Staff Insider Threat Analyst
Coupang · Taiwan
Company Introduction Coupang is reimagining the shopping experience with the goal of wowing each customer from the instant they open the Coupang app to the moment an order is delivered to their door. Our services in Taiwan include “Rocket Delivery” which offers next-day delivery for a wide selection of items at affordable prices, “Rocket Oversea” which offers free international delivery on millions of best-selling products from Korea, the U.S., and beyond. We are looking for talents to help us lead Coupang’s expansion in Taiwan. This is an exceptional opportunity to become a part of Coupang’s growth in Taiwan and create a world where our customers wonder, “How did I ever live without Coupang?”
主任內部威脅分析師 (Staff Insider Threat Analyst)我們正在尋找一位主任內部威脅分析師,擔任內部威脅團隊的深度技術專家。此職位適合經驗豐富、能在高度自主環境下發揮所長,並兼具深厚技術專長與敏銳調查思維的分析師。您將負責企業內部威脅案件中,技術分析的完整生命週期,從告警分類到執行複雜且以數據驅動的審查。您將成為團隊的主要技術專家,執行深入分析,並將發現報告給調查團隊,以協助正式的調查工作。主要職責:
主動行為分析: 透過關聯 DLP、EDR、SIEM/SOR 及其他資料來源的日誌,主動獵捕並分析異常的使用者行為,先一步在風險擴大前予以識別。
管理內部威脅分析案件的生命週期: 對新告警進行分類、管理案件排程,並對使用者活動、系統軌跡及應用程式日誌進行深入的技術審查,以建立完整的事件時間軸。
支援正式調查: 與案件調查、法務及人資團隊合作,提供技術端的威脅分析發現。將複雜的技術資料轉化為清晰、客觀的報告,以作為正式調查之基礎。
擔任領域專家 (SME): 作為團隊在內部威脅資料來源方面的技術專家,為其他分析師提供指導與專家見解。
改善偵測機制: 持續開發、調整與優化內部威脅偵測邏輯,建立新的應對戰術手冊 (Playbooks) 與告警準則,以提升內部威脅偵防的成熟度。
提供策略性見解: 不僅報告「發生了什麼 (what)」和「是誰 (who)」,更要深入探討「為什麼 (why)」和「如何發生 (how)」,為管理層提供具體可行的建議,以強化整體安全態勢與控制措施。
必備條件: • 具備 6 年以上資訊安全經驗,其中至少有 3 年直接從事內部威脅分析的實務經驗。 • 展現出色的分析與關聯資安事件的能力,熟悉以下事件源: UBA (使用者行為分析) / 內部威脅平台EDR 解決方案SIEM / 數據湖 (Data Lakes) • 在基於主機的分析 (Host-based Analysis) 以及針對端點、應用程式和網路日誌跡證的深入審查方面具備專家級經驗。 • 經證實能獨立作業,在最少監督下管理複雜且敏感的案件,並能向技術及非技術合作夥伴清晰簡報技術發現。 • 具備調查思維: 天生具有好奇心、注重細節、保持懷疑態度且客觀,並有找出根本原因的強烈動力。 • 具備腳本撰寫技能 (Python、PowerShell、Bash),能自動化分析任務與資料分析。 • 資訊工程、資訊安全或相關領域學士學位,或具備同等實務經驗。
加分條件:
具備從零開始建立或大幅提升內部威脅偵防成熟度的經驗。
具備相關業界證照 (如 GCIH、CISSP)。
精通中文與商業英文。
熟悉數位鑑識工具,並了解廣泛的鑑識原則.
You will be responsible for the full lifecycle of technical analysis for insider threat cases, from triaging alerts to conducting complex, data-driven reviews. You will be the team's primary technical expert, performing in-depth analysis and reporting your findings to the Investigations team to support formal inquiries. Key Responsibilities:
Proactive Behavioral Analysis: Proactively hunt for and analyze anomalous user behavior by correlating data from DLP logs, EDR logs, SIEM/SOR logs, and other data sources to identify risks before they escalate.
Manage the Insider Threat Analysis Lifecycle: Triage incoming alerts, manage the queue, and conduct deep-dive technical reviews of user activity, system artifacts, and application logs to build a comprehensive timeline of events.
Support Formal Investigations: Partner with and provide detailed, technical findings to the Investigations, Legal, and HR teams. Translate complex technical data into clear, objective reports that serve as the foundation for formal inquiries.
Act as a Subject Matter Expert: Serve as the team's technical SME for insider threat data sources, providing guidance and insights to other analysts.
Improve Detections: Continuously develop, tune, and refine insider threat detection logic, creating new playbooks and alerting criteria to mature the program.
Provide Strategic Insight: Go beyond just the "what" and "who" to report on the "why" and "how," providing actionable recommendations to leadership for strengthening security posture and controls.
Qualifications:
6+ years of experience in information security, with at least 3+ years of direct, hands-on experience in insider threat analysis.
Demonstrated mastery of analyzing and correlating security events from:
UBA/Insider Threat platforms
EDR solutions
SIEM / Data Lakes
Expert-level experience in host-based analysis and deep review of endpoint, application, and network log artifacts.
Proven ability to work autonomously, manage complex, sensitive cases with minimal supervision, and present technical findings clearly to both technical and non-technical partners.
An investigative mindset: You are naturally curious, detail-oriented, skeptical, and objective, with a strong drive to find the root cause.
Scripting skills (Python, PowerShell, Bash) for automating analytical tasks and data analysis.
Bachelor’s degree in Computer Science, Information Security, or equivalent practical experience.
Preferred Qualifications:
Experience in building or significantly maturing an insider threat program from the ground up.
Relevant industry certifications (GCIH, CISSP).
Languages: Mandarin - Native / English - Proficient.
Familiarity with digital forensic toolsets and a high-level understanding of forensic principles.
Recruitment Process and Others
Recruitment Process
Application Review - Phone Interview - Onsite (or Virtual Onsite) Interview – Offer The exact nature of the recruitment process may vary according to the specific job and may be changed due to scheduling or other circumstances. Interview schedules and the results will be informed to the applicant via the e-mail address submitted at the application stage.
Details to Consider
This job posting may be closed prior to the stated end date for application if all openings are filled. Coupang has the right to rescind an offer of employment if a candidate is found to have submitted false information as part of the application process. Those eligible for employment protection (recipients of veteran’s benefits, the disabled, etc.) may receive preferential treatment for employment in accordance with applicable laws.
Privacy Notice
Your personal information will be collected and managed by Coupang as stated in the Application Privacy Notice located below: https://www.coupang.jobs/privacy-policy/