Coupang

Staff Security Engineer (AI GRC)

Coupang
Apply
4 hours ago
Seoul, Korea, SouthStaff+

Responsibilities

  • Design and maintain Coupang’s AI Security and Risk Management Framework aligned with NIST AI RMF, ISO 42001, MSIT guidelines, and global AI Acts.
  • Architect policy-as-code rule sets and security baseline specifications for AI pipeline deployments.
  • Define technical control criteria and validation logic for the Control Assurance team to execute, monitor, and audit.
  • Identify, assess, and establish mitigations for AI-specific threats including prompt injection, training data leakage, model extraction, shadow AI, and supply-chain vulnerabilities.
  • Partner with AI platform teams, infrastructure engineers, security architects, Legal, Privacy, and AI/ML engineers to embed governance requirements into architectures, CI/CD workflows, and runtime environments.
  • Own the enterprise AI policy lifecycle, including model adoption frameworks, data privacy guardrails, and cross-border data transfer requirements.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Software Engineering, or a related technical or policy field.
  • 10+ years of experience in Information Security, Technical GRC, Security Architecture, or AI/Cloud Governance.
  • Deep understanding of AI/ML security risks, AWS cloud security architecture, and privacy and data protection principles.
  • Ability to evaluate system architecture diagrams, interpret API and data-flow models, and translate policy requirements into technical specifications.
  • Experience architecting governance frameworks such as NIST AI RMF, ISO 42001, NIST CSF, and PIPA in technology-driven environments.
  • Excellent written and verbal English communication skills.
  • Preferred experience defining policy-as-code specifications, continuous control monitoring logic, or automated cloud compliance guardrails.
  • Preferred hands-on familiarity with AI/ML pipelines, LLM integration architectures, data tokenization, or cloud control planes.
  • Preferred experience partnering with operational audit or assurance teams to operationalize GRC metrics and controls.
  • Relevant certifications such as CISM, CRISC, CISSP, or specialized AI security/governance credentials are preferred.

Benefits

  • The role is based in Seoul.
  • The posting describes a recruitment process of application review, phone interview, and onsite or virtual onsite interview before an offer.

Tech Stack

Categories

Coupang

About Coupang

5,001-10,000 employees

Coupang builds and operates a South Korea–focused e-commerce marketplace with an end-to-end logistics network (Rocket Delivery), plus food delivery, video streaming, and fintech under brands such as Coupang, Eats, and Play. Revenue comes from first-party retail, third-party marketplace services, advertising, and memberships (Rocket WOW). Founded in 2010, the company is headquartered in Seattle and is publicly listed on the NYSE (CPNG).

Contact me