Назад
Company hidden
12 дней назад

Staff Security Engineer (AI GRC)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
SK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Engineer (AI GRC) (AI Security Governance, Cloud Security): Designing Coupang’s enterprise AI risk framework, policy-as-code controls, and security baselines for AI pipelines with an accent on regulatory alignment, AI/ML threat assessment, and technical governance. Focus on translating AI regulations into engineering specifications, embedding guardrails into CI/CD and runtime environments, and establishing continuous control validation.

Location: Seoul, South Korea; onsite or virtual onsite interview

Company

hirify.global is a large global public commerce company building technology-driven shopping, eating, and living services in South Korea.

What you will do

  • Design and maintain the enterprise AI Security and Risk Management Framework mapped to NIST AI RMF, ISO 42001, MSIT guidelines, and global AI Acts.
  • Architect policy-as-code rules and security baseline specifications for deployment across AI pipelines.
  • Define technical control criteria and validation logic for continuous monitoring, execution, and audit.
  • Assess AI-specific threats including prompt injection, training data leakage, model extraction, shadow AI, and supply chain vulnerabilities.
  • Partner with AI platform, infrastructure, security architecture, Legal, Privacy, and Control Assurance teams to embed governance into architectures, CI/CD workflows, and runtime environments.
  • Own the AI policy lifecycle, including model adoption decisions, data privacy safeguards, and cross-border data transfer requirements.

Requirements

  • 10+ years of experience in information security, technical GRC, security architecture, or AI/cloud governance.
  • Bachelor’s degree in computer science, information security, software engineering, or a related technical or policy field.
  • Deep understanding of AI/ML security risks, AWS cloud security architecture, and privacy and data protection principles.
  • Ability to evaluate system architectures and API/data flows and translate policy requirements into technical specifications.
  • Experience architecting governance frameworks such as NIST AI RMF, ISO 42001, NIST CSF, and PIPA.
  • Excellent written and verbal English communication skills required.

Nice to have

  • Experience defining policy-as-code, continuous control monitoring, or automated cloud compliance guardrails.
  • Hands-on familiarity with AI/ML pipelines, LLM integrations, data tokenization, or cloud control planes.
  • Experience with operational audit and assurance teams, GRC metrics, and controls.
  • CISM, CRISC, CISSP, or specialized AI security/governance certifications.

Culture & Benefits

  • Startup culture combined with the resources of a large global public company.
  • Opportunity to drive new initiatives and innovations in a high-tech commerce environment.
  • Full-time regular employment with a 12-week probation period; the period may be skipped, shortened, or extended based on business needs.
  • Employment protections may apply to eligible veterans and people with disabilities under applicable laws.

Hiring process

  • Application review, phone interview, onsite or virtual onsite interview, and offer.
  • Interview schedules and results are communicated by email.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →