OKX logo
Senior Security Architecture & Governance Engineer
full-timeHong Kong Island

Summary

Location

Hong Kong Island

Type

full-time

Explore Jobs

About this role

Who We Are


At OKX, we believe that the future will be reshaped by crypto, and ultimately contribute to every individual's freedom. 


OKX is a leading crypto exchange, and the developer of OKX Wallet, giving millions access to crypto trading and decentralized crypto applications (dApps). OKX is also a trusted brand by hundreds of large institutions seeking access to crypto markets. We are safe and reliable, backed by our Proof of Reserves.


Across our multiple offices globally, we are united by our core principles: We Before Me, Do the Right Thing, and Get Things Done. These shared values drive our culture, shape our processes, and foster a friendly, rewarding, and diverse environment for every OK-er.


OKX is part of OKG, a group that brings the value of Blockchain to users around the world, through our leading products OKX, OKX Wallet, OKLink and more.



Job Responsibilities


Security Review System & Virtual Organization Construction



  • System Establishment: Responsible for building the company-level security review process and governance framework from the ground up (0 to 1), defining collaboration mechanisms, and clarifying rights and responsibilities.

  • Process Integration: Seamlessly embed security controls into IT change and release processes. Establish security entry and blocking standards (Quality Gates) to ensure full visibility and control over the company's technical changes.


Security Architecture Design & Core System Assessment



  • Architecture Planning: Lead the security architecture design for cloud infrastructure (IaaS/PaaS) and business applications. Formulate high-scalability and high-performance security defense strategies and technical baselines for complex scenarios such as Cloud-Native environments (K8s/Containers) and microservices.

  • Deep Governance: Conduct specialized security governance for core systems to identify deep-seated architectural risks in product design, system development, and runtime environments; propose systematic remediation plans and lead their implementation.


Governance Operations & Executive Decision Support



  • Visibility Construction: Establish a routine reporting mechanism for security governance and reviews. Clearly present the security posture, major risks, and governance progress to management, providing data support for decision-making.

  • Closed-Loop Management: Drive relevant stakeholders to resolve bottlenecks identified during reviews. Promote cross-departmental risk remediation and architectural upgrades, ensuring a closed-loop management process from discovery to remediation.


Policy Construction & Enablement



  • Combine industry best practices (e.g., ISO27001, SDL, DevSecOps) with regulatory requirements to improve the company's information security management policies.

  • Empower R&D and Operations teams through virtual groups/teams to enhance overall security awareness.



Requirements


Experience & Background



  • Education: Bachelor’s degree or above in Computer Science, Information Security, or related fields.

  • Experience: 5+ years of experience in internet/tech companies.

  • Key Experience: Proven experience in building security review systems from scratch or leading large-scale security governance projects. Experience operating cross-functional virtual organizations is preferred.


Professional Competencies



  • Architecture Skills: Proficient in mainstream cloud security architectures (AWS/Aliyun). Possesses a strong Application Security background (Web/API/Mobile), with a solid understanding of network, host, and data security principles. Capable of conducting threat modeling, architectural risk assessments, and designing solutions for complex business scenarios.

  • Offensive & Defensive Insight: Deep understanding of common security risks (OWASP Top 10) and attack vectors. Familiar with security development lifecycles (SDL/DevSecOps) and able to guide architectural design from an attacker/defender perspective.



Comprehensive Skills



  • Reporting & Communication: Strong logical thinking and professional writing skills (adept at writing governance weekly updates and analysis reports). Excellent cross-departmental communication and coordination skills to effectively drive cooperation between business and operations teams for remediation.

  • Project Management: Result-oriented. PMP certification or security certifications (CISSP, CISA, CCSP) are preferred.



Perks & Benefits



  • Competitive total compensation package.

  • L&D programs and Education subsidy for employees' growth and development.

  • Various team building programs and company events.

  • Wellness and meal allowances.

  • Comprehensive healthcare schemes for employees and dependants .

  • More that we love to tell you along the process!


 


Please note that Hong Kong is a group-level service hub, and OKX does not carry on a business of operating a virtual asset trading platform in Hong Kong.


 

Notice:

All official OKX vacancies are published on this website. While roles may appear on selected third-party platforms from time to time, information on other sites may be inaccurate or outdated. If in doubt, please apply directly through our official careers website.


Information collected and processed as part of the recruitment process of any job application you choose to submit is subject to OKX's Candidate Privacy Notice.

Other facts

Tech stack
Security Architecture,Governance Framework,Cloud Security,Application Security,Threat Modeling,Risk Assessment,Cross-Departmental Communication,Project Management,ISO27001,DevSecOps,PMP Certification,CISSP,CISA,CCSP,Security Review Systems,Governance Reporting

About OKX

At OKX, we believe that the future will be reshaped by Crypto, ultimately contributing to every individual's freedom.

OKX began as a crypto exchange giving millions of people access to crypto trading and over time becoming among the largest platforms in the world. In recent years, we have developed one of the most connected Web3 wallets used by millions to access decentralized crypto applications (dApps).

OKX is a trusted brand by hundreds of large institutions seeking access to crypto markets on a reliable platform that seamlessly connects with global banking and payments. In the last year, OKX has expanded into new markets including Australia, Brazil, Netherlands, Singapore and Turkey, with plans to launch in the US, Belgium and the UAE.

We are deeply committed to shaping a fairer, more transparent and accessible society through blockchain technology. This is why we publish proof of reserves monthly, and continue to ship new innovative security features.

We believe in good sportmanship and the pursuit to be better. You may see our OKX logo neatly fitted on the McLaren F1 cars, Manchester City FC team shirts, or at the Tribeca Film Festival celebrating artists and creators. Wherever you may find us, you will notice our pursuit of making our world more efficient, transparent, and connected.

To learn more about OKX, download our app or visit: www.okx.com

UK users follow: https://www.linkedin.com/company/okxuk/

Learn more about working at OKG, the business group developing OKX, our Digital Assets Exchange, our Web3 portal and blockchain ecosystems: bit.ly/WorkingatOKG

Team size: 1,001-5,000 employees
LinkedIn: Visit
Industry: Technology, Information and Internet

What you'll do

  • The Senior Security Architecture & Governance Engineer will be responsible for building the company's security review process and governance framework, integrating security controls into IT processes, and leading security architecture design. Additionally, they will conduct security governance for core systems and establish reporting mechanisms for security posture and risks.

Ready to join OKX?

Take the next step in your career journey

Frequently Asked Questions

What does a Senior Security Architecture & Governance Engineer do at OKX?

As a Senior Security Architecture & Governance Engineer at OKX, you will: the Senior Security Architecture & Governance Engineer will be responsible for building the company's security review process and governance framework, integrating security controls into IT processes, and leading security architecture design. Additionally, they will conduct security governance for core systems and establish reporting mechanisms for security posture and risks..

Why join OKX as a Senior Security Architecture & Governance Engineer?

OKX is a leading Technology, Information and Internet company.

Is the Senior Security Architecture & Governance Engineer position at OKX remote?

The Senior Security Architecture & Governance Engineer position at OKX is based in Hong Kong Island, Hong Kong, China. Contact the company through Clera for specific work arrangement details.

How do I apply for the Senior Security Architecture & Governance Engineer position at OKX?

You can apply for the Senior Security Architecture & Governance Engineer position at OKX directly through Clera. Click the "Apply Now" button above to start your application. Clera's AI-powered platform will help match your profile with this opportunity and guide you through the application process. You can also learn more about OKX on their website.