Staff Engineer, Security Platform Development
3 нед. назад
Hong KongSingaporeWorldwideLead
devsecopssecurity engineering
Staff Engineer responsible for building out security engineering and DevSecOps capabilities, designing security products, platform services, and SDKs/Agents for embedding protection into software lifecycle.
Обязанности
- This is a role for someone with real depth in security, broad coverage across the stack, and the engineering muscle to ship. Just as important is the ability to drive adoption — security that lands in complex, fast-moving business environments rather than sitting in a policy document.
-
Будет плюсом
- Security engineering experience at a top-tier internet company, cloud provider, or leading security vendor
- You've led the build of a DevSecOps platform, application security platform, RASP, code scanning platform, or cloud-native security platform
- Background in security product development, SDK/Agent engineering, vulnerability research, red team exercises, or purple team work
- Shipped AI + Security work — security copilots, intelligent rule generation, automated analysis, or remediation recommendation systems
Условия
- Competitive total compensation package
- L&D programs and Education subsidy for employees' growth and development
- Various team building programs and company events
- Wellness and meal allowances
- Comprehensive healthcare schemes for employees and dependants
- More that we love to tell you along the process!
Другое
- Architect and build our end-to-end DevSecOps platform and the SDKs/Agents behind our security products, covering code, build, artifacts, images, deployment, and runtime.
- Lead runtime protection through RASP and Java Agent — bytecode instrumentation, runtime hooking, and detection/interception engines using ASM, ByteBuddy, and Instrumentation, with continuous tuning for performance, stability, and compatibility.
- Integrate and productise scanning capabilities across SAST, DAST, IAST, SCA, code scanning, and image scanning. You'll embed tools like SonarQube and Coverity deep into CI/CD and close the loop from detection through blocking, remediation, and re-test.
- Go deep on application security offence and defence — designing detection, remediation, hardening, and counter-measures for XSS, SQL injection, SSRF, deserialisation, command execution, authentication/authorisation flaws, and API security.
- Bring AI-native security engineering to life. Apply LLMs and AI Agents to vulnerability analysis, rule generation, false-positive attribution, remediation guidance, security knowledge capture, and engineering automation — and build a coherent view of the architecture, mechanics, and security implications.
- Embed as the security technical expert inside engineering teams, driving security standards, onboarding specifications, release gates, risk tiering, and remediation mechanisms that measurably lift the security baseline and delivery quality.
- Partner across engineering, architecture, SRE, QA, and business teams on priority projects, solving the genuinely hard security problems and turning the solutions into reusable platform capability and repeatable practice.
- Strong computer science and security fundamentals — deep understanding of operating systems, networking, compilers and the JVM, distributed systems, application security, cloud-native security, and supply chain security. Both breadth and depth.
- Expert-level Java, with hands-on depth in the JVM, ClassLoader, Java Agent, ASM, ByteBuddy, bytecode instrumentation, and performance profiling and tuning. Plus working proficiency in Python or Go.
- Substantial production experience with RASP, SAST, DAST, IAST, SCA, image security, and code scanning — enough to design a capability, integrate the engine, build the platform around it, and take it to scale independently.
- Real offensive and defensive experience. You understand the root causes, exploitation paths, detection logic, bypass techniques, and fixes for common web, API, and microservices vulnerabilities — and can design from both the attacker's and defender's point of view.
- Fluency with LLMs and AI Agents, including a considered view on model capability limits, agent architecture, tool calling, context engineering, evaluation methods, and how AI is reshaping both security engineering and the attack surface.
- Strong engineering execution paired with product instinct — able to lead the design and delivery of security products, platform modules, and SDKs/Agents while balancing security outcomes against performance overhead, integration cost, and long-term operability.
- Exceptional ownership, cross-team communication, and the persistence to move security governance, rule enforcement, and remediation through to a clear result.