說明
Staff AI Security Governance Engineer (AI GRC)
Company Introduction
We exist to wow our customers. We know we’re doing the right thing when we hear our customers say, “How did I ever live without Coupang?” Born out of an obsession to make shopping, eating, and living easier than ever, we are collectively disrupting the multi-billion-dollar commerce industry from the ground up and establishing an unparalleled reputation for being leading and reliable force in South Korean commerce.
We are proud to have the best of both worlds — a startup culture with the resources of a large global public company. This fuels us to continue our growth and launch new services at the speed we have been since our inception. We are all entrepreneurs surrounded by opportunities to drive new initiatives and innovations. At our core, we are bold and ambitious people that like to get our hands dirty and make a hands-on impact. At Coupang, you will see yourself, your colleagues, your team, and the company grow every day.
Our mission to build the future of commerce is real. We push the boundaries of what’s possible to solve problems and break traditional tradeoffs. Join Coupang now to create an epic experience in this always-on, high-tech, and hyper-connected world.
Role Overview
Coupang is seeking a Staff AI Security Governance Engineer to join our AI GRC (AI Governance, Risk Management, & Compliance) team in Seoul. This role is designed for a technical governance strategist who bridges the gap between complex AI regulatory requirements and technical security architecture.
In this role, you will define and architect Coupang’s enterprise AI risk framework, translate regulatory mandates into policy-as-code specifications, and establish the technical guardrails for AI development. You will partner with AI/ML engineers, security architects, Legal, and Privacy teams to set standards, while collaborating with our dedicated Control Assurance team to ensure seamless execution and continuous monitoring.
What You Will Do
- Framework Architecture & Policy-as-Code Strategy: Design and maintain Coupang’s AI Security & Risk Management Framework (mapped to NIST AI RMF, ISO 42001, MSIT guidelines, and global AI Acts). Architect policy-as-code rule sets and security baseline specifications for deployment across AI pipelines.
- Assurance Partnering: Define the technical control criteria and validation logic that the Control Assurance team will execute, monitor, and audit.
- AI Risk Evaluation & Safeguards: Identify, assess, and set mitigation standards for AI-specific threat vectors (e.g., prompt injection, training data leakage, model extraction, shadow AI, and supply chain vulnerabilities) across internal and third-party AI SaaS/LLM deployments.
- Cross-Functional Engineering Alignment: Partner closely with AI platform teams, infrastructure engineers, and security architects to embed governance and security requirements directly into AI architectures, CI/CD workflows, and runtime environments.
- Enterprise AI Policy Ownership: Own the enterprise AI policy lifecycle, establishing clear decision frameworks for AI model adoption, data privacy guardrails, and cross-border data transfer requirements.
Basic Qualifications
- Bachelor’s degree in Computer Science, Information Security, Software Engineering, or a related technical/policy field.
- 10 + years of experience in Information Security, Technical GRC, Security Architecture, or AI/Cloud Governance.
- Deep understanding of AI/ML security risks, cloud security architecture (AWS), and privacy/data protection principles.
- Strong technical literacy to evaluate system architecture diagrams, interpret API/data flow models, and translate policy requirements into technical specifications for engineering and assurance teams.
- Proven track record of architecting governance frameworks (NIST AI RMF, ISO 42001, NIST CSF, PIPA) in tech-driven environments.
- Excellent written and verbal communication skills in English.
Preferred Qualifications
- Experience defining policy-as-code specifications, continuous control monitoring logic, or automated compliance guardrails in cloud environments.
- Hands-on familiarity with AI/ML pipelines, LLM integration architectures, data tokenization techniques, or cloud control planes.
- Experience partnering with operational audit/assurance teams to operationalize GRC metrics and controls.
- Relevant industry certifications (e.g., CISM, CRISC, CISSP, or specialized AI security/governance credentials).
Recruitment Process
- Application Review - Phone Interview - Onsite (or Virtual Onsite) Interview – Offer
- The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances.
- Interview schedules and the results will be informed to the applicant via the e-mail address submitted at the application stage.
Details to Consider
- This job posting may be closed prior to the stated end date for application if all openings are filled.
- Coupang has the right to rescind an offer of employment if a candidate is found to have submitted false information as part of the application process.
- Those eligible for employment protection (recipients of veteran’s benefits, the disabled, etc.) may receive preferential treatment for employment in accordance with applicable laws.
- Job titles and responsibilities may be subject to change depending on the candidate’s overall experience, etc. This will be communicated to the candidate at the appropriate time before the offer.
- Hiring may be restricted in case the legal qualifications required for hiring and work performance is not met.
- (Recruiter Note: add in the case of full-time regulars) This is a full-time regular position and includes 12 weeks of probation period; provided, however, the probationary period may be either skipped, shortened or extended if necessary for business purposes.
- (Recruiter Note: add if probation period is applicable, for example in the case of contract position of 3 months or longer) This is a contract position and includes 12 weeks of probation period; provided, however, the probationary period may be either skipped, shortened or extended if necessary for business purposes.
Privacy Notice
- Your personal information will be collected and managed by Coupang as stated in the Application Privacy Notice located below.
https://www.coupang.jobs/en/privacy-policy
Document Return Policy (This notice MUST be included in a job posting in Korea only to comply with the Fair Hiring Procedure Act.)
- This notification is given pursuant to Article 11 (6) of the Fair Hiring Procedure Act.
- A job applicant, who has applied but not been finally selected for a position at Coupang (the “Company”), may request the Company to return his/her hiring documents submitted pursuant to the Fair Hiring Procedure Act. However, this will not apply where the hiring documents were submitted via the website of the Company or e-mail, or where the job applicant submitted those documents voluntarily without a request from the Company. In addition, if the hiring documents were destroyed due to a natural disaster or any other reasons not attributable to the Company, such documents will be deemed to have been returned to the job applicant.
- A job applicant who wishes to request the return of his/her hiring documents pursuant to the main sentence of paragraph 2 above should fill out a “Request for Return of Hiring Documents” [Annex Form No. 3 in the Enforcement Rule of the Fair Hiring Procedure Act] and submit It by email ([email protected]). In such case, within fourteen (14) days from the date of identifying the receipt of the request, the Company will send the hiring documents to the job applicant’s designated address via registered mail. Please be informed that the job applicant is required to pay the postage on the registered mail.
- In preparation for a job applicant’s request for the return of hiring documents pursuant to the main sentence of paragraph 2 above, the Company shall retain the original hiring documents submitted by the job applicant for 180 days from the completion of the recruiting process. If no request is made until the end of this period, all his/her hiring documents will be destroyed immediately in accordance with the Personal Information Protection Act.
- The above paragraphs 1 - 4 shall only apply when the labor-related laws of Korea govern the application. They are otherwise not applicable.
人人均等的機會
Coupang提供均等的機會給所有員工。若沒有全球多元團隊的寶貴意見,我們不可能達成史無前例的成功。