Назад
Company hidden
11 дней назад

Staff Security Engineer, Penetration Tester

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
SK/Taiwan
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Engineer, Penetration Tester (Cybersecurity): Conducting hands-on penetration testing across web, mobile, API, and cloud-related environments in Taiwan with an accent on vulnerability validation, technical impact assessment, and actionable remediation guidance. Focus on independently managing testing engagements, analyzing complex attack surfaces, and coordinating security delivery with Taiwan and Korea stakeholders.

Location: Taipei, Taiwan

Company

hirify.global is expanding its e-commerce and delivery services in Taiwan, including Rocket Delivery and Rocket Overseas.

What you will do

  • Lead or execute authorized penetration tests across web applications, mobile applications, APIs, cloud environments, external services, and internal systems.
  • Define testing scope and attack surfaces, select testing methods, and document evidence, limitations, and outcomes.
  • Assess vulnerabilities, validate technical impact, distinguish verified findings from false positives, and provide remediation guidance.
  • Use Linux, command-line utilities, and penetration-testing tools for controlled security testing.
  • Build or modify scripts for request automation, test-data processing, and security-test result analysis.
  • Coordinate scope, ownership boundaries, escalation paths, status updates, and deliverables with the Korea security team and Taiwan stakeholders.

Requirements

  • Hands-on penetration-testing experience across web, mobile, or API environments.
  • Experience using penetration-testing tools in Linux or command-line environments.
  • Ability to assess vulnerabilities, explain evidence and impact, and provide actionable remediation guidance.
  • Experience testing multiple applications, external services, or internal applications through penetration testing or legally authorized bug-bounty work.
  • Ability to communicate security findings and remediation guidance in English and Traditional Chinese.
  • Ability to coordinate security activities across Taiwan and Korea, including scope, responsibilities, escalation, and delivery communication.

Nice to have

  • Red Team or adversary-simulation experience in complex application environments.
  • Cloud-security testing experience covering architecture, identity and access, public interfaces, or configuration risks.
  • Offensive-security certifications such as OSCP, OSCE, OSED, CREST, or SANS.
  • Experience preparing authorized penetration-testing cases, multi-interface testing plans, remediation comparisons, and concise bilingual security summaries.
  • A degree in Computer Science, Computer Engineering, or a related field.

Culture & Benefits

  • Cross-regional collaboration with security stakeholders in Taiwan and Korea.
  • High-tempo work across complex applications, external services, and internal systems.
  • Employment protection measures may provide preferential treatment to eligible veterans and persons with disabilities under applicable laws.

Hiring process

  • Application review, phone interview, onsite or virtual onsite interview, and offer.
  • The process may vary according to the role and scheduling circumstances.
  • Interview schedules and results are communicated by email.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →