概要
회사 소개
쿠팡은 고객 감동 실현을 위해 존재합니다. 고객들이 "쿠팡 없이 그동안 어떻게 살았을까?" 라고 말할 때, 비로소 우리의 미션을 실현하고 있음을 알 수 있습니다. 고객들의 쇼핑과 식사, 생활 전반을 편하게 만들겠다는 유일한 집념으로 쿠팡은 수억 달러 규모의 이커머스 산업 전반의 혁신을 이끌고 있습니다. 쿠팡은 가장 빠르게 성장하는 이커머스 기업 중 하나로, 국내 커머스 업계에서의 독보적인 입지와, 고객 신뢰를 구축했습니다.
쿠팡은 스타트업 문화를 기반으로 한 글로벌 대형 상장사라고 자부합니다. 이것이 창립 당시의 기민함을 지하며, 신규 서비스를 끊임없이 출시하며 비즈니스를 확장해 나가는 우리의 성장 동력입니다. 쿠팡의 모든 임직원에게는 기업가 정신을 갖추고 새로운 혁신과 이니셔티브를 추진할 수 있는 기회가 주어집니다. 주저 없이 일에 뛰어들어 성과를 이루고자 하는 과감성이, 바로 쿠팡이 일하는 방식의 본질입니다. 쿠팡에서는 여러분 자신, 동료, 팀 그리고 회사 전체가 매일 성장하는 모습을 목격할 것입니다.
쿠팡의 모든 직원은 커머스의 미래를 만들겠다는 쿠팡의 미션에 진심입니다. 우리는 고객의 문제를 해결해 나가고, 전통적인 관념과 통념에 맞서며 실현 가능한 한계를 뛰어넘고 있습니다. 고가용성 (always-on) 과 최첨단의 앞선 기술 (high-tech), 초연결사회 (hyper-connected world) 에서의 놀라운 업무 경험을 원하신다면, 지금 바로 쿠팡에 합류하세요.
직무 소개
Identity Governance and Administration(IGA) 체계를 고도화하고 Non-Human Identity(NHI) 보안 전략을 발전시킬 수 있는 뛰어난 분석력과 실무 역량을 갖춘 IAM Governance & NHI Engineer를 찾고 있습니다.
이 직무는 전통적인 휴먼 액세스 거버넌스와 머신 아이덴터티 관리를 모두 담당하는 하이브리드 역할입니다. 감사(Audit) 및 컴플라이언스 대응 자동화 분야의 Subject Matter Expert(SME)로서 활동하는 동시에, Entro, Oasis, Zuma와 같은 최신 NHI 솔루션을 직접 설계·구축하여 자동화 파이프라인, 서비스 계정 및 시크릿(Secrets) 보안을 강화하게 됩니다.
업무 내용
Identity Governance & Compliance
- Human Identity Governance 체계의 설계, 운영 및 지속적인 개선을 위한 핵심 SME 역할 수행
- 내부 및 외부 감사팀, Risk 및 Compliance 조직과 협력하여 감사 증적(Evidence) 제공, 기술 문의 대응 및 감사 지적사항 개선 수행
- SOX, SOC2, ISO 27001 등 다양한 컴플라이언스 프레임워크를 Human/Machine Identity에 적용 가능한 IAM 기술 통제로 변환 및 구현
- 반복적이고 수작업 중심의 업무를 자동화할 수 있는 플랫폼을 구축하여 컴플라이언스 및 감사 요구사항 충족
Non-Human Identity (NHI) 전략 및 구축
- 멀티 클라우드 및 온프레미스 환경 전반에서 Non-Human Identity(서비스 계정, API Key, OAuth Token, Secret, 인증서 등)를 관리·보호하기 위한 전사 전략 수립 및 실행
- 최신 NHI 및 Secrets Management 솔루션(예: Entro, Oasis, Zuma) 평가 및 도입
- NHI에 대해 Human Account와 동일한 수준의 거버넌스, 소유권 관리(Ownership), 정기 검토 프로세스가 적용될 수 있도록 라이프사이클 관리 체계 수립
- 소스코드 및 CI/CD 파이프라인 내 하드코딩되었거나 관리되지 않는 시크릿 탐지, Vault 이관 및 지속 관리
Automation & Continuous Improvement
수작업 기반 프로세스는 보안 리스크와 운영 피로도를 증가시킵니다. 본 포지션의 핵심 목표는 IAM 거버넌스 및 NHI 운영을 적극적으로 자동화하여 보안 수준, 운영 속도 및 개발자 경험(Developer Experience)을 향상시키는 것입니다.
- NHI Discovery & Rotation: Orphaned NHI를 지속적으로 탐지하고, 비정상적인 머신 간 통신(Machine-to-Machine Behavior)을 모니터링하며, 운영 환경에 영향을 주지 않는 자동 Secret Rotation 워크플로우 개발
- Automated Campaign Generation: Saviynt를 활용하여 부서 이동, 직급 변경 등 고위험 이벤트 발생 시 자동으로 타겟형 Access Certification/Micro-Certification 캠페인이 실행되도록 스크립트 및 정책 구성
- Zero-Touch Provisioning / Deprovisioning: 퇴사 시 접근 권한을 즉시 회수하는 자동화 프로세스 구축, 신규 입사자 또는 신규 마이크로서비스 생성 시 기본 권한(Baseline Access)을 자동 부여하는 워크플로우 개발
- API Integration: REST API, Python, Go, PowerShell 등을 활용하여 개별적으로 운영되는 애플리케이션을 중앙 IAM Governance 및 NHI 플랫폼과 연계하고, 기본 커넥터가 존재하지 않는 환경에서도 접근 권한 가시성 및 관리 자동화 구현
자격 요건
- 8년 이상의 IAM 관리 및 IGA 플랫폼, secret / machine identity 관리 경험
- NHI 및 개발 전문성(NHI & Development Expertise): 현대적인 NHI 라이프사이클 관리 도구(Entro, Oasis, Zuma) 및 시크릿 관리(Secrets Management)에 대한 실무 엔지니어링 및 개발 경험. 코딩 및 스크립팅 역량 필수 (Python, PowerShell, Go)
-
Saviynt: Saviynt(EIC/Cloud) 관리 및 운영 경험을 보유하신 분
-
감사 대응 역량: 감사인(Auditor) 대응 경험이 풍부하며, 기술적 IAM 개념을 비기술 조직인 리스크(Risk) 팀에 효과적으로 설명하고 커뮤니케이션할 수 있는 역량
- 심화 IAM 지식: IAM 핵심 개념인 SSO, MFA, SAML, OIDC, Active Directory, PAM, RBAC/ABAC에 대한 포괄적인 이해
전형 절차 및 안내 사항
- 전형절차
- 서류전형 - 전화면접 - 대면(화상)면접 – 최종 합격
- 전형절차는 직무별로 다르게 운영될 수 있으며, 일정 및 상황에 따라 변동될 수 있습니다.
- 전형 일정 및 결과는 지원서에 등록하신 이메일로 개별 안내 드립니다.
- 참고사항
- 본 공고는 모집 완료 시 조기 마감될 수 있습니다.
- 지원서 내용 중 허위사실이 있는 경우에는 합격이 취소될 수 있습니다.
- 취업 보호 대상자(보훈대상자, 장애인 등)는 관련 법률에 따라 채용우대를 받을 수 있습니다.
- 직급과 담당 업무 범위는 후보자의 전반적인 경력과 경험 등 제반사정을 고려하여 변경될 수 있습니다. 이러한 변경이 필요할 경우, 최종 합격 통지 전 적절한 시기에 후보자와 커뮤니케이션 될 예정입니다.
- 채용 및 업무 수행과 관련하여 요구되는 법령상 자격이 갖추어지지 않은 경우 채용이 제한될 수 있습니다.
개인정보 처리방침
- 쿠팡 그룹은 입사지원자 개인정보 처리방침(아래 링크)에 따라 귀하의 개인정보를 수집하여 처리합니다. https://www.coupang.jobs/kr/privacy-policy/
서류 반환 정책
- 본 고지는 『채용절차의공정화에관한법률』 제11조제6항에 따른 것 입니다.
- 당사 채용에 응시한 구직자 중 최종 합격이 되지 못한 구직자는 『채용절차의 공정화에 관한 법률』에 따라 제출한 채용서류의 반환을 청구할 수 있음을 알려 드립니다. 다만, 홈페이지 또는 전자우편으로 제출된 경우나 구직자가 당사의 요구 없이 자발적으로 제출한 경우에는 그러하지 아니하며, 천재지변이나 그 밖에 당사에게 책임 없는 사유로 채용서류가 멸실된 경우에는 반환한 것으로 봅니다.
- 위2항 본문에 따라 채용 서류 반환 청구를 하는 구직자는 채용 서류 반환 청구서 [채용절차의 공정화에 관한 법률 시행규칙 별지 제 3 호 서식]를 작성하여 이메일 ([email protected]) 로 제출하면, 제출이 확인된 날로부터 14 일 이내에 지정한 주소지로 등기우편을 통하여 발송해 드립니다. 이 경우 등기우편요금은 수신자 부담으로 하게 되오니 유념하시기 바랍니다.
- 당사는 위2항 본문에 따른 구직자의 반환 청구에 대비하여 채용 여부가 확정된 날로부터 180 일간 구직자가 제출한 채용서류 원본을 보관하게 되며, 그때까지 채용서류의 반환을 청구하지 아니할 경우에는 『개인정보 보호법』에 따라 지체 없이 채용서류 일체를 파기할 예정입니다.
- 단, 위 1항 내지 4항의 내용은 대한민국의 노동 관계 법령이 적용되는 경우에만 적용됩니다. 그 이외의 경우에는 적용되지 않습니다.
Company Introduction
We exist to wow our customers. We know we’re doing the right thing when we hear our customers say, “How did I ever live without Coupang?” Born out of an obsession to make shopping, eating, and living easier than ever, we are collectively disrupting the multi-billion-dollar commerce industry from the ground up and establishing an unparalleled reputation for being leading and reliable force in South Korean commerce.
We are proud to have the best of both worlds — a startup culture with the resources of a large global public company. This fuels us to continue our growth and launch new services at the speed we have been since our inception. We are all entrepreneurs surrounded by opportunities to drive new initiatives and innovations. At our core, we are bold and ambitious people that like to get our hands dirty and make a hands-on impact. At Coupang, you will see yourself, your colleagues, your team, and the company grow every day.
Our mission to build the future of commerce is real. We push the boundaries of what’s possible to solve problems and break traditional tradeoffs. Join Coupang now to create an epic experience in this always-on, high-tech, and hyper-connected world.
Role Overview
We are seeking a highly analytical and technically hands-on IAM Governance & NHI Engineer to mature our Identity Governance and Administration (IGA) framework and Non-Human Identity (NHI) security strategy. In this hybrid role, you will straddle traditional human access governance and machine identity management. You will serve as the SME to automate audit compliance, while actively developing and deploying advanced NHI solutions (using tools like Entro, Oasis, or Zuma) to secure our automated pipelines, service accounts, and secrets.
Key Responsibilities
Identity Governance & Compliance
- Serve as the primary SME for the design, execution, and continuous improvement of human Identity Governance initiatives.
- Partner directly with internal and external audit teams, Risk, and Compliance to provide evidence, answer technical inquiries, and remediate audit findings.
- Translate complex compliance frameworks (e.g., SOX, SOC2, ISO 27001) into actionable IAM technical controls for both human and machine identities.
- Introduce and build automation platforms to mitigate automated tasks, while ensuring compliance/audit requirements are met.
Non-Human Identity (NHI) Strategy & Development
- Define and execute the enterprise strategy for managing and securing Non-Human Identities (service accounts, API keys, OAuth tokens, secrets, and certificates) across multi-cloud and on-premise environments.
- Evaluate and implement modern NHI and secrets management platforms (e.g., Entro, Oasis, Zuma).
- Establish mechanisms to enforce strict lifecycle governance for NHIs, ensuring they are subject to the same rigorous oversight, ownership attribution, and review processes as human accounts.
- Identify, vault, and manage unmanaged or hardcoded secrets embedded in source code and CI/CD pipelines.
Automation & Continuous Improvement
Manual processes introduce risk and fatigue. A core objective of this role is to ruthlessly automate IAM governance and NHI operations to improve security, speed, and developer experience.
- NHI Discovery & Rotation: Develop automated workflows to continuously discover orphaned NHIs, alert on anomalous machine-to-machine behavior, and enforce automated secret rotation without disrupting production workloads.
- Automated Campaign Generation: Script and configure Saviynt to automatically trigger targeted micro-certifications based on high-risk events (e.g., department transfers, title changes).
- Zero-Touch Provisioning/Deprovisioning: Build workflows that instantly revoke access upon termination and automatically provision baseline access for new hires or newly spun-up microservices.
- API Integrations: Utilize REST APIs, Python, Go, or PowerShell to connect siloed applications to our centralized governance and NHI platforms, automating access visibility where native connectors do not exist.
Qualifications
- Experience: 8+ years of dedicated experience in Identity & Access Management, with a balanced focus on IGA platforms and secrets/machine identity management.
- NHI & Development Expertise: Hands-on engineering and development experience with modern NHI lifecycle tools (Entro, Oasis, Zuma) and secrets management. Strong coding/scripting skills (Python, PowerShell, Go) are required.
- Saviynt: Administrative experience with Saviynt (EIC/Cloud).
- Audit Fluency: Strong track record of facing auditors and communicating technical IAM concepts to non-technical risk teams.
- Deep IAM Knowledge: Comprehensive understanding of core IAM concepts (SSO, MFA, SAML, OIDC, Active Directory, PAM, RBAC/ABAC).
Recruitment Process and Others
Recruitment Process
- Application Review - 1st Interview - 2nd Interview - Offer
- The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances.
- Interview schedules and the results will be informed to the applicant via the e-mail address submitted at the application stage.
Details to Consider
- This job posting may be closed prior to the stated end date for application if all openings are filled.
- Coupang has the right to rescind an offer of employment if a candidate is found to have submitted false information as part of the application process.
- Those eligible for employment protection (recipients of veteran’s benefits, the disabled, etc.) may receive preferential treatment for employment in accordance with applicable laws.
- Job titles and responsibilities may be subject to change depending on the candidate’s overall experience, etc. This will be communicated to the candidate at the appropriate time before the offer.
- Hiring may be restricted in case the legal qualifications required for hiring and work performance is not met.
- This is a full-time regular position and includes 12 weeks of probation period; provided, however, the probationary period may be either skipped, shortened or extended if necessary for business purposes
Privacy Notice
- Your personal information will be collected and managed by Coupang as stated in the Application Privacy Notice located below.
- https://privacy.coupang.com/en/land/jobs/
Document Return Policy
- This notification is given pursuant to Article 11 (6) of the Fair Hiring Procedure Act.
- A job applicant, who has applied but not been finally selected for a position at Coupang (the “Company”), may request the Company to return his/her hiring documents submitted pursuant to the Fair Hiring Procedure Act. However, this will not apply where the hiring documents were submitted via the website of the Company or e-mail, or where the job applicant submitted those documents voluntarily without a request from the Company. In addition, if the hiring documents were destroyed due to a natural disaster or any other reasons not attributable to the Company, such documents will be deemed to have been returned to the job applicant.
- A job applicant who wishes to request the return of his/her hiring documents pursuant to the main sentence of paragraph 2 above should fill out a “Request for Return of Hiring Documents” [Annex Form No. 3 in the Enforcement Rule of the Fair Hiring Procedure Act] and submit It by email ([email protected]). In such case, within fourteen (14) days from the date of identifying the receipt of the request, the Company will send the hiring documents to the job applicant’s designated address via registered mail. Please be informed that the job applicant is required to pay the postage on the registered mail.
- In preparation for a job applicant’s request for the return of hiring documents pursuant to the main sentence of paragraph 2 above, the Company shall retain the original hiring documents submitted by the job applicant for 180 days from the completion of the recruiting process. If no request is made until the end of this period, all his/her hiring documents will be destroyed immediately in accordance with the Personal Information Protection Act.
- The above paragraphs 1 - 4 shall only apply when the labor-related laws of Korea govern the application. They are otherwise not applicable.