AI Agent Security Research Engineer
OKX is a leading global cryptocurrency exchange offering a wide range of trading services, including spot and derivatives trading, as well as Web3 solutions.
Investors
Projects
About OKX
OKX is a global cryptocurrency exchange known for its trading services and financial products. The platform offers a wide range of features, including spot and derivatives trading, staking services, and a user-friendly interface suitable for both beginners and experienced traders.
Skills
About the Role
You will design and implement multi-agent code-auditing systems for vulnerability detection, malicious-code identification, and sensitive-information leakage. You will integrate RAG and agent techniques into security audits, develop DevSecOps pipeline plugins, protect LLM applications, automate threat-response workflows, and build scalable agent services and detection APIs.
Requirements
- 3+ years of backend development experience.
- Proficiency in at least one of Python, Go, or Java.
- Hands-on experience deploying LLM agents in production.
- Experience with AI security, including prompt injection, jailbreaking, malicious agent injection, and tool misuse defenses.
- Familiarity with at least one agent framework: LangChain, LlamaIndex, AutoGen, CrewAI, or LangGraph.
- Production project experience with an agent framework.
- Proficiency in Docker and Kubernetes.
- Expertise in microservices architecture design and deployment.
Responsibilities
- Design and implement a multi-agent collaborative code-auditing system for vulnerability detection, malicious-code identification, and sensitive-information leakage.
- Lead planner, executor, and critic role decomposition, tool-invocation chains, and cross-agent state synchronization design.
- Integrate RAG, Chain-of-Thought, and Reflection techniques into security audit agents.
- Optimize detection accuracy and recall, and establish a quantifiable evaluation and iteration framework.
- Develop GitLab CI/CD, Tekton, and Jenkins plugins to enable audit-on-commit workflows.
- Build security protections for LLM applications across input, output, and runtime layers.
- Develop agent workflows for alert classification, contextual correlation, false-positive filtering, and threat-intelligence retrieval.
- Design human-machine intervention mechanisms and agent behavior audit systems.
- Construct highly available, scalable agent services for concurrent scanning-task scheduling and fault tolerance.
- Standardize detection APIs and build rule management, result visualization, and false-positive feedback systems.
Benefits
- Competitive total compensation package.
- Learning and development programs.
- Education subsidy.
- Team-building programs and company events.
- Wellness and meal allowances.
- Comprehensive healthcare schemes for employees and dependants.
