4 hours ago
Seoul, Korea, SouthStaff+
Responsibilities
- Design and maintain Coupang’s AI Security and Risk Management Framework aligned with NIST AI RMF, ISO 42001, MSIT guidelines, and global AI Acts.
- Architect policy-as-code rule sets and security baseline specifications for AI pipeline deployments.
- Define technical control criteria and validation logic for the Control Assurance team to execute, monitor, and audit.
- Identify, assess, and establish mitigations for AI-specific threats including prompt injection, training data leakage, model extraction, shadow AI, and supply-chain vulnerabilities.
- Partner with AI platform teams, infrastructure engineers, security architects, Legal, Privacy, and AI/ML engineers to embed governance requirements into architectures, CI/CD workflows, and runtime environments.
- Own the enterprise AI policy lifecycle, including model adoption frameworks, data privacy guardrails, and cross-border data transfer requirements.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Software Engineering, or a related technical or policy field.
- 10+ years of experience in Information Security, Technical GRC, Security Architecture, or AI/Cloud Governance.
- Deep understanding of AI/ML security risks, AWS cloud security architecture, and privacy and data protection principles.
- Ability to evaluate system architecture diagrams, interpret API and data-flow models, and translate policy requirements into technical specifications.
- Experience architecting governance frameworks such as NIST AI RMF, ISO 42001, NIST CSF, and PIPA in technology-driven environments.
- Excellent written and verbal English communication skills.
- Preferred experience defining policy-as-code specifications, continuous control monitoring logic, or automated cloud compliance guardrails.
- Preferred hands-on familiarity with AI/ML pipelines, LLM integration architectures, data tokenization, or cloud control planes.
- Preferred experience partnering with operational audit or assurance teams to operationalize GRC metrics and controls.
- Relevant certifications such as CISM, CRISC, CISSP, or specialized AI security/governance credentials are preferred.
Benefits
- The role is based in Seoul.
- The posting describes a recruitment process of application review, phone interview, and onsite or virtual onsite interview before an offer.
About Coupang
Coupang builds and operates a South Korea–focused e-commerce marketplace with an end-to-end logistics network (Rocket Delivery), plus food delivery, video streaming, and fintech under brands such as Coupang, Eats, and Play. Revenue comes from first-party retail, third-party marketplace services, advertising, and memberships (Rocket WOW). Founded in 2010, the company is headquartered in Seattle and is publicly listed on the NYSE (CPNG).
