4 hours ago
Responsibilities
- Lead proactive threat hunting across enterprise systems using hypotheses based on attacker TTPs, threat intelligence, and defensive data visibility.
- Apply advanced analytics, behavioral baselines, and statistical methods to large multi-domain log datasets to identify subtle anomalies and indicators of compromise.
- Use and continuously improve MITRE ATT&CK, the Diamond Model, and the NIST Cybersecurity Framework in daily threat-hunting activities.
- Investigate telemetry from SIEM, EDR, NDR, cloud, IAM, and network platforms, emphasizing cross-domain correlation and advanced behavioral analysis.
- Collaborate with SOC, Incident Response, Insider Threat, Detection Engineering, and Threat Intelligence teams to operationalize hunting results.
- Develop reusable threat-hunting playbooks and automation processes using Python, PowerShell, or comparable scripting languages.
- Identify security-control vulnerabilities and gaps and recommend improvements to detection and response capabilities.
- Provide technical mentoring and contribute to continuous improvement across the Security Group.
Requirements
- Bachelor’s degree or higher in cybersecurity, information security, computer science, or a related field.
- At least 8 years of experience in security operations, threat hunting, or incident response.
- Deep understanding of attacker TTPs, adversary tradecraft, and the MITRE ATT&CK framework, with experience applying them to enterprise threat hunting.
- Extensive hands-on experience with SIEM, EDR, cloud security, and log-analysis platforms in large enterprise environments, including multi-tenant or multi-domain environments.
- Strong analytical, investigative, and problem-solving capabilities developed through complex, multi-phase security investigations.
- E-commerce or large enterprise experience is preferred.
- Technical understanding of attacker TTPs, the intrusion lifecycle, lateral movement, and adversary simulation is preferred.
- Experience with Splunk, ELK, UEBA, QRadar, SPL, KQL, SQL, or LogScale is preferred.
- Experience conducting hypothesis-driven threat hunting and investigative research across complex multi-domain telemetry is preferred.
- Experience using Python, PowerShell, or comparable scripting and data-engineering skills to automate threat hunting and develop playbooks is preferred.
- Understanding of malware analysis, network forensics, and EDR/XDR platform internals is preferred.
- Experience identifying security-control gaps and communicating them effectively to stakeholders and leadership is preferred.
- Relevant certifications such as GCTI, GCIH, GCIA, GCED, GCFA, GMLE, CISSP, OffSec SOC-200, OffSec TH-200, or Microsoft SC-200 are preferred.
- Fluency in Korean and English is required or preferred as stated in the posting.
Benefits
- The hiring process includes document screening, first interview, second interview, and final selection, with timing subject to change.
- The posting may close early once the position is filled.
- Veterans and people with disabilities may receive hiring preference under applicable law.
- Job level and scope may be adjusted based on the candidate’s overall career and experience.
- Applicants may request return of submitted documents under applicable South Korean employment law.
About Coupang
Coupang is a technology and Fortune 150 company listed on the New York Stock Exchange (NYSE: CPNG) that provides retail, restaurant delivery, video streaming, and fintech services to customers around the world under brands that include Coupang, Eats, Play, Rocket Now, and Farfetch.