Yahoo Taiwan Holdings Limited

Sr Technical Security Engineer

Yahoo Taiwan Holdings Limited · Taipei, Taiwan

Software Development · 201-500 employees

14 h ago
Mid (2-5 yrs) Full-time Taiwan
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The engineer will manage cloud and SDLC security, including defining security requirements and conducting web security assessments. They are also responsible for monitoring security events, managing vulnerabilities, and driving the adoption of security policies across the organization.

What they look for

Cloud Security SDLC Security Web Security Vulnerability Assessment PCI DSS AWS GCP OWASP Top 10 DevOps Software Architecture Incident Response Security Policy Risk Management Security Monitoring Application Programming

Requirements

Candidates must have a degree in a STEM field or equivalent experience, along with at least 3 years of relevant professional experience. Proficiency in cloud platforms like AWS or GCP and knowledge of web security vulnerabilities and countermeasures are required.

Full description

Yahoo Taiwan E-Commerce empowers the e-commerce world with advanced business process analytics, reporting, and optimization tools designed to drive success within Yahoo Taiwan E-commerce ecosystem. Innovation is at the core of everything we do — we continuously test, refine, and integrate cutting-edge technologies to stay ahead of the curve and enhance our infrastructure. Our team is dedicated to creating high-quality products and tools that not only prioritize usability and efficiency but also foster sustainable business growth for our customers and partners.

Responsibilities We are looking for a Security Engineer responsible for cloud security, SDLC security, and security planning for TWEC.

  • Collaborate on secure software development processes, including defining security requirements, reviewing software architecture, reviewing code and providing vulnerability consultation.
  • Conduct web security assessments and ensure compliance with standards such as PCI DSS.
  • Develop and maintain scalable strategies and policies to secure TWEC's public cloud platforms.

Drive company-wide adoption of cloud and compute security policies.

  • Design and implement enhancements to identify security misconfigurations accurately. Conduct thorough security reviews and provide project consultation.
  • Evaluate and manage vulnerabilities across cloud environments, prioritize remediation efforts, and ensure continuous monitoring of potential threats.
  • Monitor, evaluate, and respond to security alerts and events. Handle and analyze incidents to support effective resolution.
  • Identify security risks and recommend improvement plans to enhance resilience.

Qualifications

  • BS/MS in a Science/Technology/Engineering/Mathematics related field or equivalent experience

3+ years of related experience

  • Experience with application programming or devops and the overall software development life cycle
  • Good knowledge of web security vulns and countermeasures, including the OWASP Top 10
  • Familiarity with the security features and best practices of major cloud platforms, such as AWS and GCP.
  • Good communication and collaboration skills to work with people from a variety of technical backgrounds