- Hong Kong Hong Kong Hong Kong
Working Location
Job Description
Responsibilities
This is a role for someone with real depth in security, broad coverage across the stack, and the engineering muscle to ship. Just as important is the ability to drive adoption — security that lands in complex, fast-moving business environments rather than sitting in a policy document.
Architect and build our end-to-end DevSecOps platform and the SDKs/Agents behind our security products, covering code, build, artifacts, images, deployment, and runtime.
Lead runtime protection through RASP and Java Agent — bytecode instrumentation, runtime hooking, and detection/interception engines using ASM, ByteBuddy, and Instrumentation, with continuous tuning for performance, stability, and compatibility.
Integrate and productise scanning capabilities across SAST, DAST, IAST, SCA, code scanning, and image scanning. You'll embed tools like SonarQube and Coverity deep into CI/CD and close the loop from detection through blocking, remediation, and re-test.
Strong computer science and security fundamentals — deep understanding of operating systems, networking, compilers and the JVM, distributed systems, application security, cloud-native security, and supply chain security. Both breadth and depth.
Expert-level Java, with hands-on depth in the JVM, ClassLoader, Java Agent, ASM, ByteBuddy, bytecode instrumentation, and performance profiling and tuning. Plus working proficiency in Python or Go.
Substantial production experience with RASP, SAST, DAST, IAST, SCA, image security, and code scanning — enough to design a capability, integrate the engine, build the platform around it, and take it to scale independently.
Real offensive and defensive experience. You understand the root causes, exploitation paths, detection logic, bypass techniques, and fixes for common web, API, and microservices vulnerabilities — and can design from both the attacker's and defender's point of view.
Fluency with LLMs and AI Agents, including a considered view on model capability limits, agent architecture, tool calling, context engineering, evaluation methods, and how AI is reshaping both security engineering and the attack surface.
Security engineering experience at a top-tier internet company, cloud provider, or leading security vendor
You've led the build of a DevSecOps platform, application security platform, RASP, code scanning platform, or cloud-native security platform
Competitive total compensation package
L&D programs and Education subsidy for employees' growth and development
Various team building programs and company events
Wellness and meal allowances
Comprehensive healthcare schemes for employees and dependants
More that we love to tell you along the process!
Important Information
Never provide your bank or credit card details when applying for jobs. Do not transfer any money or complete unrelated online surveys. If you see something suspicious, Report this Job ad.