10 days ago
Seoul, Korea, SouthStaff+
Responsibilities
- Lead proactive threat hunting across enterprise systems using hypotheses based on attacker TTPs, threat intelligence, and defensive data visibility.
- Apply advanced analytics, behavioral baselines, and statistical methods to large multi-domain log datasets to identify subtle anomalies and indicators of compromise.
- Use and continuously improve MITRE ATT&CK, the Diamond Model, and the NIST Cybersecurity Framework in daily threat-hunting activities.
- Investigate telemetry from SIEM, EDR, NDR, cloud, IAM, and network platforms, emphasizing cross-domain correlation and advanced behavioral analysis.
- Collaborate with SOC, Incident Response, Insider Threat, Detection Engineering, and Threat Intelligence teams to operationalize hunting results.
- Develop reusable threat-hunting playbooks and automation processes using Python, PowerShell, or comparable scripting languages.
- Identify security-control vulnerabilities and gaps and recommend improvements to detection and response capabilities.
- Provide technical mentoring and contribute to continuous improvement across the Security Group.
Requirements
- Bachelor’s degree or higher in cybersecurity, information security, computer science, or a related field.
- At least 8 years of experience in security operations, threat hunting, or incident response.
- Deep understanding of attacker TTPs, adversary tradecraft, and the MITRE ATT&CK framework, with experience applying them to enterprise threat hunting.
- Extensive hands-on experience with SIEM, EDR, cloud security, and log-analysis platforms in large enterprise environments, including multi-tenant or multi-domain environments.
- Strong analytical, investigative, and problem-solving capabilities developed through complex, multi-phase security investigations.
- E-commerce or large enterprise experience is preferred.
- Technical understanding of attacker TTPs, the intrusion lifecycle, lateral movement, and adversary simulation is preferred.
- Experience with Splunk, ELK, UEBA, QRadar, SPL, KQL, SQL, or LogScale is preferred.
- Experience conducting hypothesis-driven threat hunting and investigative research across complex multi-domain telemetry is preferred.
- Experience using Python, PowerShell, or comparable scripting and data-engineering skills to automate threat hunting and develop playbooks is preferred.
- Understanding of malware analysis, network forensics, and EDR/XDR platform internals is preferred.
- Experience identifying security-control gaps and communicating them effectively to stakeholders and leadership is preferred.
- Relevant certifications such as GCTI, GCIH, GCIA, GCED, GCFA, GMLE, CISSP, OffSec SOC-200, OffSec TH-200, or Microsoft SC-200 are preferred.
- Fluency in Korean and English is required or preferred as stated in the posting.
Benefits
- The hiring process includes document screening, first interview, second interview, and final selection, with timing subject to change.
- The posting may close early once the position is filled.
- Veterans and people with disabilities may receive hiring preference under applicable law.
- Job level and scope may be adjusted based on the candidate’s overall career and experience.
- Applicants may request return of submitted documents under applicable South Korean employment law.
About Coupang
Coupang builds and operates a South Korea–focused e-commerce marketplace with an end-to-end logistics network (Rocket Delivery), plus food delivery, video streaming, and fintech under brands such as Coupang, Eats, and Play. Revenue comes from first-party retail, third-party marketplace services, advertising, and memberships (Rocket WOW). Founded in 2010, the company is headquartered in Seattle and is publicly listed on the NYSE (CPNG).
