Hiring.Camp

Senior Staff Security Engineer (Digital Trust GRC)

Coupang

Location
Seoul, South Korea · Seoul
Department
Security
Seniority
Senior
Experience
10+ years

Description

We exist to wow our customers. We know we’re doing the right thing when we hear our customers say, “How did I ever live without Coupang?” Born out of an obsession to make shopping, eating, and living easier than ever, we are collectively disrupting the multi-billion-dollar commerce industry from the ground up and establishing an unparalleled reputation for being leading and reliable force in South Korean commerce.

We are proud to have the best of both worlds — a startup culture with the resources of a large global public company. This fuels us to continue our growth and launch new services at the speed we have been since our inception. We are all entrepreneurs surrounded by opportunities to drive new initiatives and innovations. At our core, we are bold and ambitious people that like to get our hands dirty and make a hands-on impact. At Coupang, you will see yourself, your colleagues, your team, and the company grow every day.

Our mission to build the future of commerce is real. We push the boundaries of what’s possible to solve problems and break traditional tradeoffs. Join Coupang now to create an epic experience in this always-on, high-tech, and hyper-connected world.

Team Introduction 

The Digital Trust GRC Team plays a pivotal role in proactively identifying security risks and establishing robust security governance in a hyper-growth environment. Moving beyond checklist-driven compliance, we champion a "Risk & Data-centric" approach that understands deep technical context to maintain robust security posture without slowing down business innovation. We closely collaborate with engineering teams to design, implement, and run our own Control Assurance Framework that fosters trust and safety across our entire ecosystem. 

Key Responsibilities 

  • Design & Operationalize Control Assurance Framework: Architect, implement, and continuously mature the organization's Control Assurance Framework. Establish mechanisms to validate that security controls are functioning effectively and continuously. 
  • Tailoring Global Standards: Interpret and tailor global security standards (e.g., NIST CSF, NIST SP 800-53, ISO 27001, SOC 2) to fit Coupang environment. 
  • Incorporate Technical Incidents into Governance Strategy: Analyze real-world security incidents, vulnerabilities, and technical issues through a GRC lens. Formulate, execute, and refine long-term security governance strategies to prevent recurrence. 
  • Drive Risk & Data-Centric Approach: Utilize security metrics and telemetry data to conduct risk assessments, prioritize risk registers, and propose practical mitigation controls that materially reduce the organization’s attack surface. 
  • Cross-Functional Communication & Partnerships: Act as a bridge between Digital Trust GRC, Security Engineering, DevOps, and business leaders. Successfully communicate complex risk profiles and influence technical teams to align on security governance priorities. 
  • Elevate GRC Technical Capability: Leverage deep technical domain knowledge (Cloud Security, IAM, Application Security) to guide other GRC team members, helping elevate the overall technical literacy and analytical capacity of the GRC team. 

Basic Qualifications  

  • 10+ years of professional experience in Security GRC, Information Security, or Security Engineering (or equivalent proven leadership as an Individual Contributor). 
  • In-depth expertise in Global Security Frameworks (such as NIST CSF, NIST SP 800-53, ISO 27001, SOC 2, PCI-DSS) with hands-on experience in tailoring and mapping controls to dynamic environments. 
  • Strong technical knowledge of AWS cloud environments, including cloud architecture, Identity & Access Management (IAM), and continuous compliance monitoring/automation. 
  • Demonstrated Risk & Data-centric mindset with the ability to translate technical security incidents into actionable business risk and remediation strategies. 
  • Exceptional communication, writing, and stakeholder-management skills, with a proven track record of building consensus and trust among diverse technical and non-technical teams. 

 Preferred Qualifications 

  • Experience establishing GRC guidelines in large-scale logistics, e-commerce, or highly dynamic distributed environments. 
  • Relevant professional certifications such as CISA, CISM, CRISC, CISSP, CCSK, or AWS Certified Security - Specialty. 
  • Experience defining automated security metrics or designing Continuous Controls Monitoring (CCM) using data-driven tools (e.g., SQL, Python). 

 Recruitment Process and Others:

Recruitment Process

  • Application Review - 1st Interview - Virtual Onsite Interviews - Offer
  • The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances.
  • Interview schedules and the results will be informed to the applicant via the e-mail address submitted at the application stage.

Things to Consider

  • This job posting may be closed prior to the stated end date for application if all openings are filled.
  • Coupang has the right to rescind an offer of employment if a candidate is found to have submitted false information as part of the application process.
  • Coupang does not discriminate against disabled applicants or those with veteran status. We are proud to offer equal opportunities for all applicants.

Privacy Notice

  • Your personal information will be collected and managed by Coupang as stated in the Application Privacy Notice located below.
  • https://www.coupang.jobs/en/privacy-policy/

Document Return Policy

  • This notification is given pursuant to Article 11 (6) of the Fair Hiring Procedure Act.
  • A job applicant, who has applied but not been finally selected for a position at Coupang (the “ Company ”), may request the Company to return his/her hiring documents submitted pursuant to the Fair Hiring Procedure Act. However, this will not apply where the hiring documents were submitted via the website of the Company or e-mail, or where the job applicant submitted those documents voluntarily without a request from the Company. In addition, if the hiring documents were destroyed due to a natural disaster or any other reasons not attributable to the Company, such documents will be deemed to have been returned to the job applicant.
  • A job applicant who wishes to request the return of his/her hiring documents pursuant to the main sentence of paragraph 2 above should fill out a “Request for Return of Hiring Documents” [Annex Form No. 3 in the Enforcement Rule of the Fair Hiring Procedure Act] and submit the request to the Company by email ([email protected]) In such case, within fourteen (14) days from the date of identifying the receipt of the request, the Company will send the hiring documents to the job applicant’s designated address via registered mail. Please be informed that the job applicant is required to pay the postage on the registered mail.
  • In preparation for a job applicant’s request for the return of hiring documents pursuant to the main sentence of paragraph 2 above, the Company shall retain the original hiring documents submitted by the job applicant for 180 days from the completion of the recruiting process. If no request is made until the end of this period, all of his/her hiring documents will be destroyed immediately in accordance with the Personal Information Protection Act.

Equal Opportunities for All

Coupang is an equal opportunity employer. Our unprecedented success could not be possible without the valuable inputs of our globally diverse team.

Skills

PythonAWSSQLSOCDevOpsComplianceSOC 2ISO 27001AWS CertifiedCISSP

Similar Jobs

30

Senior Staff Security Engineer

Form Energy · Berkeley, CA · Onsite

5 days ago

Senior Staff Security Engineer

Qualcomm · San Diego, CA,US, US

5 days ago

Staff / Senior Security Engineer, Firmware Test, SSD

Micron · MSB, Singapore

1 month ago

Staff / Senior Security Engineer, Firmware Test, SSD

Micron Technology · SG

1 month ago

Senior Staff Security Analyst

OpenLoop Health · United States - Remote +3 · Remote

1 month ago

Senior/Staff Security Engineer, Threat Intelligence

Anthropic · Zürich, CH +1 · Onsite

1 month ago

Senior Staff Security Incident Commander | Security Org

ServiceNow · Santa Clara, California, United States · Remote

1 month ago

Senior Staff Security Architect, Embedded Systems

Dolby · Dublin, D,IE, IE

1 month ago

Staff/Senior Security Engineer - DeFi

Ethenalabs · Globally Remote · Remote

2 months ago

Senior Staff Security Engineer - Network Security

"Gusto, Inc." · San Francisco, CA +1

2 months ago

Senior Staff Security Engineer, Corporate Security

Outreach · United States · Remote

3 months ago

Platform Engineer, Security (Senior/Staff)

Pallet · San Francisco or New York +1

3 months ago

Senior / Staff Security Engineer, Red Team

Radar · New York · Onsite

4 months ago

Senior Staff Security Architect

Cloudera Careers · Canada-Ontario-Toronto · Remote

4 months ago

Senior Staff Security Governance & Compliance Analyst

Diligentcorporation · Bengaluru, Karnataka, India

5 months ago

Information Security - Senior Staff Architect

Deluxe · Chennai-TN-IND, India

5 months ago

Senior Staff Security Architect - First Advantage (Bangalore/Mumbai)

First Advantage · Bangalore, Karnataka · Hybrid

5 months ago

Senior Staff Security Infrastructure Engineer

Bloomreach · Czechia +1

6 months ago

Senior Staff Security Infrastructure Engineer

Bloomreach · Slovakia

6 months ago

Senior/Staff Security Engineer

Zettabyte · United States · Hybrid

6 months ago

Senior Staff Cloud Security Engineer – Financial Services - Office of the CISO

ServiceNow · Toronto, Ontario, Canada · Remote

4 days ago

Senior Staff Cloud Security Engineer | Operational Technology | Office of CISO

ServiceNow · Alberta, CANADA, Canada · Remote

4 days ago

Senior Staff Cloud Security Engineer – Office of the CISO

ServiceNow · Toronto, Ontario, Canada · Remote

1 week ago

Senior Staff Cloud Security Engineer | Operational Technology | Office of CISO

ServiceNow · Toronto, Ontario, Canada · Remote

1 week ago

Senior Staff Product Security Engineer | Product Security Incident Response Team (PSIRT)

ServiceNow · Kirkland, Washington, United States · Hybrid

2 weeks ago

Senior Staff Product Security Engineer | Product Security Incident Response Team (PSIRT)

ServiceNow · Kirkland, Washington, United States · Hybrid

2 weeks ago

Senior Staff Product Security Engineer | Product Security Incident Response Team (PSIRT)

ServiceNow · Kirkland, Washington, United States · Remote

2 weeks ago

Senior Staff SaaS Security Architect

Statestreet · BOSTON, United States of America +3

2 weeks ago

Senior/Staff Engineer, Security Platform Development

Okx · Hong Kong, Hong Kong SAR; Singapore, Singapore +2

2 weeks ago

Senior/Staff Network Security Engineer

Zoox · Foster City, CA · Hybrid

1 month ago