About the Role
The Security team protects product, infrastructure, and customer data, embedding B2B customer security requirements into the platform. We connect policy/governance with infrastructure/product security to ensure all product teams have secure by default settings. Currently, we manage policy, certification, log check automation, and incident response, and are seeking engineers to build the next phase (EDR, SIEM, MDM, Security Agent, etc.) from the ground up.
Responsibilities
- Cloud Security (AWS): Design and audit IAM, VPC, Security Groups; introduce and operate native security services like GuardDuty, Security Hub, Config, WAF; code security policies with IaC tools like Terraform.
- Security Infrastructure Construction: Introduce and establish operating systems for core security solutions not yet present, such as MDM, EDR, and SIEM.
- Security Automation (Security Engineering): Automate security checks and evidence collection; integrate security checks (SAST, DAST, SCA) into CI/CD pipelines; expand existing log check automation into a continuous monitoring system.
- Incident Response & Detection: Monitor logs and anomalies, write detection rules, and lead detection, initial response, root cause analysis, and recurrence prevention during incidents.
- Vulnerability Management & Product Security: Track follow-up actions for regular vulnerability assessments and penetration test results; collaborate with development teams on threat modeling, security design reviews, and secure coding; develop in-product security features.
- Compliance Operations: Provide technical support for maintaining and renewing domestic and international certifications like ISMS-P and ISO 27001/27017/27018/27701; respond to security audits from customers and partners.
Requirements
- Minimum 3 years of practical experience in information security (or infrastructure/security engineering) (lv4 or higher, mid-level to senior).
- Experience operating and building security in a cloud environment (AWS, etc.) (e.g., IAM, VPC, Security Groups).
- Experience automating security tasks using code — Channel's Security Engineers are builders rather than just users.
- Fundamental knowledge of network and endpoint security, and understanding of web/application vulnerabilities (OWASP Top 10).
- Understanding of or practical experience with security certification frameworks such as ISMS-P and ISO 27001.
- Communication skills to explain and persuade stakeholders (developers, related departments, management) about technical risks at their level.
Skills
- AWS
- IAM
- VPC
- Security Groups
- GuardDuty
- Security Hub
- Config
- WAF
- Terraform
- IaC
- MDM
- EDR
- SIEM
- SAST
- DAST
- SCA
- CI/CD
- OWASP Top 10
- ISMS-P
- ISO 27001
- ISO 27017
- ISO 27018
- ISO 27701
- CBPR
Location
- South Korea
Work Type
- Full-time
Experience Level
- Mid-level
- Senior
About the Company
- Security team protects product, infrastructure, and customer data.
- Embeds B2B customer security requirements into the platform.
- Connects policy/governance with infrastructure/product security.
- Ensures all product teams have secure by default settings.
- Currently manages policy, certification, log check automation, and incident response.
- Seeking engineers to build the next phase (EDR, SIEM, MDM, Security Agent, etc.) from the ground up.
- Homepage
- Blog
- YouTube
Equal Opportunity
- By agreeing to the personal information processing policy and applying for employment, you acknowledge and agree that the applicant's personal information will be transferred internationally.
- Recipient and transferring country: Lever / United States
- Transferred personal information items: Name, email, contact information, and related documents.
- Purpose of transfer and retention period: For recruitment process / 2 years.
- You may choose not to agree to the international transfer of personal information, but you will not be able to submit the final application. By clicking 'Apply', you are deemed to have agreed.
