Senior Security Engineer, Penetration Tester

Coupang · Taipei, Taiwan · Taipei

Spotted 5d ago

What you'll need to apply

Fields this application requires

NameEmailPhoneRésumé

Company-specific questions

  • Coupang Corporation or its affiliates and subsidiaries* (or collectively referred to as “Coupang”) does not collect, process or use any personal information other than the types of information specified in this Consent. Please ensure that your resume does not include any personal information other than the types specified in this Consent.
  • 1. What is your nationality?
  • 1. (Required) By submitting your resume, you consent to the required collection, processing, use, required provision/transfer, and consignment of personal information as set forth in our Privacy Policy (https://privacy.coupang.com/en/land/jobs/).
  • 2. (Optional) Name, contact information, email address, nationality, educational background, work experience, qualifications, national merit status (for special hiring program applicants only), relative’s name/relationship/team and application history are collected and used on an ongoing basis for recruitment purposes and may be provided to any of our affiliates and subsidiaries*, other than the company to which you originally applied, for the purpose of reviewing and conducting recruitment for similar positions. Personal information collected and provided will be retained for the duration of the year-round recruitment retention period defined in the Privacy Policy. You may refuse to provide consent, but such refusal may prevent the year-round hiring from progressing normally or may result in the restriction of opportunities in the hiring process of companies other than the one you applied.
  • 3. (Optional) Recordings of the interview process and transcriptions of interview audio maybe collected and used for the following purposes: i) to record the interview process, ii) to transcribe and document interview audio, iii) to summarize interview results, iv) to verify the interview process and evaluation results, v) to improve the hiring procedures, vi) to check candidate fit for other open positions, vii) to review past interview records. Collected personal information are retained for 4 years from the notification of hiring result, and then deleted. You may refuse to provide this consent, and refusal will not affect the recruitment process.
  • 4. (Optional) Coupang or its affiliate or subsidiary company* will send recruitment notifications through transmission media such as phone, email, and SMS using the contact information and email address based on your consent.
  • 5. (Optional) Coupang or its affiliate or subsidiary company* will conduct reference checks on you within the following scope based on your consent: Additional reference checks may be conducted on applicants who applied for a job at Coupang and passed interviews, and Coupang arranges means to conduct reference checks. Coupang may collect other personal information about you, including integrity information collected from public sources and the performance evaluation information collected from your former employer or colleagues.
  • 1. I understand that working with Relatives in the Coupang group of companies (collectively, the "Coupang Group") -- where they can influence each other’s work -- can potentially create conflicts of interest. Therefore, such a situation requires prior approval from the People Operations. In view of the above, I hereby confirm that I DO NOT have any Relatives working in any company within the Coupang Group or serving on the Board of Directors of any company within the Coupang Group;
  • 1. Are you currently, or have you been a government official, public servant, or employee of a public institution who may be subject to post employment or reemployment restrictions under applicable laws or regulations?
  • You have the right to inquire/access, request a copy, supplement/correct, delete, suspend the collection, processing, or use and suspend the transfer of your personal information that Coupang holds. Exercising certain rights, such as deletion of personal information, may result in the restriction of the hiring process. If you wish to exercise any of these choices, please contact our privacy representative at [candidatedataremove@coupang.com].
  • Document Policy
Job description

About this role

Employer-provided description, formatted for easier reading.

Coupang is reimagining the shopping experience with the goal of wowing each customer from the instant they open the Coupang app to the moment an order is delivered to their door. Our services in Taiwan include “Rocket Delivery” which offers next-day delivery for a wide selection of items at affordable prices, “Rocket Overseas” which offers free international delivery on millions of best-selling products from Korea, the U. S.

, and beyond. We are looking for talents to help us lead Coupang’s expansion in Taiwan. This is an exceptional opportunity to become a part of Coupang’s growth in Taiwan and create a world where our customers wonder, “How did I ever live without Coupang?

Position: Senior Security Engineer, Penetration Tester

The Security Engineer will conduct hands-on penetration testing across web, mobile, API, and cloud-related environments supporting Coupang’s security activities and services in Taiwan. The engineer will identify and validate vulnerabilities, communicate their technical impact, and provide actionable remediation guidance while collaborating with the Korea security team.

This L5 role is intended for a developing penetration tester who can execute defined testing activities with appropriate scope, guidance, and technical support. The role will contribute to consistent security-testing delivery across complex applications, external services, and internal systems.

What will you do?

  • Execute authorized penetration tests across web applications, mobile applications, APIs, and cloud-related attack surfaces within an agreed scope.
  • Identify attack surfaces, apply appropriate testing methods, and produce clear supporting evidence for validated findings.
  • Assess vulnerabilities, distinguish verified findings from false positives, and provide actionable remediation guidance.
  • Use Linux, command-line utilities, and penetration-testing tools to complete controlled testing tasks and validate results.
  • Build or modify scripts that support request automation, test-data processing, or analysis of security-testing results.
  • Coordinate testing status, blockers, findings, and next steps with the Korea security team and Taiwan stakeholders.

Basic Qualifications

  • Demonstrated hands-on penetration-testing capability across web, mobile, or API environments.
  • Demonstrated ability to use penetration-testing tools in Linux or command-line environments.
  • Ability to assess vulnerabilities, explain supporting evidence and impact, and provide actionable remediation guidance.
  • Programming or scripting capability that supports security testing.
  • Offensive-security experience sufficient to execute defined penetration-testing activities with appropriate support.
  • Fluency in both Mandarin Chinese and English, able to communicate security findings and remediation guidance in English and Mandarin Chinese.
  • Ability to collaborate across Taiwan and Korea security activities, including scope coordination, responsibility boundaries, escalation, and delivery communication.

Preferred Qualifications

  • Experience completing scoped penetration-testing activities with clearly defined support, requirements, and testing boundaries.
  • Experience responding constructively to technical direction, review feedback, and newly identified testing requirements.
  • Experience testing multiple applications, external services, or internal applications through penetration testing or legally authorized bug-bounty work.
  • Experience in e-commerce, banking, web services, or other complex application environments.
  • Exposure to cloud-security testing, including architecture, identity and access, public interfaces, or configuration risks.
  • Red Team or adversary-simulation exposure.
  • A degree in Computer Science, Computer Engineering, or a related field.
  • An offensive-security certification such as OSCP, OSCE, OSED, CREST, or SANS.
  • Ability to demonstrate an authorized penetration-testing case covering scope, methodology, evidence, findings, limitations, and delivery outcome.
  • Ability to complete a controlled attack-surface analysis and testing plan for a multi-interface application.
  • Ability to compare remediation options based on risk reduction, constraints, and validation approach.
  • Ability to prepare concise bilingual security summaries for technical and cross-regional stakeholders.

Recruitment Process

  • • Application Review - Phone Interview - Onsite (or Virtual Onsite) Interview - Offer
  • The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances.
  • Interview schedules and results will be communicated to the applicant through the email address submitted at the application stage.

Details to Consider

  • • This job posting may be closed before the stated application end date if all openings are filled.
  • Coupang has the right to rescind an offer of employment if a candidate is found to have submitted false information as part of the application process.
  • Those eligible for employment protection, including recipients of veterans’ benefits and persons with disabilities, may receive preferential treatment in accordance with applicable laws.

Privacy Notice

Your personal information will be collected and managed by Coupang as stated in the Application Privacy Notice located below: https://www. coupang. jobs/privacy-policy/

Interested in this role?Continue on Coupang's careers page.
Apply on Coupang