions of workflows without having to worry about failures, scalability or visibility into the executions....


  • Singapore Tbwa ChiatDay Inc Full time

    DKatalis is a financial technology company with multiple offices in the APAC region. In our quest to build a better financial world, one of our key goals is to create an ecosystem linked financial services business. DKatalis is built and backed by experienced and successful entrepreneurs, bankers, and investors in Singapore and Indonesia who have more than...


  • Singapore Tbwa ChiatDay Inc Full time

    Paradex isn’t just another decentralized exchange—it’s a Super App. We’ve combined three powerful financial primitives: Exchange, Asset Management, and Borrow/Lend Markets, all seamlessly composable and accessible through one unified account that uses your entire portfolio as collateral, including any spot and derivative assets. Trade, earn, borrow,...


  • Singapore Tbwa ChiatDay Inc Full time

    OKX will be prioritising applicants who have a current right to work in Singapore, and do not require OKX's sponsorship of a visa. (We are open to hire from junior to senior levels)Who We Are At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom. OKX is a leading crypto exchange, and...


  • Singapore Tbwa ChiatDay Inc Full time

    OKX will be prioritizing applicants who have a current right to work in Singapore and do not require OKX's sponsorship of a visa. (We are open to hire from junior to senior levels)Who We Are At OKX, we believe that the future will be reshaped by Crypto, ultimately contributing to every individual's freedom. OKX began as a crypto exchange giving...


  • Singapore Tbwa ChiatDay Inc Full time

    OKX will be prioritising applicants who have a current right to work in Singapore, and do not require OKX's sponsorship of a visa. Who We Are At OKX, we believe that the future will be reshaped by Crypto, ultimately contributing to every individual's freedom. OKX began as a crypto exchange giving millions of people access to crypto trading and over...


  • Singapore Tbwa ChiatDay Inc Full time

    At Paradigm, we are changing the future of finance! By joining us at this early stage, you’ll be building cutting-edge, distributed financial service infrastructure that will reshape financial services across CeFi and DeFi markets. About Paradigm Paradigm is a zero-fee, institutional liquidity network for derivatives traders across CeFi and DeFi. We...


  • Singapore Tbwa ChiatDay Inc Full time

    Workato is the only integration and automation platform that is as simple as it is powerful — and because it’s built to power the largest enterprises, it is quite powerful. Simultaneously, it’s a low-code/no-code platform. This empowers any user (dev/non-dev) to painlessly automate workflows across any apps and databases. We’re proud to be named a...


  • Singapore Tbwa ChiatDay Inc Full time

    Diligent is the global leader in modern governance, providing SaaS solutions across governance, risk, compliance, audit and ESG. Empowering more than 1 million users and 700,000 board members and leaders with a holistic view of their organization’s GRC practices so they can make better decisions, faster. No matter the challenge. At Diligent, you are an...


  • Singapore Tbwa ChiatDay Inc Full time

    OceanX is a mission to explore the ocean and to bring it back to the world through captivating media. Uniting leading media, science, and philanthropy partners, OceanX utilizes next-gen technology, cutting edge science, compelling storytelling, and immersive experiences to educate, inspire, and connect the world with the ocean and build a global community...


  • Singapore Tbwa ChiatDay Inc Full time

    Easyship is revolutionizing logistics for eCommerce. With our all-in-one cloud based shipping software, businesses of all shapes and sizes have the tools needed to scale globally. At Easyship we believe in accelerating borderless commerce. We’re proud that a diversity of small business owners, crowdfunding campaigns, and global brands trust Easyship as...


  • Singapore Tbwa ChiatDay Inc Full time

    We are seeking an experienced Technical Support Manager to lead our technical support team. The ideal candidate will be responsible for ensuring exceptional customer service, overseeing technical support operations in our APAC region, and driving continuous improvement initiatives. This role requires a strong technical background, excellent leadership...