Skip to content
← Back to job listings

Senior Security Engineer (Attack Surface Identification)

Coupang · Seattle, United States

CybersecurityExternal listingfull-timeabout 1 hour ago

About The Role

We exist to wow our customers. We know we’re doing the right thing when we hear our customers say, “How did we ever live without Coupang?” Born out of an obsession to make shopping, eating, and living easier than ever, we’re collectively disrupting the multi-billion-dollar e-commerce industry from the ground up. We are one of the fastest-growing e-commerce companies that established an unparalleled reputation for being a dominant and reliable force in South Korean commerce.

We are proud to have the best of both worlds — a startup culture with the resources of a large global public company. This fuels us to continue our growth and launch new services at the speed we have been since our inception. We are all entrepreneurs surrounded by opportunities to drive new initiatives and innovations. At our core, we are bold and ambitious people that like to get our hands dirty and make a hands-on impact. At Coupang, you will see yourself, your colleagues, your team, and the company grow every day.

Our mission to build the future of commerce is real. We push the boundaries of what’s possible to solve problems and break traditional tradeoffs. Join Coupang now to create an epic experience in this always-on, high-tech, and hyper-connected world.

Role Overview

This role mitigates security threats by continuously identifying IT interfaces and digital footprints exposed to attackers. As attackers' infiltration methods evolve rapidly with advancements in AI technology, proactive attack surface management is no longer an option , but a necessity. We are looking for an expert to join us in achieving our proactive cybersecurity mission to minimize attack surface exposure, staying one step ahead of the attackers.

What You Will Do

  • Continuous Monitoring of Digital Footprint: Constantly identify and map our officially/unofficially exposed IT assets (domains, IPs, open ports, cloud environments, etc.).
  • Discovery of Shadow IT & Blind Spots: Proactively detect abandoned servers, test pages, and unnecessary exposed interfaces that are out of the management organization's visibility.
  • Vulnerability Identification & Mitigation Strategy: Identify vulnerable application versions and paths exposing internal information, evaluate them based on business impact, and prioritize remediation efforts.
  • Cross-functional Collaboration & Proactive Defense: Work closely with infrastructure and development teams to swiftly eliminate vulnerable paths or apply protective measures before an attack surface leads to a real breach.
  • ASM Solution Implementation & Operation: Implement and operate commercial ASM solutions while simultaneously building and utilizing our own in-house Attack Surface Discovery tools.
  • ASM Automation Pipeline: Automate processes to streamline attack surface identification and establish integration architectures with existing security solutions.

Basic Qualifications

  • Bachelors Degree in Computer Science or a related field
  • 2 years of experience in Security Engineering or Cybersecurity

Preferred Qualifications

  • 5+ years of hands-on experience in cybersecurity threat identification, response, assessment, and management (with at least 2 years of experience in Attack Surface Management preferred).

Technical Skills

  • ASM Solution Utilization: Experience in implementing and operating commercial ASM solutions.
  • Scanner & Script Development: Experience developing vulnerability scanners or detection scripts from an attacker's perspective (Offensive perspective). Usage of AI IDEs is highly welcomed.
  • Security Automation: Ability to efficiently write automation scripts utilizing AWS resources and Python for API integration and building attack surface identification tools.

Security Knowledge

  • Security Architecture Understanding: Structural understanding of Cloud (AWS, Azure, GCP), On-premises, IoT, User Endpoints, DNS, Admin Consoles, etc.
  • Network & Cloud Security: In-depth knowledge of major network protocols (TCP/IP, DNS, HTTP/S, RDP, etc.) and web/cloud architecture security.
  • Cyber Attack Mechanisms (TTPs): Understanding of real-world attack mechanisms including attack path discovery, vulnerability exploitation, malware distribution/execution, lateral movement, DDoS, and supply chain attacks.
  • Language Proficiency: Intermediate or higher proficiency in English (Reading, Writing, Speaking) to communicate smoothly in a global environment.
  • Cloud Security Expertise: Understanding of infrastructure operations and security assessment experience in large-scale public cloud environments (AWS, Azure, GCP, etc.).
  • Related Security Experience: Hands-on experience in Bug Bounty programs, discovering and reporting major vulnerabilities (CVEs), penetration testing, incident response, threat hunting, security architecture review, or Cyber Threat Intelligence (CTI).
  • Large-Scale Infrastructure Experience: Security operations experience within a complex, massive global IT infrastructure.
  • Bilingual Proficiency: Fluent in both Korean and English, capable of seamless communication and collaboration in a global work environment.

Pay & Benefits

Our compensation reflects the cost of living across several US geographic markets. At Coupang, your base pay is one part of your total compensation.

The base pay for this position ranges from $108,000/year to $232,000/year. Pay is based on several factors including market location and may vary depending on job-related knowledge, skills and experience.

General Description of All Benefits

  • Annual bonus is 0-20% of the base salary
  • Medical/Dental/Vision/Life, AD&D insurance
  • Flexible Spending Accounts (FSA) & Health Savings Account (HAS)
  • Long-term/Short-term Disability
  • Employee Assistance Program (EAP) program
  • 401K Plan with Company Match
  • 18-21 days of Paid Time Off (PTO) a year based on the tenure
  • 12 Paid Holidays
  • Paid Parental leave
  • Pre-tax commuter benefits
  • MTV- [Free] Electric Car Charging Station

General Description of Other Compensation

“Other Compensation” includes, but is not limited to, bonuses, equity, or other forms of compensation that would be offered to the hired applicant in addition to their established salary or wage scale.

Recruitment Process and Others

Recruitment Process

  • Application Review - Phone Interview - Onsite (or Virtual Onsite) Interview – Offer
  • The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances.
  • Interview schedules and the results will be informed to the applicant via the e-mail address submitted at the application stage.

Details to Consider

  • This job posting may be closed prior to the stated end date for application if all openings are filled.
  • Coupang has the right to rescind an offer of employment if a candidate is found to have submitted false information as part of the application process.
  • Coupang does not discriminate against disabled applicants or those with

This is an external listing. JobSpring does not represent or verify the employer. Report this listing