Senior Security Architecture & Governance Engineer
OkxHong Kong, Hong Kong SARPosted 12 March 2026
Tech Stack
Job Description
Who We Are
At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom.
OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves.
Across our multiple offices globally, we are united by our core principles: We Before Me, Do the Right Thing, and Get Things Done. These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er.
OKX is part of OKG, a group that brings the value of Blockchain to users around the world, through our leading products OKX, OKX Wallet, OKLink and more.
Job Responsibilities
Security Review System Virtual Organization Construction
System Establishment: Responsible for building the company-level security review process and governance framework from the ground up (0 to 1), defining collaboration mechanisms, and clarifying rights and responsibilities.
Process Integration: Seamlessly embed security controls into IT change and release processes. Establish security entry and blocking standards (Quality Gates) to ensure full visibility and control over the company's technical changes.
Security Architecture Design Core System Assessment
Architecture Planning: Lead the security architecture design for cloud infrastructure (IaaS/PaaS) and business applications. Formulate high-scalability and high-performance security defense strategies and technical baselines for complex scenarios such as Cloud-Native environments (K8s/Containers) and microservices.
Deep Governance: Conduct specialized security governance for core systems to identify deep-seated architectural risks in product design, system development, and runtime environments; propose systematic remediation plans and lead their implementation.
Governance Operations Executive Decision Support
Visibility Construction: Establish a routine reporting mechanism for security governance and reviews. Clearly present the security posture, major risks, and governance progress to management, providing data support for decision-making.
Closed-Loop Management: Drive relevant stakeholders to resolve bottlenecks identified during reviews. Promote cross-departmental risk remediation and architectural upgrades, ensuring a closed-loop management process from discovery to remediation.
Policy Construction Enablement
Combine industry best practices (e.g., ISO27001, SDL, DevSecOps) with regulatory requirements to improve the company's information security management policies.
Empower RD and Operations teams through virtual groups/teams to enhance overall security awareness.
Requirements
Experience Background
Education: Bachelor’s degree or above in Computer Science, Information Security, or related fields.
Experience: 5+ years of experience in internet/tech companies.
Key Experience: Proven experience in building security review systems from scratch or leading large-scale security governance projects. Experience operating cross-functional virtual organizations is preferred.
Professional Competencies
Architecture Skills: Proficient in mainstream cloud security architectures (AWS/Aliyun). Possesses a strong Application Security background (Web/API/Mobile), with a solid understanding of network, host, and data security principles. Capable of conducting threat modeling, architectural risk assessments, and designing solutions for complex business scenarios.
Offensive Defensive Insight: Deep understanding of common security risks (OWASP Top 10) and attack vectors. Familiar with security development lifecycles (SDL/DevSecOps) and able to guide architectural design from an attacker/defender perspective.
Comprehensive Skills
Reporting Communication: Strong logical thinking and profes ... (truncated, view full listing at source)
More jobs at Okx
See all →More HTML jobs
See all →Senior Product Designer
Aiwyn · Remote (US-based)
Director, Web Strategy
New Relic · Arlington, Virginia, USA; Atlanta, Georgia, USA; Austin, Texas, USA; Baltimore, Maryland, USA; Charlotte, North Carolina, USA; Chicago, Illinois, USA; Cleveland, Ohio, USA; Hartford, Connecticut, USA; Houston, Texas, USA; Jersey City, New Jersey, USA; Raleigh, North Carolina, USA
Growth Web Engineer
New Relic · Arlington, Virginia, USA; Atlanta, Georgia, USA; Austin, Texas, USA; Chicago, Illinois, USA; Hartford, Connecticut, USA; Jersey City, New Jersey, USA; Raleigh, North Carolina, USA
Senior Product Manager LIVE Encoding
Bitmovin · Vienna, Klagenfurt, London