쿠팡 · Security & Privacy and Data Governance

Senior Staff Security Engineer (Digital Trust GRC)

#쿠팡 채용#쿠팡 데이터·AI 면접#데이터·AI 면접

이 공고, 이렇게 물어볼 겁니다

Q1
지난 5년간 보안 위협이 가장 많이 증가한 분야는 무엇이며, 그에 대한 대응책은 무엇인가요?
🎯 보안 위협에 대한 이해와 대응책을 확인
Q2
AWS 클라우드 환경에서 Identity Access Management(IAM)를 설계하고 구현한 경험은 무엇인가요? 또한, 클라우드 보안을 위한 지속적인 모니터링과 자동화에 대한 접근법은 무엇인가요?
🎯 클라우드 보안과 IAM에 대한 이해와 실제 적용 경험을 확인
Q3
Risk Data-Centric Approach를 적용하여 보안 위험을 평가하고 완화한 경험은 무엇인가요? 또한, 보안 메트릭스와 텔레메트리 데이터를 사용하여 위험을 평가하는 방법은 무엇인가요?
🎯 Risk Data-Centric Approach에 대한 이해와 실제 적용 경험을 확인
Q4
Cross-Functional Communication Partnerships를 통해 보안 거버넌스 우선순위를 기술 팀과 비즈니스 리더에게 전달한 경험은 무엇인가요? 또한, 기술 팀과 비즈니스 리더를 설득하여 보안 거버넌스 우선순위를 Align 시킨 방법은 무엇인가요?
🎯 보안 거버넌스 우선순위를 전달하고 Align 시키는 방법을 확인
질문만 읽으면 컨닝이에요. 소리 내어 답해보세요 — 어디서 틀어지는지 짚어드립니다.

공고 내용

We exist to wow our customers. We know we’re doing the right thing when we hear our customers say, “How did I ever live without Coupang?” Born out of an obsession to make shopping, eating, and living easier than ever, we are collectively disrupting the multi-billion-dollar commerce industry from the ground up and establishing an unparalleled reputation for being leading and reliable force in South Korean commerce.

We are proud to have the best of both worlds — a startup culture with the resources of a large global public company. This fuels us to continue our growth and launch new services at the speed we have been since our inception. We are all entrepreneurs surrounded by opportunities to drive new initiatives and innovations. At our core, we are bold and ambitious people that like to get our hands dirty and make a hands-on impact. At Coupang, you will see yourself, your colleagues, your team, and the company grow every day.

Our mission to build the future of commerce is real. We push the boundaries of what’s possible to solve problems and break traditional tradeoffs. Join Coupang now to create an epic experience in this always-on, high-tech, and hyper-connected world.

Team Introduction

The Digital Trust GRC Team plays a pivotal role in proactively identifying security risks and establishing robust security governance in a hyper-growth environment. Moving beyond checklist-driven compliance, we champion a "Risk Data-centric" approach that understands deep technical context to maintain robust security posture without slowing down business innovation. We closely collaborate with engineering teams to design, implement, and run our own Control Assurance Framework that fosters trust and safety across our entire ecosystem.

Key Responsibilities

· Design Operationalize Control Assurance Framework : Architect, implement, and continuously mature the organization's Control Assurance Framework. Establish mechanisms to validate that security controls are functioning effectively and continuously.

· Tailoring Global Standards : Interpret and tailor global security standards (e.g., NIST CSF, NIST SP 800-53, ISO 27001, SOC 2) to fit Coupang environment.

· Incorporate Technical Incidents into Governance Strategy : Analyze real-world security incidents, vulnerabilities, and technical issues through a GRC lens. Formulate, execute, and refine long-term security governance strategies to prevent recurrence.

· Drive Risk Data-Centric Approach : Utilize security metrics and telemetry data to conduct risk assessments, prioritize risk registers, and propose practical mitigation controls that materially reduce the organization’s attack surface.

· Cross-Functional Communication Partnerships : Act as a bridge between Digital Trust GRC, Security Engineering, DevOps, and business leaders. Successfully communicate complex risk profiles and influence technical teams to align on security governance priorities.

· Elevate GRC Technical Capability : Leverage deep technical domain knowledge (Cloud Security, IAM, Application Security) to guide other GRC team members, helping elevate the overall technical literacy and analytical capacity of the GRC team.

Basic Qualifications

· 10+ years of professional experience in Security GRC, Information Security, or Security Engineering (or equivalent proven leadership as an Individual Contributor).

· I n-depth expertise in Global Security Frameworks (such as NIST CSF, NIST SP 800-53, ISO 27001, SOC 2, PCI-DSS) with hands-on experience in tailoring and mapping controls to dynamic environments.

· Strong technical knowledge of AWS cloud environments , including cloud architecture, Identity Access Management (IAM), and continuous compliance monitoring/automation.

· Demonstrated Risk Data-centric mindset with the ability to translate technical security incidents into actionable business risk and remediation strategies.

· Exceptional communication, writing, and stakeholder-management skills, with a proven track record of building consensus and trust among diverse technical and non-technical teams.

Preferred Qualifications

· Experience establishing GRC guidelines in large-scale logistics, e-commerce, or highly dynamic distributed environments.

· Relevant professional certifications such as CISA, CISM, CRISC, CISSP, CCSK, or AWS Certified Security - Specialty.

· Experience defining automated security metrics or designing Continuous Controls Monitoring (CCM) using data-driven tools (e.g., SQL, Python).

Recruitment Process and Others:

Recruitment Process

· Application Review - 1st Interview - Virtual Onsite Interviews - Offer

· The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances.

· Interview schedules and the results will be informed to the applicant via the e-mail address submitted at the application stage.

Things to Consider

· This job posting may be closed prior to the stated end date for application if all openings are fill

원문에서 전체 공고 보기 →

이 회사 다른 포지션 · 비슷한 공고