Sr Security Engineer - Red Team - 11817
Coupang · India
Coupa makes margins multiply through its community-generated AI and industry-leading total spend management platform for businesses large and small. Coupa AI is informed by trillions of dollars of direct and indirect spend data across a global network of 10M+ buyers and suppliers. We empower you with the ability to predict, prescribe, and automate smarter, more profitable business decisions to improve operating margins.
Why join Coupa?
🔹 Pioneering Technology: At Coupa, we're at the forefront of innovation, leveraging the latest technology to empower our customers with greater efficiency and visibility in their spend. 🔹 Collaborative Culture: We value collaboration and teamwork, and our culture is driven by transparency, openness, and a shared commitment to excellence. 🔹 Global Impact: Join a company where your work has a global, measurable impact on our clients, the business, and each other.
Learn more on Life at Coupa blog and hear from our employees about their experiences working at Coupa.
The Impact of a Sr Security Engineer at Coupa: Coupa's Sr Security Engineer is a key part of the Red Team, responsible for challenging and improving the company's security posture by simulating real-world attacks. This role will involve executing programs and tools to protect the Coupa Cloud for our growing customer base. This is a hands-on role. We need people who are self-motivated, have a strong desire to learn, a can-do attitude, tenacity to solve problems, team players, and results focused.
What You’ll Do : As a Sr Security Engineer, you will execute sophisticated penetration tests and red team exercises. You will also contribute to the development of new attack techniques and testing methodologies. Conduct penetration testing on internally and externally hosted applications such as Web apps, Mobile Apps, AI/LLM and APIs, leveraging both traditional and AI-powered tools. Perform specialized security assessments and penetration testing on Coupa's AI and LLM integrations, specifically targeting prompt injection, jailbreaking, data poisoning, and model evasion. Develop, deploy, and manage AI agents for continuous and autonomous security testing and vulnerability discovery. Identify network and system vulnerabilities and provide recommended countermeasures or mitigating controls to reduce risk to an acceptable and manageable level. Perform penetration and remediation testing & reporting and apply advanced penetration techniques in a fast-paced, highly technical environment. Guide and consult development teams on secure coding best practices, including security for AI/ML models. Serve as a key escalation point during critical security incidents, leveraging deep technical knowledge to lead root-cause analysis and threat hunting efforts. Maintain, support, and extend our application security tooling, standards, and processes, including but not limited to SAST, DAST, WAF, and emerging AI-based security analysis platforms.
What You Will Bring to Coupa : 3-8 years of experience in an equivalent security-related role, with hands-on experience in AI-driven security testing. Bachelor's or Master's degree in Computer Science (or equivalent), or equivalent experience. Hands-on Experience in developing or utilizing autonomous, agentic systems for security penetration testing. Proven track record of building and maintaining cross-functional relationships, effectively navigating organizational friction to implement necessary security improvements. Relevant security certifications are a plus, but not required (CEH, OSCP, GPEN, LPT, EWPTX). Strong experience in web / API security, with a focus on testing and defending against attacks on AI/ML systems. Familiarity with Cloud environments such as AWS, Azure, GCP. Hands on experience in handling and managing bug bounty programs. Proficiency in one or more scripting languages, with a strong preference for Python for AI/ML development. Knowledge of common application security issues (e.g., OWASP Top 10, SANS Top 25) and familiarity with the OWASP Top 10 for Large Language Models. Well-versed with pentest standards/frameworks such as PTES, OSSTMM, NIST, OSINT, and OWASP. Ability to translate complex, highly technical security findings into actionable business risks for non-technical stakeholders and executive leadership. Ability to work in a team environment.