Staff Security Engineer, Penetration Tester
Summary
The Staff Security Engineer conducts hands‑on penetration testing of web, mobile, API and cloud services, leads engagements, analyzes vulnerabilities, and provides remediation guidance while coordinating with Korean security teams.
What will you do?
- Lead or execute authorized penetration-testing engagements across web applications, mobile applications, APIs, and cloud-related attack surfaces.
- Define testing scope, identify attack surfaces, select appropriate testing methods, and document evidence, limitations, and outcomes.
- Assess discovered vulnerabilities, validate technical impact, distinguish verified findings from false positives, and provide remediation guidance.
- Use Linux, command-line utilities, and penetration-testing tools to perform controlled testing and verify results.
- Build or modify scripts that support request automation, test-data processing, or security-test result analysis.
- Coordinate testing scope, ownership boundaries, escalation paths, status updates, and deliverables with the Korea security team and Taiwan stakeholders.
- Independently manage engagement priorities and review testing output to identify gaps and provide specific technical guidance.
Basic Qualifications
- Demonstrated hands-on penetration-testing capability across web, mobile, or API environments.
- Demonstrated experience using penetration-testing tools in Linux or command-line environments.
- Ability to assess vulnerabilities, explain supporting evidence and impact, and provide actionable remediation guidance.
- Experience testing multiple applications, external services, or internal applications through penetration-testing or legally authorized bug-bounty work.
- Offensive-security experience sufficient to carry out penetration-testing engagements.
- Ability to communicate security findings and remediation guidance in English and Traditional Chinese.
- Ability to collaborate across Taiwan and Korea security activities, including scope coordination, responsibility boundaries, escalation, and delivery communication.
Preferred Qualifications
- Experience in Red Team or adversary-simulation experience in a complex application environments.
- Exposure to cloud-security testing, including architecture, identity and access, public interfaces, or configuration risks.
- Relevant offensive-security certification such as OSCP, OSCE, OSED, CREST, or SANS.
- Ability to demonstrate an authorized penetration-testing case covering scope, methodology, evidence, findings, limitations, and delivery outcome.
- Ability to complete a controlled attack-surface analysis and testing plan for a multi-interface application.
- Ability to compare remediation options based on risk reduction, constraints, and validation approach.
- Ability to prepare concise bilingual security summaries for technical and cross-regional stakeholders.
- A degree in Computer Science, Computer Engineering, or a related field.
Recruitment Process
-
- Application Review - Phone Interview - Onsite (or Virtual Onsite) Interview - Offer
- The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances.
- Interview schedules and the results will be informed to the applicant via the e-mail address submitted at the application stage.
Details to Consider
-
- This job posting may be closed prior to the stated end date for application if all openings are filled.
- Coupang has the right to rescind an offer of employment if a candidate is found to have submitted false information as part of the application process.
- Those eligible for employment protection, including recipients of veteran’s benefits and persons with disabilities, may receive preferential treatment for employment in accordance with applicable laws.
Your personal information will be collected and managed by Coupang as stated in the Application Privacy Notice located below:
https://www.coupang.jobs/privacy-policy/
As published by greenhouse
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
- 1. (Optional) Recordings of the interview process and transcriptions of interview audio may be collected and used for the following purposes: i) to record the interview process, ii) to transcribe and document interview audio, iii) to summarize interview results, iv) to verify the interview process and evaluation results, v) to improve the hiring procedures, vi) to check candidate fit for other open positions, vii) to review past interview records, viii) to assess suitability for internal transfer/conversion opportunities, which may involve sharing your personal data with affiliated entities within the Coupang group. Collected personal information is retained for 4 years from the notification of hiring result, and then deleted. You may refuse to provide this consent, and refusal will not affect the recruitment process. For details on how your personal data is handled, please refer to the Privacy Notice (https://coupa.ng/ckJm4X). choose one