Senior Security Engineer, Penetration Tester
Coupang · Taipei, Taiwan
Open. First seen 3 October 2026.
Description
Coupang is reimagining the shopping experience with the goal of wowing each customer from the instant they open the Coupang app to the moment an order is delivered to their door. Our services in Taiwan include “Rocket Delivery” which offers next-day delivery for a wide selection of items at affordable prices, “Rocket Overseas” which offers free international delivery on millions of best-selling products from Korea, the U.S., and beyond. We are looking for talents to help us lead Coupang’s expansion in Taiwan.
This is an exceptional opportunity to become a part of Coupang’s growth in Taiwan and create a world where our customers wonder, “How did I ever live without Coupang?”
Position: Senior Security Engineer, Penetration Tester
The Security Engineer will conduct hands-on penetration testing across web, mobile, API, and cloud-related environments supporting Coupang’s security activities and services in Taiwan. The engineer will identify and validate vulnerabilities, communicate their technical impact, and provide actionable remediation guidance while collaborating with the Korea security team. This L5 role is intended for a developing penetration tester who can execute defined testing activities with appropriate scope, guidance, and technical support.
The role will contribute to consistent security-testing delivery across complex applications, external services, and internal systems.
What will you do?
- Execute authorized penetration tests across web applications, mobile applications, APIs, and cloud-related attack surfaces within an agreed scope.
- Identify attack surfaces, apply appropriate testing methods, and produce clear supporting evidence for validated findings.
- Assess vulnerabilities, distinguish verified findings from false positives, and provide actionable remediation guidance.
- Use Linux, command-line utilities, and penetration-testing tools to complete controlled testing tasks and validate results.
- Build or modify scripts that support request automation, test-data processing, or analysis of security-testing results.
- Coordinate testing status, blockers, findings, and next steps with the Korea security team and Taiwan stakeholders.
Basic Qualifications
- Demonstrated hands-on penetration-testing capability across web, mobile, or API environments.
- Demonstrated ability to use penetration-testing tools in Linux or command-line environments.
- Ability to assess vulnerabilities, explain supporting evidence and impact, and provide actionable remediation guidance.
- Programming or scripting capability that supports security testing.
- Offensive-security experience sufficient to execute defined penetration-testing activities with appropriate support.
- Fluency in both Mandarin Chinese and English, able to communicate security findings and remediation guidance in English and Mandarin Chinese.
- Ability to collaborate across Taiwan and Korea security activities, including scope coordination, responsibility boundaries, escalation, and delivery communication.
Preferred Qualifications
- Experience completing scoped penetration-testing activities with clearly defined support, requirements, and testing boundaries.
- Experience responding constructively to technical direction, review feedback, and newly identified testing requirements.
- Experience testing multiple applications, external services, or internal applications through penetration testing or legally authorized bug-bounty work.
- Experience in e-commerce, banking, web services, or other complex application environments.
- Exposure to cloud-security testing, including architecture, identity and access, public interfaces, or configuration risks.
- Red Team or adversary-simulation exposure.
- A degree in Computer Science, Computer Engineering, or a related field.
- An offensive-security certification such as OSCP, OSCE, OSED, CREST, or SANS.
- Ability to demonstrate an authorized penetration-testing case covering scope, methodology, evidence, findings, limitations, and delivery outcome.
- Ability to complete a controlled attack-surface analysis and testing plan for a multi-interface application.
- Ability to compare remediation options based on risk reduction, constraints, and validation approach.
- Ability to prepare concise bilingual security summaries for technical and cross-regional stakeholders.
Recruitment Process
- Application Review - Phone Interview - Onsite (or Virtual Onsite) Interview - Offer
- The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances.
- Interview schedules and results will be communicated to the applicant through the email address submitted at the application stage.
Details to Consider
- This job posting may be closed before the stated application end date if all openings are filled.
- Coupang has the right to rescind an offer of employment if a candidate is found to have submitted false information as part of the application process.
- Those eligible for employment protection, including recipients of veterans’ benefits and persons with disabilities, may receive preferential treatment in accordance with applicable laws.
Privacy Notice
Your personal information will be collected and managed by Coupang as stated in the Application Privacy Notice located below:
https://www.coupang.jobs/privacy-policy/
職務說明 (Job Description)
Coupang 正重新定義購物體驗,我們的目標是讓顧客從打開 Coupang App 的那一刻起,直到商品送達家門口,都能感到驚喜與讚歎。我們在台灣的服務包括:「火箭速配」,以實惠的價格為豐富多樣的商品提供次日送達服務;以及「火箭跨境」,提供來自韓國、美國及其他國家數百萬款熱銷商品的免費跨境配送。我們正在尋求優秀人才,共同引領 Coupang 在台灣的業務擴展。這是一個絕佳的機會,能讓您成為 Coupang 在台灣成長的一部分,並創造一個讓顧客驚嘆「如果沒有 Coupang,我以前是怎麼生活的?」的世界。
職位:高級資安工程師 - 滲透測試員 (Senior Security Engineer, Penetration Tester)
資安工程師將在 Web、行動裝置 (Mobile)、API 及雲端相關環境中開展實機滲透測試,以支援 Coupang 在台灣 indicate 的資安活動與服務。工程師需識別並驗證漏洞,說明其技術影響,並提供具體可行的修復建議,同時與韓國資安團隊保持協作。此 L5 職位適合具備一定經驗且正在成長中的滲透測試員,需能在適當的範圍、指導與技術支援下執行指定的測試任務。該職位將有助於在複雜的應用程式、外部服務及內部系統中提供一致的安全性測試服務。
工作內容 (What will you do?)
- 在約定的測試範圍內,對 Web 應用程式、行動應用程式、API 及雲端相關的攻擊面執行授權的滲透測試。
- 識別攻擊面,採用適當的測試方法,並針對已驗證的發現提供清晰的支援證據。
- 評估漏洞,區分真實漏洞與誤報 (False Positives),並提供具體可行的修復指引。
- 使用 Linux、命令列工具 (CLI) 及滲透測試工具完成受控的測試任務並驗證結果。
- 開發或修改腳本,以支援請求自動化、測試資料處理或安全性測試結果分析。
- 與韓國資安團隊及台灣利害關係人協調測試進度、阻礙因素 (Blockers)、測試結果及後續步驟。
基本條件 (Basic Qualifications)
- 具備在 Web、行動裝置或 API 環境中進行實機滲透測試的實務能力。
- 具備在 Linux 或命令列環境中使用滲透測試工具的能力。
- 具備評估漏洞、解釋支援證據與影響,並提供可行修復指引的能力。
- 具備支援安全性測試的程式設計或腳本編寫 (Scripting) 能力。
- 具備足夠的進攻性資安 (Offensive Security) 經驗,能在獲得適當支援下執行指定的滲透測試任務。
- 精通中文(華語)與英文,能以中英文流利溝通資安漏洞發現與修復建議。
- 具備跨台灣與韓國資安活動協作的能力,包括範圍協調、責任邊界劃分、問題升級 (Escalation) 與交付溝通。
優先條件 (Preferred Qualifications)
- 具備在明確支援、需求與測試邊界下完成指定範圍滲透測試的經驗。
- 具備針對技術指導、審查回饋及新識別出的測試需求作出積極建設性回應的經驗。
- 具備透過滲透測試或合法授權的漏洞獎勵計畫 (Bug Bounty),對多個應用程式、外部服務或內部系統進行測試的經驗。
- 具備電子商務 (E-commerce)、金融銀行、網路服務或其他複雜應用程式環境的相關經驗。
- 接觸過雲端資安測試,包括架構、身分與存取管理 (IAM)、公開介面或配置風險。
- 具備紅隊演練 (Red Team) 或模擬敵對攻擊 (Adversary Simulation) 的經驗。
- 資訊工程、資訊科學、電腦工程或相關領域之學士或碩士學位。
- 持有進攻性資安相關認證,如 OSCP、OSCE、OSED、CREST 或 SANS。
- 能展示含括測試範圍、方法論、證據、漏洞發現、局限性及交付結果的授權滲透測試案例。
- 能針對多介面應用程式制定受控的攻擊面分析與測試計畫。
- 能基於風險降低程度、約束條件及驗證方法比較不同的修復方案。
- 能為技術人員與跨區域利害關係人準備簡明的中英雙語資安摘要。
應徵流程 (Recruitment Process)
履歷審查 (Application Review) ➔ 電話面試 (Phone Interview) ➔ 現場 / 視訊面試 (Onsite / Virtual Onsite Interview) ➔ 錄取通知 (Offer)
- 具體的招聘流程可能會根據特定職位有所不同,並可能因排程或其他情況有所調整。
- 面試時間及結果將透過應徵時提交的電子郵件信箱通知應徵者。
注意事項 (Details to Consider)
- 若所有職缺已填補完畢,本招聘公告可能會在預定的截止日期前提前結束。
- 若發現求職者在應徵過程中提供虛假資訊,Coupang 有權撤銷錄取通知 (Offer)。
- 符合就業保護資格者(包括具備退伍軍人身分/榮民資格及身障人士)得依相關法律規定享有優先錄用資格。
隱私權聲明 (Privacy Notice)
您的個人資料將由 Coupang 根據下方連結中的「應徵者隱私權聲明」進行收集與管理: https://www.coupang.jobs/privacy-policy/
Similar jobs
- Senior Security Engineer, Penetration Tester at Coupang Internal
- [TW Catalog] Staff Back-end Engineer at Coupang
- Technical Program Manager at Coupang
- Technical Program Manager at Coupang
- Technical Lead Manager, Mobile Engineering — Search AI Product & Mobile at Coupang
- Staff Technical Program Manager - Engineering Controls & Compliance at Coupang
Is this your posting and you want it taken down? Email info@careerholo.com.