Role at a Glance
Senior Staff (individual contributor) | Coupang, Seoul, South Korea | On-site | Salary: not disclosed | Experience: 10+ years required | Core skills: AWS, IAM, NIST CSF, ISO 27001, SOC 2, PCI-DSS | Nice-to-have: SQL, Python, CISA/CISSP certifications | Recruitment: four-stage process (application → first interview → virtual onsite → offer)
What This Role Is About
Coupang's Digital Trust GRC team is hiring a technically deep governance practitioner to build the systems that prove security controls actually work — not just that policies exist on paper. Based in Seoul, you will own the company's Control Assurance Framework, shape how global standards like NIST and ISO 27001 apply to a high-velocity e-commerce environment, and act as the technical authority who bridges compliance, security engineering, and executive leadership. This is a senior individual-contributor track with high organizational influence, not a people-management role.
About Coupang
Coupang is South Korea's leading e-commerce platform, handling consumer shopping, food delivery, and related on-demand services at national scale. The company describes itself as a large, publicly listed enterprise that has retained a startup culture — a combination that means engineering teams ship fast while operating under the governance expectations of a global public company. That structural tension is precisely what the Digital Trust GRC team exists to navigate: enabling business velocity without sacrificing security posture.
What You'll Be Doing
- Design and continuously mature the organization's Control Assurance Framework — building the mechanisms that verify security controls remain effective in practice, not just on paper
- Adapt major global security standards (NIST CSF, NIST SP 800-53, ISO 27001, SOC 2, PCI-DSS) to fit Coupang's specific, fast-moving technical environment rather than applying them off the shelf
- Feed real security incidents back into governance strategy — analyzing vulnerabilities and events through a GRC lens, then formulating improvements that reduce recurrence
- Use security telemetry and metrics data to run risk assessments, maintain and prioritize the risk register, and recommend mitigations that measurably shrink the attack surface
- Serve as the communication bridge between the Digital Trust GRC team, Security Engineering, DevOps, and business stakeholders — translating complex risk profiles into decisions leadership can act on
- Raise the technical floor of the GRC team by applying deep expertise in cloud security, IAM, and application security to guide peers and expand the team's analytical capacity
Must-Have Qualifications
- 10 or more years of professional experience in Security GRC, Information Security, or Security Engineering — individual contributor scope with equivalent proven leadership is accepted
- Deep, hands-on expertise in NIST CSF, NIST SP 800-53, ISO 27001, SOC 2, and PCI-DSS, including experience mapping and tailoring these controls to dynamic, real-world environments
- Solid technical grounding in AWS: cloud architecture, Identity and Access Management (IAM), and continuous compliance monitoring or automation
- Proven ability to translate security incidents and technical risk findings into business-level impact statements and concrete remediation strategies
- Exceptional written and verbal communication, with a demonstrated track record of building alignment between technical teams and non-technical leadership
Preferred Qualifications
- Prior experience establishing GRC practices inside large-scale logistics, e-commerce, or similarly fast-moving distributed environments
- Relevant industry certifications such as CISA, CISM, CRISC, CISSP, CCSK, or AWS Certified Security – Specialty
- Hands-on experience building automated security metrics or Continuous Controls Monitoring (CCM) pipelines using SQL or Python
Skills Breakdown: Required vs. Preferred
The mandatory technical foundation is AWS fluency (architecture, IAM, compliance automation) paired with working command of at least NIST CSF, NIST SP 800-53, ISO 27001, SOC 2, and PCI-DSS. Strong cross-functional communication — both written and verbal — is equally load-bearing and treated as a hard requirement, not a soft skill. SQL and Python for CCM automation, along with certifications such as CISM or CISSP, sit on the preferred list only. At Senior Staff level, the bar is independent technical direction-setting and active peer elevation, not just executing assigned governance tasks.
Compensation & Salary
Coupang has not disclosed a salary range for this position, and the job posting contains no compensation details. Candidates should research current market rates for Senior Staff security engineering roles in Seoul independently. As a large, publicly listed company, Coupang may offer structured total compensation, but no specifics have been confirmed for this role. Raise the compensation question early in the interview process to avoid late-stage misalignment.
Location & Work Arrangement
This position is based in Seoul, South Korea. The job posting does not mention a remote or hybrid arrangement, indicating on-site work as the default expectation. No relocation assistance or visa sponsorship is stated — candidates outside South Korea should confirm work authorization requirements directly with Coupang's recruiting team before investing time in the process.