Senior Security Engineer, Penetration Tester
Summary
Conducts hands‑on penetration testing of web, mobile, API and cloud services, identifies vulnerabilities, provides remediation guidance, and collaborates with the Korea security team, using Linux command‑line tools and scripting.
What will you do?
- Execute authorized penetration tests across web applications, mobile applications, APIs, and cloud-related attack surfaces within an agreed scope.
- Identify attack surfaces, apply appropriate testing methods, and produce clear supporting evidence for validated findings.
- Assess vulnerabilities, distinguish verified findings from false positives, and provide actionable remediation guidance.
- Use Linux, command-line utilities, and penetration-testing tools to complete controlled testing tasks and validate results.
- Build or modify scripts that support request automation, test-data processing, or analysis of security-testing results.
- Coordinate testing status, blockers, findings, and next steps with the Korea security team and Taiwan stakeholders.
Basic Qualifications
- Demonstrated hands-on penetration-testing capability across web, mobile, or API environments.
- Demonstrated ability to use penetration-testing tools in Linux or command-line environments.
- Ability to assess vulnerabilities, explain supporting evidence and impact, and provide actionable remediation guidance.
- Programming or scripting capability that supports security testing.
- Offensive-security experience sufficient to execute defined penetration-testing activities with appropriate support.
- Ability to communicate security findings and remediation guidance in English and Traditional Chinese.
- Ability to collaborate across Taiwan and Korea security activities, including scope coordination, responsibility boundaries, escalation, and delivery communication.
Preferred Qualifications
- Experience completing scoped penetration-testing activities with clearly defined support, requirements, and testing boundaries.
- Experience responding constructively to technical direction, review feedback, and newly identified testing requirements.
- Experience testing multiple applications, external services, or internal applications through penetration testing or legally authorized bug-bounty work.
- Experience in e-commerce, banking, web services, or other complex application environments.
- Exposure to cloud-security testing, including architecture, identity and access, public interfaces, or configuration risks.
- Red Team or adversary-simulation exposure.
- A degree in Computer Science, Computer Engineering, or a related field.
- An offensive-security certification such as OSCP, OSCE, OSED, CREST, or SANS.
- Ability to demonstrate an authorized penetration-testing case covering scope, methodology, evidence, findings, limitations, and delivery outcome.
- Ability to complete a controlled attack-surface analysis and testing plan for a multi-interface application.
- Ability to compare remediation options based on risk reduction, constraints, and validation approach.
- Ability to prepare concise bilingual security summaries for technical and cross-regional stakeholders.
Recruitment Process
-
- Application Review - Phone Interview - Onsite (or Virtual Onsite) Interview - Offer
- The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances.
- Interview schedules and results will be communicated to the applicant through the email address submitted at the application stage.
Details to Consider
-
- This job posting may be closed before the stated application end date if all openings are filled.
- Coupang has the right to rescind an offer of employment if a candidate is found to have submitted false information as part of the application process.
- Those eligible for employment protection, including recipients of veterans’ benefits and persons with disabilities, may receive preferential treatment in accordance with applicable laws.
https://www.coupang.jobs/privacy-policy/
As published by greenhouse · 1 question
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
Pick from a list (1)
- 1. (Optional) Recordings of the interview process and transcriptions of interview audio may be collected and used for the following purposes: i) to record the interview process, ii) to transcribe and document interview audio, iii) to summarize interview results, iv) to verify the interview process and evaluation results, v) to improve the hiring procedures, vi) to check candidate fit for other open positions, vii) to review past interview records, viii) to assess suitability for internal transfer/conversion opportunities, which may involve sharing your personal data with affiliated entities within the Coupang group. Collected personal information is retained for 4 years from the notification of hiring result, and then deleted. You may refuse to provide this consent, and refusal will not affect the recruitment process. For details on how your personal data is handled, please refer to the Privacy Notice (https://coupa.ng/ckJm4X).