ChaeYoung "Klara" Kim
Cyber Risk & Compliance ยท Robot/IoT/CPS Security
Ask me anything below โ
// journey.log
Where I've been.
Click a pin to see details
// about.md
One person, two threat models.
I split my time between two ways of asking the same question โ "where does this actually break?" By day, I support ISMS-P certification, SOC 2 and HIPAA-related IT audit, and third-party security assessments, reading controls the way an auditor has to: literally, evidentially, line by line.
์ ๋ ๊ฐ์ ์ง๋ฌธ์ ๋ ๊ฐ์ง ๋ฐฉ์์ผ๋ก ๋ฌป์ต๋๋ค โ "์ค์ ๋ก ์ด๋์ ๋ฌด๋์ง๋๊ฐ?" ๋ฎ์๋ ISMS-P ์ธ์ฆ, SOC 2ยทHIPAA IT ๊ฐ์ฌ, ์ 3์ ๋ณด์ ํ๊ฐ๋ฅผ ์ง์ํด์. ๊ฐ์ฌ์์ ์์ ์ผ๋ก, ์ฆ๊ฑฐ์ ๊ธฐ๋ฐํด, ํ ์ค ํ ์ค ํต์ ํญ๋ชฉ์ ์ฝ์ด๋ ๋๋ค.
Outside client work, I research how those same assumptions hold up in service robots, IoT-connected spaces, and cyber-physical systems โ threat modeling with STRIDE and LINDDUN, and occasionally turning audit findings into proof-of-concept attack paths just to see if the paperwork was right.
๊ทธ ์ธ ์๊ฐ์๋ ์๋น์ค ๋ก๋ด, IoT ์ฐ๊ฒฐ ๊ณต๊ฐ, ์ฌ์ด๋ฒ-๋ฌผ๋ฆฌ ์์คํ ์์ ๊ฐ์ ๊ฐ์ ์ด ์ผ๋ง๋ ๋ฒํฐ๋์ง ์ฐ๊ตฌํฉ๋๋ค. STRIDE์ LINDDUN์ผ๋ก ์ํ์ ๋ชจ๋ธ๋งํ๊ณ , ๊ฐ๋์ ๊ฐ์ฌ ํ์ธ๋ฉ์ PoC ๊ณต๊ฒฉ ๊ฒฝ๋ก๋ก ๋ฐ๊ฟ์ '์๋ฅ๋ ๋ง์๋'๋ฅผ ํ์ธํ๊ธฐ๋ ํด์.
That habit started early. I learned Linux in a campus user group before I learned how to write an audit finding, and spent a year leading newsletter coverage for a national security training program before I ever sat in a client meeting. I'm most comfortable where compliance and offense meet.
์ด ์ต๊ด์ ์ผ์ฐ ์์๋์ด์. ๊ฐ์ฌ ํ์ธ๋ฉ์ ์ฐ๊ธฐ ์ ์ ์บ ํผ์ค ๋ฆฌ๋ ์ค ์ฌ์ฉ์ ๊ทธ๋ฃน์์ Linux๋ฅผ ๋ฐฐ์ ๊ณ , ํด๋ผ์ด์ธํธ ๋ฏธํ ์ ๋ค์ด๊ฐ๊ธฐ ์ ์ ๊ตญ๊ฐ ๋ณด์ ํ๋ จ ํ๋ก๊ทธ๋จ์ ๋ด์ค๋ ํฐ ํธ์ง์ฅ์ ํ์ด์. ์ปดํ๋ผ์ด์ธ์ค์ ๊ณต๊ฒฉ ๋ณด์์ด ๋ง๋๋ ์ง์ ์ด ๊ฐ์ฅ ํธํฉ๋๋ค.
// education.log
From a Linux user group to client floors.
Formal Education
๋์์คํ๊ต (Daewang Middle School)
์ฐฝ๋์ฌ์๊ณ ๋ฑํ๊ต (Changdeok Girls' High School)
์์ธ์ฌ์๋ํ๊ต (Seoul Women's University)
- SWLUG (Seoul Women's University Linux User Group), 25th cohort
- SWLUG (์์ธ์ฌ์๋ํ๊ต ๋ฆฌ๋ ์ค ์ฌ์ฉ์ ๊ทธ๋ฃน), 25๊ธฐ
Community & Training
BoB (Best of the Best) โ 13th Cohortโ 13๊ธฐ
BoB Newsletter
Global Cybersecurity Camp (GCC) โ 2025 Cohortโ 2025
// experience.log
Selected Experience
Deloitte Anjin LLC โ Cyber Security Consultantโ ์ฌ์ด๋ฒ ๋ณด์ ์ปจ์คํดํธ
T&T Cyber Risk & Compliance
T&T ์ฌ์ด๋ฒ ๋ฆฌ์คํฌ & ์ปดํ๋ผ์ด์ธ์ค
- Support ISMS initial and re-certification consulting projects for client-confidential global brands.
- Participate in third-party security assessment and IT audit projects.
- Support SOC 2 and HIPAA-related IT audit work for a Korean listed company's U.S. subsidiary.
- ๊ธ๋ก๋ฒ ๊ธฐ์ ๋์ ISMS ์ด๊ธฐยท๊ฐฑ์ ์ธ์ฆ ์ปจ์คํ ํ๋ก์ ํธ ์ง์.
- ์ 3์ ๋ณด์ ํ๊ฐ ๋ฐ IT ๊ฐ์ฌ ํ๋ก์ ํธ ์ฐธ์ฌ.
- ๊ตญ๋ด ์์ฅ์ฌ์ ๋ฏธ๊ตญ ์ํ์ฌ ๋์ SOC 2ยทHIPAA IT ๊ฐ์ฌ ์ง์.
PentaSecurity โ Internโ ์ธํด
Planning Team 1 / WAPPLES Product
๊ธฐํ 1ํ / WAPPLES ์ ํ
- Prepared web vulnerability analysis reports and customer-facing documentation.
- Analyzed PCI-DSS v4.0.1 and other compliance requirements for WAPPLES product strategy.
- Conducted competitive analysis and supported new business model planning.
- ์น ์ทจ์ฝ์ ๋ถ์ ๋ณด๊ณ ์ ๋ฐ ๊ณ ๊ฐ์ฌ ๋์ ๋ฌธ์ ์์ฑ.
- WAPPLES ์ ํ ์ ๋ต์ ์ํ PCI-DSS v4.0.1 ์๊ตฌ์ฌํญ ๋ถ์.
- ๊ฒฝ์์ฌ ๋ถ์ ๋ฐ ์ ๊ท ๋น์ฆ๋์ค ๋ชจ๋ธ ๊ธฐํ ์ง์.
Kakao Mobility โ Internโ ์ธํด
CR Strategy Office / External Affairs Team
CR ์ ๋ต์ค / ๋์ธํ๋ ฅํ
- Authored a report on cyber security and data protection in the autonomous vehicle and mobility industry.
- ์์จ์ฃผํยท๋ชจ๋น๋ฆฌํฐ ์ฐ์ ์ ์ฌ์ด๋ฒ๋ณด์ ๋ฐ ๋ฐ์ดํฐ ๋ณดํธ์ ๊ดํ ๋ณด๊ณ ์ ์์ฑ.
Ericsson-LG R&D โ Software Engineering Internโ ์ํํธ์จ์ด ์์ง๋์ด๋ง ์ธํด
CI/CD Testing Team / vCU7 Team
CI/CD ํ ์คํ ํ / vCU7 ํ
- Built a Jenkins-based build pipeline to support namespace cleanup in a Kubernetes environment.
- Gained experience in agile development, CI/CD workflows, and internal deployment processes.
- Kubernetes ํ๊ฒฝ ๋ค์์คํ์ด์ค ์ ๋ฆฌ๋ฅผ ์ํ Jenkins ๋น๋ ํ์ดํ๋ผ์ธ ๊ตฌ์ถ.
- ์ ์์ผ ๊ฐ๋ฐ, CI/CD ์ํฌํ๋ก์ฐ, ๋ด๋ถ ๋ฐฐํฌ ํ๋ก์ธ์ค ๊ฒฝํ.
// projects.dir
Featured Projects
Service Robot Security Consulting
์๋น์ค ๋ก๋ด ๋ณด์ ์ปจ์คํ
Led a security consulting project focused on vulnerability assessment, threat modeling, and security requirement derivation for autonomous service robots.
์์จ ์๋น์ค ๋ก๋ด ์ทจ์ฝ์ ํ๊ฐ, ์ํ ๋ชจ๋ธ๋ง, ๋ณด์ ์๊ตฌ์ฌํญ ๋์ถ ์ปจ์คํ ํ๋ก์ ํธ ๋ฆฌ๋.
- LG Electronics service robot security consulting
- Robot security model publication with KIRIA and KISA
- Policy and standardization discussion around service robot cyber security
- LG์ ์ ์๋น์ค ๋ก๋ด ๋ณด์ ์ปจ์คํ
- KIRIAยทKISA์ ๋ก๋ด ๋ณด์ ๋ชจ๋ธ ๋ ผ๋ฌธ ๊ธฐ์ฌ
- ์๋น์ค ๋ก๋ด ์ฌ์ด๋ฒ๋ณด์ ์ ์ฑ ยทํ์คํ ๋ ผ์ ์ฐธ์ฌ
Kinryu Labs (formerly SATCR4K)
Member of Kinryu Labs, an international research collective on CubeSat security with Singapore and Taiwan teams.
์ฑ๊ฐํฌ๋ฅดยท๋๋ง ํ๊ณผ ํจ๊ปํ๋ ๊ตญ์ ํ๋ธ์ ๋ณด์ ์ฐ๊ตฌ ๊ทธ๋ฃน Kinryu Labs์ ๋ฉค๋ฒ.
- Presented at DefCamp, Romania
- Focused on satellite and embedded system security
- ๋ฃจ๋ง๋์ DefCamp ์ฐ๊ตฌ ๋ฐํ
- ์์ฑ ๋ฐ ์๋ฒ ๋๋ ์์คํ ๋ณด์ ์ฐ๊ตฌ
APT Group Profiling Framework
APT ๊ทธ๋ฃน ํ๋กํ์ผ๋ง ํ๋ ์์ํฌ
Designed a profiling framework to identify APT groups by combining hash-unit evidence with TTPs.
ํด์ ๋จ์ ์ฆ๊ฑฐ์ TTP๋ฅผ ๊ฒฐํฉํด APT ๊ทธ๋ฃน์ ์๋ณํ๋ ํ๋กํ์ผ๋ง ํ๋ ์์ํฌ ์ค๊ณ.
- Published in IEICE Transactions on Information and Systems
- Best Paper Award at KIISE KSC 2023
- IEICE Transactions on Information and Systems ๊ฒ์ฌ
- KIISE KSC 2023 ํ๋ถ์ ๋ ผ๋ฌธ ๊ฒฝ์ง๋ํ ์ฅ๋ ค์
AI Synthetic Voice Detection System
AI ํฉ์ฑ์์ฑ ํ์ง ์์คํ
Led a deepvoice detection project covering dataset collection, preprocessing, model development, training, and testing.
๋ฐ์ดํฐ์ ์์ง, ์ ์ฒ๋ฆฌ, ๋ชจ๋ธ ๊ฐ๋ฐยทํ์ตยทํ ์คํธ ์ ๊ณผ์ ๋ฆฌ๋.
- SK Telecom CEO Award at the AI Ethics Competition
- Software patent application and academic publication
- AI ์ค๋ฆฌ ๊ฒฝ์ง๋ํ SKํ ๋ ์ฝค ๋ํ์ด์ฌ์
- ์ํํธ์จ์ด ํนํ ์ถ์ ๋ฐ ๋ ผ๋ฌธ ๋ฐํ
// publications.bib
Selected Publications
R-SPS: A Security, Privacy, and Safety Assessment Framework for Service Robots
Target venue: ETRI Journal. Co-authors: MinYoung Park, HunHee Lee, Kyounggon Kim.
ํฌ๊ณ ์์ : ETRI Journal. ๊ณต์ ์: ๋ฐ๋ฏผ์, ์ดํํฌ, ๊น๊ฒฝ๊ณค.
FORESIGHT: A Unified Framework for Threat Modeling and Risk Assessment in Robotics and IoT
NDSS Symposium co-located workshop SDIoTSec Poster, San Diego, Feb. 2025.
NDSS Symposium ๋ถ๋ ์ํฌ์ SDIoTSec ํฌ์คํฐ, ๋ฏธ๊ตญ ์๋์์ด๊ณ , 2025.02.
Practical APT Group Hash Unit Profiling Framework Using TTPs
IEICE Transactions on Information and Systems, vol. E107-D, no. 12, Dec. 2024. SCIE.
IEICE Transactions on Information and Systems, vol. E107-D, no. 12, 2024.12. SCIE.
Privacy Threat Modeling and Verification of LTE Phone Transmission in Autonomous Robots Using LINDDUN
KIISC, Nov. 2024.
์ ๋ณด๋ณดํธํํ, 2024.11.
Security Requirements Derivation for Indoor Autonomous Driving Robots Based on STRIDE
IEIE, Nov. 2024.
์ ์๊ณตํํ, 2024.11.
// talks_and_awards.log
Talks, Lectures & Awards
Talks & Lectures
๋ฐํ & ๊ฐ์ฐ
- DefCamp, Romania โ Research Presentation, Nov. 2025
- DefCamp, ๋ฃจ๋ง๋์ โ ์ฐ๊ตฌ ๋ฐํ, 2025.11
- NIPA Overseas Trainee Invitational Lecture, Sep. 2025
- NIPA ํด์ธ ์ฐ์์ ์ด์ฒญ ๊ฐ์ฐ, 2025.09
- KISEC Hyundai AutoEver Lecture, Aug. 2025
- KISEC ํ๋์คํ ์๋ฒ ๊ฐ์ฐ, 2025.08
- NDSS SDIoTSec, San Diego โ Poster Presentation, Feb. 2025
- NDSS SDIoTSec, ์๋์์ด๊ณ โ ํฌ์คํฐ ๋ฐํ, 2025.02
Awards
์์
- Future Korea Idea Contest, Finalist, Ministry of Economy and Finance, 2024
- ๋ฏธ๋ ํ๊ตญ ์์ด๋์ด ๊ณต๋ชจ์ ๋ณธ์ , ๊ธฐํ์ฌ์ ๋ถ, 2024
- AI Ethics Competition, SK Telecom CEO Award, 2024
- AI ์ค๋ฆฌ ๊ฒฝ์ง๋ํ, SKํ ๋ ์ฝค ๋ํ์ด์ฌ์, 2024
- Korea Software Congress Undergraduate Paper Competition, Encouragement Award, 2024
- ํ๊ตญ์ํํธ์จ์ด์ข ํฉํ์ ๋ํ ํ๋ถ์ ๋ ผ๋ฌธ ๊ฒฝ์ง๋ํ, ์ฅ๋ ค์, 2024
- Ericsson-LG Girls in ICT Hackathon, Best Award, 2023
- ์๋ฆญ์จ-LG Girls in ICT ํด์ปคํค, ์ต์ฐ์์, 2023
// contact.sh
Open to research collaboration, projects, talks, and mentoring.
ยฉ ChaeYoung "Klara" Kim. All rights reserved.