概要
Coupang is reimagining the shopping experience with the goal of wowing each customer from the instant they open the Coupang app to the moment an order is delivered to their door. Our services in Taiwan include “Rocket Delivery” which offers next-day delivery for a wide selection of items at affordable prices, “Rocket Overseas” which offers free international delivery on millions of best-selling products from Korea, the U.S., and beyond. We are looking for talents to help us lead Coupang’s expansion in Taiwan. This is an exceptional opportunity to become a part of Coupang’s growth in Taiwan and create a world where our customers wonder, “How did I ever live without Coupang?”
Position: Staff Security Engineer, Penetration Tester
The Staff Security Engineer will conduct hands-on penetration testing across web, mobile, API, and cloud-related environments supporting Coupang’s security activities and services in Taiwan. This role will identify and validate vulnerabilities, communicate technical impact, and provide actionable remediation guidance while working with the Korea security team. The staff engineer is expected to independently own penetration-testing engagements and provide technical guidance to fellow engineers. The role will help maintain consistent security-testing delivery across complex applications, external services, and internal systems in a high-tempo, cross-regional environment.
What will you do?
- Lead or execute authorized penetration-testing engagements across web applications, mobile applications, APIs, and cloud-related attack surfaces.
- Define testing scope, identify attack surfaces, select appropriate testing methods, and document evidence, limitations, and outcomes.
- Assess discovered vulnerabilities, validate technical impact, distinguish verified findings from false positives, and provide remediation guidance.
- Use Linux, command-line utilities, and penetration-testing tools to perform controlled testing and verify results.
- Build or modify scripts that support request automation, test-data processing, or security-test result analysis.
- Coordinate testing scope, ownership boundaries, escalation paths, status updates, and deliverables with the Korea security team and Taiwan stakeholders.
- Independently manage engagement priorities and review testing output to identify gaps and provide specific technical guidance.
Basic Qualifications
- Demonstrated hands-on penetration-testing capability across web, mobile, or API environments.
- Demonstrated experience using penetration-testing tools in Linux or command-line environments.
- Ability to assess vulnerabilities, explain supporting evidence and impact, and provide actionable remediation guidance.
- Experience testing multiple applications, external services, or internal applications through penetration-testing or legally authorized bug-bounty work.
- Offensive-security experience sufficient to carry out penetration-testing engagements.
- Ability to communicate security findings and remediation guidance in English and Traditional Chinese.
- Ability to collaborate across Taiwan and Korea security activities, including scope coordination, responsibility boundaries, escalation, and delivery communication.
Preferred Qualifications
- Experience in Red Team or adversary-simulation experience in a complex application environments.
- Exposure to cloud-security testing, including architecture, identity and access, public interfaces, or configuration risks.
- Relevant offensive-security certification such as OSCP, OSCE, OSED, CREST, or SANS.
- Ability to demonstrate an authorized penetration-testing case covering scope, methodology, evidence, findings, limitations, and delivery outcome.
- Ability to complete a controlled attack-surface analysis and testing plan for a multi-interface application.
- Ability to compare remediation options based on risk reduction, constraints, and validation approach.
- Ability to prepare concise bilingual security summaries for technical and cross-regional stakeholders.
- A degree in Computer Science, Computer Engineering, or a related field.
Recruitment Process
-
- Application Review - Phone Interview - Onsite (or Virtual Onsite) Interview - Offer
- The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances.
- Interview schedules and the results will be informed to the applicant via the e-mail address submitted at the application stage.
Details to Consider
-
- This job posting may be closed prior to the stated end date for application if all openings are filled.
- Coupang has the right to rescind an offer of employment if a candidate is found to have submitted false information as part of the application process.
- Those eligible for employment protection, including recipients of veteran’s benefits and persons with disabilities, may receive preferential treatment for employment in accordance with applicable laws.
Privacy Notice
Your personal information will be collected and managed by Coupang as stated in the Application Privacy Notice located below:
https://www.coupang.jobs/privacy-policy/
Your personal information will be collected and managed by Coupang as stated in the Application Privacy Notice located below:
https://www.coupang.jobs/privacy-policy/