Senior Security Engineer; Attack Surface Identification
Listed on 2026-09-14
-
IT/Tech
Cybersecurity
We exist to wow our customers. We know we’re doing the right thing when we hear our customers say, “How did we ever live without Coupang?” Born out of an obsession to make shopping, eating, and living easier than ever, we’re collectively disrupting the multi-billion-dollar e-commerce industry from the ground up. We are one of the fastest-growing e-commerce companies that established an unparalleled reputation for being a dominant and reliable force in South Korean commerce.
We are proud to have the best of both worlds — a startup culture with the resources of a large global public company. This fuels us to continue our growth and launch new services at the speed we have been since our inception. We are all entrepreneurs surrounded by opportunities to drive new initiatives and innovations. At our core, we are bold and ambitious people that like to get our hands dirty and make a hands-on impact.
At Coupang, you will see yourself, your colleagues, your team, and the company grow every day.
Our mission to build the future of commerce is real. We push the boundaries of what’s possible to solve problems and break traditional tradeoffs. Join Coupang now to create an epic experience in this always-on, high-tech, and hyper-connected world.
Role OverviewThis role mitigates security threats by continuously identifying IT interfaces and digital footprints exposed to attackers. As attackers' infiltration methods evolve rapidly with advancements in AI technology, proactive attack surface management is no longer an option, but a necessity. We are looking for an expert to join us in achieving our proactive cybersecurity mission to minimize attack surface exposure, staying one step ahead of the attackers.
WhatYou Will Do
- Continuous Monitoring of Digital Footprint:
Constantly identify and map our officially/unofficially exposed IT assets (domains, IPs, open ports, cloud environments, etc.). - Discovery of Shadow IT & Blind Spots:
Proactively detect abandoned servers, test pages, and unnecessary exposed interfaces that are out of the management organization's visibility. - Vulnerability Identification & Mitigation Strategy:
Identify vulnerable application versions and paths exposing internal information, evaluate them based on business impact, and prioritize remediation efforts. - Cross-functional Collaboration & Proactive Defense:
Work closely with infrastructure and development teams to swiftly eliminate vulnerable paths or apply protective measures before an attack surface leads to a real breach. - ASM Solution Implementation & Operation:
Implement and operate commercial ASM solutions while simultaneously building and utilizing our own in-house Attack Surface Discovery tools. - ASM Automation Pipeline:
Automate processes to streamline attack surface identification and establish integration architectures with existing security solutions.
- Bachelors Degree in Computer Science or a related field
- 2 years of experience in Security Engineering or Cybersecurity
- 5+ years of hands‑on experience in cybersecurity threat identification, response, assessment, and management (with at least 2 years of experience in Attack Surface Management preferred).
Skills:
- ASM Solution Utilization:
Experience in implementing and operating commercial ASM solutions. - Scanner & Script Development:
Experience developing vulnerability scanners or detection scripts from an attacker's perspective (Offensive perspective). Usage of AI IDEs is highly welcomed. - Security Automation:
Ability to efficiently write automation scripts utilizing AWS resources and Python for API integration and building attack surface identification tools.
- Security Architecture Understanding:
Structural…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).