メインコンテンツに移動

Senior Security Engineer, Penetration Tester

概要

Coupang is reimagining the shopping experience with the goal of wowing each customer from the instant they open the Coupang app to the moment an order is delivered to their door. Our services in Taiwan include “Rocket Delivery” which offers next-day delivery for a wide selection of items at affordable prices, “Rocket Overseas” which offers free international delivery on millions of best-selling products from Korea, the U.S., and beyond. We are looking for talents to help us lead Coupang’s expansion in Taiwan. This is an exceptional opportunity to become a part of Coupang’s growth in Taiwan and create a world where our customers wonder, “How did I ever live without Coupang?”
Position: Senior Security Engineer, Penetration Tester
The Security Engineer will conduct hands-on penetration testing across web, mobile, API, and cloud-related environments supporting Coupang’s security activities and services in Taiwan. The engineer will identify and validate vulnerabilities, communicate their technical impact, and provide actionable remediation guidance while collaborating with the Korea security team. This L5 role is intended for a developing penetration tester who can execute defined testing activities with appropriate scope, guidance, and technical support. The role will contribute to consistent security-testing delivery across complex applications, external services, and internal systems.

What will you do?

  • Execute authorized penetration tests across web applications, mobile applications, APIs, and cloud-related attack surfaces within an agreed scope.
  • Identify attack surfaces, apply appropriate testing methods, and produce clear supporting evidence for validated findings.
  • Assess vulnerabilities, distinguish verified findings from false positives, and provide actionable remediation guidance.
  • Use Linux, command-line utilities, and penetration-testing tools to complete controlled testing tasks and validate results.
  • Build or modify scripts that support request automation, test-data processing, or analysis of security-testing results.
  • Coordinate testing status, blockers, findings, and next steps with the Korea security team and Taiwan stakeholders.

Basic Qualifications

  • Demonstrated hands-on penetration-testing capability across web, mobile, or API environments.
  • Demonstrated ability to use penetration-testing tools in Linux or command-line environments.
  • Ability to assess vulnerabilities, explain supporting evidence and impact, and provide actionable remediation guidance.
  • Programming or scripting capability that supports security testing.
  • Offensive-security experience sufficient to execute defined penetration-testing activities with appropriate support.
  • Ability to communicate security findings and remediation guidance in English and Traditional Chinese.
  • Ability to collaborate across Taiwan and Korea security activities, including scope coordination, responsibility boundaries, escalation, and delivery communication.

Preferred Qualifications

  • Experience completing scoped penetration-testing activities with clearly defined support, requirements, and testing boundaries.
  • Experience responding constructively to technical direction, review feedback, and newly identified testing requirements.
  • Experience testing multiple applications, external services, or internal applications through penetration testing or legally authorized bug-bounty work.
  • Experience in e-commerce, banking, web services, or other complex application environments.
  • Exposure to cloud-security testing, including architecture, identity and access, public interfaces, or configuration risks.
  • Red Team or adversary-simulation exposure.
  • A degree in Computer Science, Computer Engineering, or a related field.
  • An offensive-security certification such as OSCP, OSCE, OSED, CREST, or SANS.
  • Ability to demonstrate an authorized penetration-testing case covering scope, methodology, evidence, findings, limitations, and delivery outcome.
  • Ability to complete a controlled attack-surface analysis and testing plan for a multi-interface application.
  • Ability to compare remediation options based on risk reduction, constraints, and validation approach.
  • Ability to prepare concise bilingual security summaries for technical and cross-regional stakeholders.

Recruitment Process

    • Application Review - Phone Interview - Onsite (or Virtual Onsite) Interview - Offer
    • The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances.
    • Interview schedules and results will be communicated to the applicant through the email address submitted at the application stage.

Details to Consider

    • This job posting may be closed before the stated application end date if all openings are filled.
    • Coupang has the right to rescind an offer of employment if a candidate is found to have submitted false information as part of the application process.
    • Those eligible for employment protection, including recipients of veterans’ benefits and persons with disabilities, may receive preferential treatment in accordance with applicable laws.
Privacy Notice
Your personal information will be collected and managed by Coupang as stated in the Application Privacy Notice located below:
https://www.coupang.jobs/privacy-policy/

機会均等