Staff Security Engineer
CoupangAbout the role
Location: Hybrid from Seattle, WA or Mountain View, CA.
Coupang is reimagining the shopping experience with the goal of wowing each customer from the instant they open the Coupang app to the moment an order is delivered to their door. Powered by an outstanding end-to-end e-commerce and logistics network and a fanatical culture of customer centricity, Coupang has broken tradeoffs around speed, selection and price. Today, we provide exceedingly fast shipping speeds on millions of items including fresh groceries, delivered within hours nationwide, 365 days a year. We are doing this for millions of consumers in Korea. Korea is home to one of the largest and fastest growing e-commerce opportunities anywhere in the world.
Coupang has been added into the 2023 fortune 500 list, a ranking U.S-based companies by revenue. We have been named as one of the ‘50 Smartest Companies in the World’ by MIT Technology Review, and as one of Forbes magazine’s ‘30 Global Game Changers.’ In 2020, we placed second on CNBC’s ‘Disruptor 50’ list.
Job Overview
Coupang's Access Management Team operates a centralized platform for authentication and authorization. The team is responsible for Single Sign-On (SSO), dynamic authorization based on policies, and providing operational support for user access. The Access Management team ensures that the right users have access to enterprise assets in the appropriate context. We are currently seeking a Security Architect who has prior experience and is creative in problem-solving. The ideal candidate should be enthusiastic about working with new technologies and must be ready to assume multiple roles to accomplish tasks in a fast-paced, innovative, and collaborative startup environment.
What You Will Do
- Lead architecture and design for enterprise-wide access management solutions such as SSO, MFA, dynamic authorization, and privileged access management. Produce artifacts for custom solutions implemented.
- Share responsibility for managing and maintaining highly resilient authentication and authorization platform ensuring 99.999% availability for business-critical applications
- As a Technical Lead, you should be able to solve complex problems, use sophisticated analytical thinking to exercise judgment and identify innovative solutions.
- Be responsible for developing and deploying infrastructure /processes that will ensure 5 9s availability for business critical Authn &Authz
- As the SME for access management tools, provide technical training and educate IAM team peers.
- Provide L3 support for escalations on user access issues and platform/tool defects.
- Guide enterprise apps to adopt SSO technologies, enable fine-grained access control using dynamic claims-based authorization.
- Collaborate with others in the IAM and Security teams to establish standard operations, new capabilities, as well as provide input on best practices for enabling access and authorization for critical apps and assets.
- Manage and maintain access management infrastructure.
- Author technical documentation, such as system design and engineering artifacts for custom solutions
- Support the day-to-day operations of the Access Management team.
- Develop and maintain documentation of Standard operational processes.
- Stay up to date with the latest security best practices and to remain informed about new threats and CVEs.
- Participate in 24x7 after business hours on-call rotation for L2/L3 support for critical services.
- Develop scripts to automate operation tasks to improve efficiency.
Basic Qualifications:
- Have a DevOps mindset, understanding the collaboration and integration required to achieve objectives including Agile and Continuous Delivery methodologies.
- Solid hands-on experience with and deep knowledge of SSO tools such as Okta, Azure AD, Ping or a comparable product
- Hands on experience with and deep knowledge of PlainID or similar PBAC tool
- Good technical knowledge of authentication/authorization, identity management standards and protocols such as LDAP, SAML, OpenID Connect, OAuth2
- Have working knowledge of the MFA/FIDO security products providing advanced biometrics authentication solutions.
- Experience with various LDAP products including AD, Radiant Logic FID, or a comparable product
- Experience working with RBAC, just-in-time access, and related authorization strategies.
- Knowledge of web services (REST/SOAP)
- Deep understanding of Windows, Unix, Database & Directory services
- Experience with AWS DevOps and hands on knowledge of EKS, Automation/Orchestration Tools (Ansible, Jenkins, Terraform, etc.
- Experience with Cloud technologies (Google Cloud Platform, Azure or AWS)
- Prior coding an
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s