Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com

AI Agent Security Research Engineer

OKX
๐Ÿ‡ฆ๐Ÿ‡บ Australia | ๐Ÿ‡ง๐Ÿ‡ฉ Bangladesh | ๐Ÿ‡จ๐Ÿ‡ณ China | ๐Ÿ‡ซ๐Ÿ‡ฏ Fiji | ๐Ÿ‡ญ๐Ÿ‡ฐ Hong Kong | ๐Ÿ‡ฎ๐Ÿ‡ฉ Indonesia | ๐Ÿ‡ฎ๐Ÿ‡ณ India | ๐Ÿ‡ฏ๐Ÿ‡ต Japan | ๐Ÿ‡ฐ๐Ÿ‡ฌ Kyrgyzstan | ๐Ÿ‡ฐ๐Ÿ‡ญ Cambodia | ๐Ÿ‡ฐ๐Ÿ‡ท South Korea | ๐Ÿ‡ฐ๐Ÿ‡ฟ Kazakhstan | ๐Ÿ‡ฑ๐Ÿ‡ฆ Laos | ๐Ÿ‡ฑ๐Ÿ‡ฐ Sri Lanka | ๐Ÿ‡ฒ๐Ÿ‡ฒ Myanmar | ๐Ÿ‡ฒ๐Ÿ‡ณ Mongolia | ๐Ÿ‡ฒ๐Ÿ‡ป Maldives | ๐Ÿ‡ฒ๐Ÿ‡พ Malaysia | ๐Ÿ‡ณ๐Ÿ‡ต Nepal | ๐Ÿ‡ณ๐Ÿ‡ฟ New Zealand | ๐Ÿ‡ต๐Ÿ‡ญ Philippines | ๐Ÿ‡ต๐Ÿ‡ฐ Pakistan | ๐Ÿ‡ธ๐Ÿ‡ฌ Singapore | ๐Ÿ‡น๐Ÿ‡ญ Thailand | ๐Ÿ‡น๐Ÿ‡ฏ Tajikistan | ๐Ÿ‡น๐Ÿ‡ฒ Turkmenistan | ๐Ÿ‡น๐Ÿ‡ผ Taiwan | ๐Ÿ‡บ๐Ÿ‡ฟ Uzbekistan | ๐Ÿ‡ป๐Ÿ‡ณ Vietnam
On-site
Staff / Principal
4 months ago
  • AI
  • RAG
  • DevSecOps
  • GitLab CI/CD
  • Jenkins
  • Threat Intelligence
  • OWASP
  • Python
  • Java
  • LangChain
  • LlamaIndex
  • AutoGen
  • CrewAI
  • LangGraph
  • Docker
  • Kubernetes
  • Microservices
  • SAST
  • CodeQL
  • Semgrep
  • SonarQube
  • LoRA
  • GitHub
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

Who We Are

At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom.ย 

OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves.

Across our multiple offices globally, we are united by our core principles: We Before Me, Do the Right Thing, and Get Things Done. These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er.

OKX is part of OKG, a group that brings the value of Blockchain to users around the world, through our leading products OKX, OKX Wallet, OKLink and more.


Responsibilities

  • AI-Driven Code Security Detection Engine
    1. Design and implement a multi-agent collaborative code auditing system covering vulnerability detection, malicious code identification, and sensitive information leakage scenarios; lead the role decomposition of Planners/Executors/Critics, tool invocation chains, and cross-agent state synchronization mechanism design.

    2. Integrate RAG, Chain-of-Thought, Reflection, and other technologies into security audit agents. Continuously optimize detection accuracy and recall rates while establishing a quantifiable evaluation and iteration framework.
    3. Deeply integrate with DevSecOps workflows. Develop plugins for mainstream pipelines like GitLab CI/CD, Tekton, and Jenkins to achieve โ€œaudit-on-commit.โ€
  • AI System Security Protection and Threat Response
    1. Responsible for constructing a security protection framework for large language model applications, covering three dimensions: input layer (prompt injection, jailbreak detection), output layer (sensitive information leakage, compliance auditing), and runtime (tool invocation sandboxing, anomaly behavior circuit breaking).

    2. Develop Agent workflows for automated alert classification, contextual correlation, and false positive filtering. Integrate RAG-driven threat intelligence retrieval to generate automated analysis conclusions, supporting SOAR platform integration.
    3. Design human-machine collaboration intervention mechanisms and Agent behavior audit systems to ensure observability, traceability, and intervenability of Agent actions in production environments, adhering to industry standards like the OWASP Top 10 Risks for LLMs.
  • Engineering Development and Platform Services
    1. Construct a highly available, scalable Agent service architecture supporting large-scale concurrent scanning task scheduling and fault tolerance.
    2. Oversee standardized API output for detection capabilities, building closed-loop systems for rule management, result visualization, and false positive feedback.

Requirements

  • Development Experience: 3+ years of backend development experience, proficient in at least one of Python/Go/Java, with a solid engineering foundation.
  • Agent Implementation & Security: Hands-on experience deploying LLM Agents (not just demos), capable of detailing engineering challenges such as Agent architecture design, hallucination handling, and tool invocation fault tolerance; Hands-on experience with AI security, understanding risks like prompt injection, jailbreaking, malicious agent injection, and tool misuse, with implementable defense strategies.
  • Framework Proficiency: Familiarity with at least one agent framework (LangChain, LlamaIndex, AutoGen, CrewAI, or LangGraph), with production project experience.
  • Engineering Capabilities: Proficient in Docker and Kubernetes, with expertise in microservices architecture design and deployment.

Preferred Qualifications

  • Security Tool Experience: Experience with SAST/SCA tools, or deep usage of code auditing tools like CodeQL, Semgrep, or SonarQube.
  • Model Fine-Tuning: Experience with LLM fine-tuning (SFT, LoRA), or familiarity with local deployment and optimization of models like Llama 3, Qwen, or DeepSeek. Bonus points for security-domain fine-tuning experience, such as training and evaluating security detection models for malicious prompt detection, unauthorized access identification, or harmful content filtering.
  • Open-Source Contributions: High-quality open-source projects related to agents on GitHub, or pull requests submitted to mainstream LLM frameworks.
  • Security Competitions: Awards from CTF competitions, or a track record of submitting CVE/CNVD vulnerabilities.


Perks & Benefits

  • Competitive total compensation package
  • L&D programs and Education subsidy for employees' growth and development
  • Various team building programs and company events
  • Wellness and meal allowances
  • Comprehensive healthcare schemes for employees and dependants
  • More that we love to tell you along the process!


    Please note that Hong Kong is a group-level service hub, andย OKXย does not carry on a business of operating a virtual asset trading platform in Hong Kong.
Notice:
All officialOKX vacancies are published on this website.While roles may appear on selected third-party platforms from time to time, information on other sites may be inaccurate or outdated.If in doubt, please apply directly through our official careers website.Information collected and processed as part of the recruitment process of any job application you choose to submit is subject toย OKX'sCandidate Privacy Notice.

AI Agent Security Research Engineer ยท OKX

Auto apply with Likeremote