Staff Security Engineer [Product Security Engineering]

Seoul, South Korea

Coupang

Join us to innovate. Rocket your career. Collaborate with teams across the globe. Find your role and learn more about our culture.

View all jobs at Coupang

Apply now Apply later

We exist to wow our customers. We know we’re doing the right thing when we hear our customers say, “How did we ever live without Coupang?” Born out of an obsession to make shopping, eating, and living easier than ever, we’re collectively disrupting the multi-billion-dollar e-commerce industry from the ground up. We are one of the fastest-growing e-commerce companies that established an unparalleled reputation for being a dominant and reliable force in South Korean commerce.

We are proud to have the best of both worlds — a startup culture with the resources of a large global public company. This fuels us to continue our growth and launch new services at the speed we have been since our inception. We are all entrepreneurial surrounded by opportunities to drive new initiatives and innovations. At our core, we are bold and ambitious people that like to get our hands dirty and make a hands-on impact. At Coupang, you will see yourself, your colleagues, your team, and the company grow every day.

Our mission to build the future of commerce is real. We push the boundaries of what’s possible to solve problems and break traditional tradeoffs. Join Coupang now to create an epic experience in this always-on, high-tech, and hyper-connected world.

 

Team Description:

The Product & Data Security team is responsible for Coupang's application security and data security, which is the foundation of the great experience we deliver to our customers. 

In the area of application security, we are responsible for activities such as security design and auditing of application architecture, design and implementation of SDL processes, auditing and helping to fix application security vulnerabilities, security automation, and more. 

In the Product & Data Security team, you will have access to the full spectrum of application security domains and enjoy an open, diverse work atmosphere.

 

Role Overview:

This position will work as part of the product security engineering team and will be responsible for the implementation of various security activities during SDL and DevSecOps, as well as providing support to the development team.

 

Key Responsibilities:

  • Responsible for the tuning of security scanning tools and the fixing of scanning results
  • Design and various application security-related metrics
  • Implement security left shift and security automation activities
  • Participate in the design and implementation of application security training
  • Review security features of application to ensures that they are implemented properly.
  • Provide remediation guidelines for vulnerabilities
  • Coordinates with various teams involved in Information Security, Risk, Architecture, and development teams.
  • To work together with global teams across different time zones to support urgent project need

 

 

Basic Qualifications:

  • Bachelor's degree in Information Technology, Computer Science, or related field
  • Good understanding of Application risks/vulnerabilities, e.g. OWASP Top 10 /CWE Top 25
  • Minimum 5 years working experience in Information Security
  • Experienced in designing and building application security solutions
  • Experienced in reviewing and implementing application security features 
  • Experience in software supply chain security or vulnerability management of 3rd party libraries 
  • Experience with *AST and SCA tools 
  • Experienced in security integration of CI/CD

 

Preferred Qualifications:

  • Familiar with one or several languages, e.g. Python/Java, can develop simple security tools
  • Experienced in application security training
  • Be responsible, serious, and rigorous at work, strong learning ability, strong communication, and coordination
  • Verbal and written communication skills in English

Office: Jamsil Office (non sponsored work visa)

Recruiting Process: Resume(must write in English) - Virtual Zoom Interviews - Offer

전형 절차 및 기타 사항  

  1. 전형절차: 서류전형(*영문이력서 제출 필) - 화상 기술면접 - 처우협의/최종합격
  2. 전형절차는 직무별로 다르게 운영될 수 있으며, 일정 및 상황에 따라 변동될 수 있습니다.
    • 참고 사항
      • 본 공고는 모집 완료 시 조기 마감될 수 있습니다. 
      • 지원서 내용 중 허위사실이 있는 경우에는 합격이 취소될 수 있습니다.
      • 보훈대상자 및 장애인 여부는 채용 과정에서 어떠한 불이익도 미치지 않습니다. 
    • 개인정보 처리방침 
    • 서류   반환 정책 
      • 본 고지는 『채용절차의 공정화에 관한 법률』 제11조 제6항에 따른 것입니다. 
      • 당사 채용에 응시한 구직자 중 최종합격이 되지 못한 구직자는 『채용절차의 공정화에 관한 법률』에 따라 제출한 채용서류의 반환을 청구할 수 있음을 알려 드립니다. 다만, 홈페이지 또는 전자우편으로 제출된 경우나 구직자가 당사의 요구 없이 자발적으로 제출한 경우에는 그러하지 아니하며, 천재지변이나 그 밖에 당사에게 책임 없는 사유로 채용서류가 멸실된 경우에는 반환한 것으로 봅니다.  
      • 위 2항 본문에 따라 채용서류 반환 청구를 하는 구직자는 채용서류 반환청구서[채용절차의 공정화에 관한 법률 시행규칙 별지 제3호 서식]를 작성하여 당사 이메일( recruitingops@coupang.com )로 제출하면, 제출이 확인된 날로부터 14일 이내에 지정한 주소지로 등기우편을 통하여 발송해 드립니다. 이 경우 등기우편요금은 수신자 부담으로 하게 되오니 유념하시기 바랍니다.  
      • 당사는 위 2항 본문에 따른 구직자의 반환 청구에 대비하여 채용 여부가 확정된 날로부터 180일간 구직자가 제출한 채용서류 원본을 보관하게 되며, 그때까지 채용서류의 반환을 청구하지 아니할 경우에는 『개인정보 보호법』에 따라 지체 없이 채용서류 일체를 파기할 예정입니다. 

 

 

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Application security Audits Automation CI/CD Computer Science DevSecOps E-commerce Java OWASP Privacy Product security Python Vulnerabilities Vulnerability management

Perks/benefits: Career development Startup environment Team events

Region: Asia/Pacific
Country: South Korea

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.