12 hours ago
Seoul, Korea, SouthStaff+
Responsibilities
- Establish technical direction and design the end-to-end architecture for security data platforms such as SIEM and automation platforms such as SOAR.
- Solve architecture-level reliability, performance, and cost-efficiency problems in large-scale security log pipelines.
- Design SOAR workflows and AI-SOC systems, resolve technical challenges, and define quality standards.
- Advance the Detection-as-Code framework, including detection-rule lifecycle management, automated testing, and deployment pipelines.
- Technically evaluate the selection, adoption, and replacement of security solutions.
- Provide technical advice and impact analysis for enterprise security architecture changes and new system introductions from the Detection Engineering perspective.
- Design architectures for AI- and LLM-based security automation.
Requirements
- At least 10 years of experience in security engineering or security infrastructure.
- Deep understanding of SIEM architecture, data pipelines, and detection engines, including implementation, large-scale operations, performance optimization, and migration.
- Hands-on experience designing, building, and operating SOAR or security automation platforms, including workflow principles, solution-integration architecture, and incident-response mechanisms.
- Python development skills sufficient to produce both prototypes and production-grade code.
- Broad practical experience with the operating principles and integration methods of security solutions such as EDR, CTI, ticketing systems, and cloud security services.
- Understanding and implementation experience in AI/LLM-based security automation or AI-SOC systems, including LLM agent architecture, prompt design, and automated analysis and decision workflows.
- Ability to structure complex technical problems and clearly articulate trade-offs.
- Deep experience with both SIEM and SOAR and making architectural decisions at their intersection.
- Experience designing and operating large-scale system architectures in cloud environments such as AWS.
- Preferred: experience architecting or introducing AI-SOC or LLM-based security automation systems.
- Preferred: experience optimizing costs for large-scale security data platforms.
- Preferred: deep understanding of Detection-as-Code or security data modeling standards such as OCSF and CIM.
- Preferred: experience performing technical evaluations during security-solution selection or replacement.
- Preferred: experience designing security-log collection and monitoring architectures for Kubernetes-based infrastructure.
- Preferred: experience operating security infrastructure in high-traffic environments such as e-commerce or fintech.
- Preferred: experience improving engineering processes such as code reviews, design reviews, and technical standards.
Benefits
- Permanent employment with a 12-week probationary period, which may be waived, shortened, or extended when required by the work.
- Work location: Coupang Seoul Guei Office.
- Recruitment process: document screening, two video technical interviews, and final selection.
- Eligible veterans and persons with disabilities may receive hiring preference under applicable law.
Tech Stack
Categories
About Coupang
Coupang builds and operates a South Korea–focused e-commerce marketplace with an end-to-end logistics network (Rocket Delivery), plus food delivery, video streaming, and fintech under brands such as Coupang, Eats, and Play. Revenue comes from first-party retail, third-party marketplace services, advertising, and memberships (Rocket WOW). Founded in 2010, the company is headquartered in Seattle and is publicly listed on the NYSE (CPNG).
