쿠팡
Staff Security Engineer, Penetration Tester
채용 상세
<p> </p> <div> <div class="paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol">Coupang is reimagining the shopping experience with the goal of wowing each customer from the instant they open the Coupang app to the moment an order is delivered to their door. Our services in Taiwan include “Rocket Delivery” which offers next-day delivery for a wide selection of items at affordable prices, “Rocket Overseas” which offers free international delivery on millions of best-selling products from Korea, the U.S., and beyond. We are looking for talents to help us lead Coupang’s expansion in Taiwan. This is an exceptional opportunity to become a part of Coupang’s growth in Taiwan and create a world where our customers wonder, “How did I ever live without Coupang?”</div> <div class="paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol"> </div> <div class="paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol"><strong>Position: Staff Security Engineer, Penetration Tester</strong></div> <div class="paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol"> </div> <div class="paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol"> <div>The Staff Security Engineer will conduct hands-on penetration testing across web, mobile, API, and cloud-related environments supporting Coupang’s security activities and services in Taiwan. This role will identify and validate vulnerabilities, communicate technical impact, and provide actionable remediation guidance while working with the Korea security team. The staff engineer is expected to independently own penetration-testing engagements and provide technical guidance to fellow engineers. The role will help maintain consistent security-testing delivery across complex applications, external services, and internal systems in a high-tempo, cross-regional environment.</div> <div> <h4>What will you do?</h4> <ul> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Lead or execute authorized penetration-testing engagements across web applications, mobile applications, APIs, and cloud-related attack surfaces.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Define testing scope, identify attack surfaces, select appropriate testing methods, and document evidence, limitations, and outcomes.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Assess discovered vulnerabilities, validate technical impact, distinguish verified findings from false positives, and provide remediation guidance.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Use Linux, command-line utilities, and penetration-testing tools to perform controlled testing and verify results.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Build or modify scripts that support request automation, test-data processing, or security-test result analysis.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Coordinate testing scope, ownership boundaries, escalation paths, status updates, and deliverables with the Korea security team and Taiwan stakeholders.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Independently manage engagement priorities and review testing output to identify gaps and provide specific technical guidance.</li> </ul> <h4>Basic Qualifications</h4> <ul> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Demonstrated hands-on penetration-testing capability across web, mobile, or API environments.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Demonstrated experience using penetration-testing tools in Linux or command-line environments.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Ability to assess vulnerabilities, explain supporting evidence and impact, and provide actionable remediation guidance.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Experience testing multiple applications, external services, or internal applications through penetration-testing or legally authorized bug-bounty work.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Offensive-security experience sufficient to carry out penetration-testing engagements.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Fluency in both Mandarin Chinese and English, able to communicate security findings and remediation guidance in English and Mandarin Chinese.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Ability to collaborate across Taiwan and Korea security activities, including scope coordination, responsibility boundaries, escalation, and delivery communication.</li> </ul> <h4>Preferred Qualifications</h4> <ul> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Experience in Red Team or adversary-simulation experience in a complex application environments.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Exposure to cloud-security testing, including architecture, identity and access, public interfaces, or configuration risks.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Relevant offensive-security certification such as OSCP, OSCE, OSED, CREST, or SANS.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Ability to demonstrate an authorized penetration-testing case covering scope, methodology, evidence, findings, limitations, and delivery outcome.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Ability to complete a controlled attack-surface analysis and testing plan for a multi-interface application.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Ability to compare remediation options based on risk reduction, constraints, and validation approach.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Ability to prepare concise bilingual security summaries for technical and cross-regional stakeholders.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">A degree in Computer Science, Computer Engineering, or a related field.</li> </ul> <p><strong>Recruitment Process</strong></p> <ul> <li> <ul> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Application Review - Phone Interview - Onsite (or Virtual Onsite) Interview - Offer</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Interview schedules and the results will be informed to the applicant via the e-mail address submitted at the application stage.</li> </ul> </li> </ul> <p><strong>Details to Consider</strong></p> <ul> <li> <ul> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">This job posting may be closed prior to the stated end date for application if all openings are filled.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Coupang has the right to rescind an offer of employment if a candidate is found to have submitted false information as part of the application process.</li> <li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf">Those eligible for employment protection, including recipients of veteran’s benefits and persons with disabilities, may receive preferential treatment for employment in accordance with applicable laws.</li> </ul> </li> </ul> <div class="paragraph-in-scc-markdown-text ___1ngh792 ftgm304 f1iaxwol"><strong>Privacy Notice</strong><br>Your personal information will be collected and managed by Coupang as stated in the Application Privacy Notice located below:<br>https://www.coupang.jobs/privacy-policy/</div> </div> </div> </div>