11 дней назад
Senior Security Engineer, Penetration Tester (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Engineer, Penetration Tester (Cybersecurity): Conducting authorized penetration tests across web, mobile, API, and cloud-related environments with an accent on vulnerability validation, technical evidence, and actionable remediation guidance. Focus on analyzing complex attack surfaces, automating security-testing workflows with scripts, and coordinating findings across Taiwan and Korea security activities.
Location: Taipei, Taiwan
Company
operates an e-commerce and delivery platform, including Rocket Delivery and international commerce services in Taiwan.
What you will do
- Execute authorized penetration tests across web applications, mobile applications, APIs, and cloud-related attack surfaces.
- Identify attack surfaces, apply testing methods, and document evidence for validated findings.
- Assess vulnerabilities, eliminate false positives, and provide actionable remediation guidance.
- Use Linux, command-line utilities, and penetration-testing tools for controlled security testing.
- Build or modify scripts for request automation, test-data processing, and results analysis.
- Coordinate scope, blockers, findings, and next steps with the Korea security team and Taiwan stakeholders.
Requirements
- Hands-on penetration-testing experience across web, mobile, or API environments.
- Experience using penetration-testing tools in Linux or command-line environments.
- Ability to assess vulnerabilities, explain evidence and impact, and recommend remediation.
- Programming or scripting capability supporting security testing.
- Offensive-security experience sufficient to execute defined testing activities with appropriate support.
- Ability to communicate security findings and remediation guidance in English and Traditional Chinese.
Nice to have
- Experience testing complex applications, external services, or internal systems through penetration testing or authorized bug-bounty work.
- Cloud-security testing experience, including architecture, identity and access, public interfaces, or configuration risks.
- Red Team or adversary-simulation experience.
- Offensive-security certifications such as OSCP, OSCE, OSED, CREST, or SANS.
- Experience preparing bilingual security summaries, testing plans, and remediation comparisons.
Culture & Benefits
- Collaboration with security stakeholders in Taiwan and Korea.
- Work supporting 's expansion and security activities in Taiwan.
- The role is classified as L5 and includes defined testing scope, guidance, and technical support.
Hiring process
- Application review.
- Phone interview.
- Onsite or virtual onsite interview, followed by an offer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →