MOMENTUS
모의면접
쿠팡 · Security & Privacy and Data Governance

Staff Security Engineer (AI GRC)

#쿠팡 채용#쿠팡 데이터·AI 면접#데이터·AI 면접

이 공고, 이렇게 물어볼 겁니다

Q1
AI 보안 위험 관리 프레임워크를 설계하고 유지하는 경험에 대해 구체적으로 설명해주세요.
🎯 AI 보안 위험 관리 프레임워크 설계 및 유지 경험 확인
Q2
AI 개발을 위한 기술 가이드라인을 설정하고, 이를 어떻게 보장하는지 설명해주세요.
🎯 AI 개발 기술 가이드라인 설정 및 보장 경험 확인
Q3
AI 관련 위험을 식별하고, 평가 및 완화하는 프로세스를 설명해주세요.
🎯 AI 관련 위험 식별, 평가 및 완화 프로세스 확인
Q4
AI 보안을 위한 기술적 제어 기준을 정의하고, 이를 어떻게 검증하는지 설명해주세요.
🎯 AI 보안 기술적 제어 기준 정의 및 검증 경험 확인
Q5
AI 개발 프로세스에 보안 및 거버넌스 요구사항을 통합하는 경험에 대해 구체적으로 설명해주세요.
🎯 AI 개발 프로세스에 보안 및 거버넌스 요구사항 통합 경험 확인
질문만 읽으면 컨닝이에요. 소리 내어 답해보세요 — 어디서 틀어지는지 짚어드립니다.

공고 내용

Staff AI Security Governance Engineer (AI GRC)

Company Introduction

Role Overview

Coupang is seeking a Staff AI Security Governance Engineer to join our AI GRC (AI Governance, Risk Management, Compliance) team in Seoul. This role is designed for a technical governance strategist who bridges the gap between complex AI regulatory requirements and technical security architecture.

In this role, you will define and architect Coupang’s enterprise AI risk framework, translate regulatory mandates into policy-as-code specifications, and establish the technical guardrails for AI development. You will partner with AI/ML engineers, security architects, Legal, and Privacy teams to set standards, while collaborating with our dedicated Control Assurance team to ensure seamless execution and continuous monitoring.

What You Will Do

· Framework Architecture Policy-as-Code Strategy: Design and maintain Coupang’s AI Security Risk Management Framework (mapped to NIST AI RMF, ISO 42001, MSIT guidelines, and global AI Acts). Architect policy-as-code rule sets and security baseline specifications for deployment across AI pipelines.

· Assurance Partnering: Define the technical control criteria and validation logic that the Control Assurance team will execute, monitor, and audit.

· AI Risk Evaluation Safeguards: Identify, assess, and set mitigation standards for AI-specific threat vectors (e.g., prompt injection, training data leakage, model extraction, shadow AI, and supply chain vulnerabilities) across internal and third-party AI SaaS/LLM deployments.

· Cross-Functional Engineering Alignment: Partner closely with AI platform teams, infrastructure engineers, and security architects to embed governance and security requirements directly into AI architectures, CI/CD workflows, and runtime environments.

· Enterprise AI Policy Ownership: Own the enterprise AI policy lifecycle, establishing clear decision frameworks for AI model adoption, data privacy guardrails, and cross-border data transfer requirements.

Basic Qualifications

· Bachelor’s degree in Computer Science, Information Security, Software Engineering, or a related technical/policy field.

· 10 + years of experience in Information Security, Technical GRC, Security Architecture, or AI/Cloud Governance.

· Deep understanding of AI/ML security risks, cloud security architecture (AWS), and privacy/data protection principles.

· Strong technical literacy to evaluate system architecture diagrams, interpret API/data flow models, and translate policy requirements into technical specifications for engineering and assurance teams.

· Proven track record of architecting governance frameworks (NIST AI RMF, ISO 42001, NIST CSF, PIPA) in tech-driven environments.

· Excellent written and verbal communication skills in English.

Preferred Qualifications

· Experience defining policy-as-code specifications, continuous control monitoring logic, or automated compliance guardrails in cloud environments.

· Hands-on familiarity with AI/ML pipelines, LLM integration architectures, data tokenization techniques, or cloud control planes.

· Experience partnering with operational audit/assurance teams to operationalize GRC metrics and controls.

· Relevant industry certifications (e.g., CISM, CRISC, CISSP, or specialized AI security/governance credentials).

Recruitment Process

· Application Review - Phone Interview - Onsite (or Virtual Onsite) Interview – Offer

Details to Consider

· This job posting may be closed prior to the stated end date for application if all openings

회사마다 모든 공고에 똑같이 붙는 안내 문구(지원 절차·서류 반환·개인정보 고지 1,467자)는 접어뒀어요. 원문에서 전체 보기 →

원문에서 전체 공고 보기 →

이 회사 다른 포지션 · 비슷한 공고