Job Description:
- Perform security assessments and penetration testing on Shopee's web applications, APIs and internal systems find real, exploitable issues and drive them to closure with engineering teams.
- Review code and architecture designs to catch security flaws before they ship, and help embed security requirements into new business and technology initiatives.
- Build and improve the security automation and tooling that scales the team's coverage beyond manual review: in-house AI agents for security workflows, as well as SAST, DAST and SCA capabilities integrated into the development pipeline.
- Assess the security of AI-powered features and internal AI tooling - prompt injection, unsafe tool/agent invocation, data leakage and over-permissive integrations.
- Support vulnerability response and incident investigation track industry trends and bring what you learn back into our defences.
Requirements:
- Solid networking and web fundamentals: a working understanding of L4/L7 protocols, HTTP, TLS, session and authentication mechanisms, and the risks introduced by common cryptographic misuse.
- Familiar with the OWASP Top 10 - able to explain the root cause, exploitation path and correct remediation of each class understands the mechanics and exploit chains of landmark vulnerabilities such as fastjson and log4j.
- Proficient in at least one of Go, Java, Python, PHP, C or JavaScript able to read design documents and business code, and to script your way out of repetitive work.
- Basic grasp of business-logic vulnerabilities: broken access control, authentication bypass, race conditions and flawed workflows.
- Aware of the security risks in AI / LLM applications (e.g. the OWASP Top 10 for LLM Applications), with genuine curiosity about how AI is reshaping both the attack surface and the defender's toolkit.
- A fast learner who communicates clearly - able to explain a vulnerability to engineers without a security background.
Preferred Qualifications:
- Interested in security engineering: understands the basic principles and limitations of SAST / DAST / SCA, and prefers building tools over repeating manual work.
- CVEs credited in well-known open-source projects or general-purpose software, especially framework-level findings.
- Placements in CTF competitions, or a consistent track record on SRC / bug bounty platforms.
- Has built security tooling: scanners, fuzzers, SAST rules (Semgrep / CodeQL), Burp extensions, or LLM-based security automation and agents.
- A security blog, GitHub projects, conference talks or published research.