Senior Security Engineer
$91,000–$149,600 year
On-siteLos Angeles, California, United States
Job Summary
Operate and manage public/private bug bounty programs on platforms like HackerOne, triaging incoming reports, interfacing with security researchers, and validating vulnerabilities to drive remediation. Coordinate third-party penetration testing engagements, review deliverables, and track remediation to closure while owning internal security testing tickets for web and mobile applications. Participate in offensive and defensive red/blue team exercises to strengthen the security posture and contribute to AI/LLM application security efforts, including security testing and automation. Provide actionable remediation guidance to engineering teams and stakeholders. This role supports SHEIN's global security engineering team in safeguarding products and infrastructure, with a focus on emerging AI threats and on-demand production methodologies.
Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent practical experience)
- Solid understanding of the OWASP Top 10 and common web/mobile application vulnerabilities
- Hands-on experience with web application vulnerability assessments and penetration testing
- Familiarity with bug bounty platforms (e.g., HackerOne, Bugcrowd) and triage workflows
- Strong communication skills; ability to translate technical findings into clear remediation guidance
Desired Qualifications
- Professional proficiency in Mandarin Chinese (to collaborate effectively with global / Chinese-speaking teams)
- Relevant certifications such as OSCP, GWAPT, or similar
- Experience with AI/LLM security testing and security automation
- Experience coordinating third-party pentest vendors and managing remediation lifecycles
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.