4 hours ago
Base Salary
$108k - $232k/yr
Responsibilities
- Continuously identify and map exposed IT assets including domains, IPs, open ports, and cloud environments.
- Detect shadow IT, abandoned servers, test pages, and other externally exposed blind spots.
- Identify vulnerable application versions and exposed paths, assess business impact, and prioritize remediation.
- Collaborate with infrastructure and development teams to remove vulnerable paths or apply protective measures.
- Implement and operate commercial attack surface management solutions.
- Build and use in-house attack surface discovery tools.
- Automate attack surface identification processes and integrate them with existing security solutions.
Requirements
- Bachelor’s degree in computer science or a related field.
- At least 2 years of experience in security engineering or cybersecurity.
- Preferred: 5+ years of hands-on cybersecurity experience in threat identification, response, assessment, and management, including at least 2 years in attack surface management.
- Experience implementing and operating commercial ASM solutions.
- Experience developing vulnerability scanners or detection scripts from an offensive, attacker-focused perspective.
- Ability to write automation scripts using AWS and Python for API integration and attack surface identification tools.
- Understanding of cloud, on-premises, IoT, user endpoints, DNS, and administrative consoles.
- In-depth knowledge of TCP/IP, DNS, HTTP/S, RDP, and web and cloud architecture security.
- Understanding of attack path discovery, vulnerability exploitation, malware distribution and execution, lateral movement, DDoS, and supply chain attacks.
- Experience with public cloud infrastructure operations and security assessment in AWS, Azure, or GCP environments.
- Hands-on experience in areas such as bug bounty programs, CVE discovery and reporting, penetration testing, incident response, threat hunting, security architecture review, or cyber threat intelligence.
- Experience operating security functions in complex, large-scale global IT infrastructure.
- Intermediate or higher English proficiency; fluent Korean and English proficiency preferred.
Benefits
- Annual bonus of 0–20% of base salary.
- Medical, dental, vision, life, and AD&D insurance.
- Flexible Spending Accounts and Health Savings Account.
- Long-term and short-term disability coverage.
- Employee Assistance Program.
- 401(k) plan with company match.
- 18–21 days of paid time off annually based on tenure.
- 12 paid holidays.
- Paid parental leave.
- Pre-tax commuter benefits.
- Free electric car charging station.
- Recruitment may include an application review, phone interview, and onsite or virtual onsite interview.
Tech Stack
Categories
About Coupang
Coupang builds and operates a South Korea–focused e-commerce marketplace with an end-to-end logistics network (Rocket Delivery), plus food delivery, video streaming, and fintech under brands such as Coupang, Eats, and Play. Revenue comes from first-party retail, third-party marketplace services, advertising, and memberships (Rocket WOW). Founded in 2010, the company is headquartered in Seattle and is publicly listed on the NYSE (CPNG).
