12 hours ago
Seoul, Korea, SouthStaff+
Responsibilities
- Lead proactive threat hunting across enterprise systems using hypotheses based on attacker TTPs, threat intelligence, and defensive data visibility.
- Apply advanced analytics, behavioral baselines, and statistical methods to large, multi-domain log datasets to identify anomalies and indicators of compromise.
- Use MITRE ATT&CK, the Diamond Model, and the NIST Cybersecurity Framework in threat-hunting activities.
- Investigate telemetry from SIEM, EDR, NDR, cloud, IAM, and network platforms, emphasizing cross-domain correlation and advanced behavioral analysis.
- Collaborate with SOC, Incident Response, Insider Threat, Detection Engineering, and Threat Intelligence teams to operationalize hunting results.
- Develop reusable threat-hunting playbooks and automation with Python, PowerShell, or comparable scripting technologies.
- Identify security-control gaps and recommend improvements to detection and response capabilities.
- Provide technical mentoring and contribute to continuous improvement across the Security Group.
Requirements
- Bachelor’s degree or higher in cybersecurity, information security, computer science, or a related field.
- At least 8 years of experience in security operations, threat hunting, or incident response.
- Deep understanding of attacker TTPs, attacker behavior, and the MITRE ATT&CK framework, with experience applying them to enterprise threat hunting.
- Extensive hands-on experience with SIEM, EDR, cloud security, and log-analysis platforms in large enterprise, multi-tenant, or multi-domain environments.
- Strong analytical, investigative, and problem-solving abilities based on experience with complex, multi-stage security investigations.
- Experience in e-commerce or large enterprise environments is preferred.
- Technical understanding of attacker TTPs, the attack lifecycle, lateral movement, and adversary simulation is preferred.
- Experience with Splunk, ELK, UEBA, QRadar, SPL, KQL, SQL, or LogScale is preferred.
- Experience conducting hypothesis-driven threat hunting and investigations across complex, multi-domain telemetry is preferred.
- Experience automating threat hunting and developing playbooks with Python, PowerShell, or comparable scripting and data-engineering skills is preferred.
- Understanding of malware analysis, network forensics, and EDR/XDR platform internals is preferred.
- Experience identifying security-control gaps and communicating them effectively to stakeholders and leadership is preferred.
- Relevant certifications such as GCTI, GCIH, GCIA, GCED, GCFA, GMLE, CISSP, OffSec SOC-200, OffSec TH-200, or Microsoft SC-200 are preferred.
- Fluency in Korean and English is preferred.
About Coupang
Coupang builds and operates a South Korea–focused e-commerce marketplace with an end-to-end logistics network (Rocket Delivery), plus food delivery, video streaming, and fintech under brands such as Coupang, Eats, and Play. Revenue comes from first-party retail, third-party marketplace services, advertising, and memberships (Rocket WOW). Founded in 2010, the company is headquartered in Seattle and is publicly listed on the NYSE (CPNG).
