klara@security: ~/home
/
TLP:CLEAR

ChaeYoung "Klara" Kim

Cyber Risk & Compliance ยท Robot/IoT/CPS Security

Ask me anything below โ†“

Where I've been.

Seoul ๐Ÿ 
Closter, NJ
San Diego
Bucharest
Taoyuan

Click a pin to see details

One person, two threat models.

COMPLIANCE AUDIT ์ปดํ”Œ๋ผ์ด์–ธ์Šค ๊ฐ์‚ฌ ISMS-P ยท SOC 2 HIPAA OFFENSIVE RESEARCH ๊ณต๊ฒฉ ๋ณด์•ˆ ์—ฐ๊ตฌ STRIDE ยท LINDDUN ATT&CK KLARA evidence โ‡„ exploit ์ฆ๊ฑฐ โ‡„ ์ต์Šคํ”Œ๋กœ์ž‡

I split my time between two ways of asking the same question โ€” "where does this actually break?" By day, I support ISMS-P certification, SOC 2 and HIPAA-related IT audit, and third-party security assessments, reading controls the way an auditor has to: literally, evidentially, line by line.

์ €๋Š” ๊ฐ™์€ ์งˆ๋ฌธ์„ ๋‘ ๊ฐ€์ง€ ๋ฐฉ์‹์œผ๋กœ ๋ฌป์Šต๋‹ˆ๋‹ค โ€” "์‹ค์ œ๋กœ ์–ด๋””์„œ ๋ฌด๋„ˆ์ง€๋Š”๊ฐ€?" ๋‚ฎ์—๋Š” ISMS-P ์ธ์ฆ, SOC 2ยทHIPAA IT ๊ฐ์‚ฌ, ์ œ3์ž ๋ณด์•ˆ ํ‰๊ฐ€๋ฅผ ์ง€์›ํ•ด์š”. ๊ฐ์‚ฌ์ž์˜ ์‹œ์„ ์œผ๋กœ, ์ฆ๊ฑฐ์— ๊ธฐ๋ฐ˜ํ•ด, ํ•œ ์ค„ ํ•œ ์ค„ ํ†ต์ œ ํ•ญ๋ชฉ์„ ์ฝ์–ด๋ƒ…๋‹ˆ๋‹ค.

Outside client work, I research how those same assumptions hold up in service robots, IoT-connected spaces, and cyber-physical systems โ€” threat modeling with STRIDE and LINDDUN, and occasionally turning audit findings into proof-of-concept attack paths just to see if the paperwork was right.

๊ทธ ์™ธ ์‹œ๊ฐ„์—๋Š” ์„œ๋น„์Šค ๋กœ๋ด‡, IoT ์—ฐ๊ฒฐ ๊ณต๊ฐ„, ์‚ฌ์ด๋ฒ„-๋ฌผ๋ฆฌ ์‹œ์Šคํ…œ์—์„œ ๊ฐ™์€ ๊ฐ€์ •์ด ์–ผ๋งˆ๋‚˜ ๋ฒ„ํ‹ฐ๋Š”์ง€ ์—ฐ๊ตฌํ•ฉ๋‹ˆ๋‹ค. STRIDE์™€ LINDDUN์œผ๋กœ ์œ„ํ˜‘์„ ๋ชจ๋ธ๋งํ•˜๊ณ , ๊ฐ€๋”์€ ๊ฐ์‚ฌ ํŒŒ์ธ๋”ฉ์„ PoC ๊ณต๊ฒฉ ๊ฒฝ๋กœ๋กœ ๋ฐ”๊ฟ”์„œ '์„œ๋ฅ˜๋Š” ๋งž์•˜๋‚˜'๋ฅผ ํ™•์ธํ•˜๊ธฐ๋„ ํ•ด์š”.

That habit started early. I learned Linux in a campus user group before I learned how to write an audit finding, and spent a year leading newsletter coverage for a national security training program before I ever sat in a client meeting. I'm most comfortable where compliance and offense meet.

์ด ์Šต๊ด€์€ ์ผ์ฐ ์‹œ์ž‘๋์–ด์š”. ๊ฐ์‚ฌ ํŒŒ์ธ๋”ฉ์„ ์“ฐ๊ธฐ ์ „์— ์บ ํผ์Šค ๋ฆฌ๋ˆ…์Šค ์‚ฌ์šฉ์ž ๊ทธ๋ฃน์—์„œ Linux๋ฅผ ๋ฐฐ์› ๊ณ , ํด๋ผ์ด์–ธํŠธ ๋ฏธํŒ…์— ๋“ค์–ด๊ฐ€๊ธฐ ์ „์— ๊ตญ๊ฐ€ ๋ณด์•ˆ ํ›ˆ๋ จ ํ”„๋กœ๊ทธ๋žจ์˜ ๋‰ด์Šค๋ ˆํ„ฐ ํŽธ์ง‘์žฅ์„ ํ–ˆ์–ด์š”. ์ปดํ”Œ๋ผ์ด์–ธ์Šค์™€ ๊ณต๊ฒฉ ๋ณด์•ˆ์ด ๋งŒ๋‚˜๋Š” ์ง€์ ์ด ๊ฐ€์žฅ ํŽธํ•ฉ๋‹ˆ๋‹ค.

From a Linux user group to client floors.

Formal Education

Elementary ์ดˆ๋“ฑํ•™๊ต

Seoul + Closter, New Jersey, USA ์„œ์šธ + ๋ฏธ๊ตญ ๋‰ด์ €์ง€์ฃผ ํด๋กœ์Šคํ„ฐ

4 years abroad at elementary school in Closter, NJ, USA

๋ฏธ๊ตญ ๋‰ด์ €์ง€์ฃผ ํด๋กœ์Šคํ„ฐ ์ดˆ๋“ฑํ•™๊ต 4๋…„ ์œ ํ•™

Middle School ์ค‘ํ•™๊ต

๋Œ€์™•์ค‘ํ•™๊ต (Daewang Middle School)

Seoul, South Korea

High School ๊ณ ๋“ฑํ•™๊ต

์ฐฝ๋•์—ฌ์ž๊ณ ๋“ฑํ•™๊ต (Changdeok Girls' High School)

Seoul, South Korea

University ๋Œ€ํ•™๊ต

์„œ์šธ์—ฌ์ž๋Œ€ํ•™๊ต (Seoul Women's University)

Seoul, South Korea

  • SWLUG (Seoul Women's University Linux User Group), 25th cohort
  • SWLUG (์„œ์šธ์—ฌ์ž๋Œ€ํ•™๊ต ๋ฆฌ๋ˆ…์Šค ์‚ฌ์šฉ์ž ๊ทธ๋ฃน), 25๊ธฐ

Community & Training

Training Program ๊ต์œก ํ”„๋กœ๊ทธ๋žจ

BoB (Best of the Best) โ€” 13th Cohortโ€” 13๊ธฐ

KITRI โ€” Korea's national elite cybersecurity talent program

KITRI โ€” ๊ตญ๋‚ด ์ตœ๊ณ  ์ˆ˜์ค€์˜ ์‚ฌ์ด๋ฒ„๋ณด์•ˆ ์ธ์žฌ ์–‘์„ฑ ํ”„๋กœ๊ทธ๋žจ

Community Leadership ์ปค๋ฎค๋‹ˆํ‹ฐ ๋ฆฌ๋”์‹ญ

BoB Newsletter

Reporter Team Lead, 6th cohort โ†’ Editor-in-Chief, 7th cohort

๊ธฐ์žํŒ€์žฅ 6๊ธฐ โ†’ ํŽธ์ง‘์žฅ 7๊ธฐ

Training Program ๊ต์œก ํ”„๋กœ๊ทธ๋žจ

Global Cybersecurity Camp (GCC) โ€” 2025 Cohortโ€” 2025

International cybersecurity talent program, Taoyuan, Taiwan

๊ตญ์ œ ์‚ฌ์ด๋ฒ„๋ณด์•ˆ ์ธ์žฌ ํ”„๋กœ๊ทธ๋žจ, ๋Œ€๋งŒ ํƒ€์˜ค์œ„์•ˆ

Selected Experience

Dec 2025 โ€“ Present Compliance ยท IT Audit

Deloitte Anjin LLC โ€” Cyber Security Consultantโ€” ์‚ฌ์ด๋ฒ„ ๋ณด์•ˆ ์ปจ์„คํ„ดํŠธ

T&T Cyber Risk & Compliance

T&T ์‚ฌ์ด๋ฒ„ ๋ฆฌ์Šคํฌ & ์ปดํ”Œ๋ผ์ด์–ธ์Šค

  • Support ISMS initial and re-certification consulting projects for client-confidential global brands.
  • Participate in third-party security assessment and IT audit projects.
  • Support SOC 2 and HIPAA-related IT audit work for a Korean listed company's U.S. subsidiary.
  • ๊ธ€๋กœ๋ฒŒ ๊ธฐ์—… ๋Œ€์ƒ ISMS ์ดˆ๊ธฐยท๊ฐฑ์‹  ์ธ์ฆ ์ปจ์„คํŒ… ํ”„๋กœ์ ํŠธ ์ง€์›.
  • ์ œ3์ž ๋ณด์•ˆ ํ‰๊ฐ€ ๋ฐ IT ๊ฐ์‚ฌ ํ”„๋กœ์ ํŠธ ์ฐธ์—ฌ.
  • ๊ตญ๋‚ด ์ƒ์žฅ์‚ฌ์˜ ๋ฏธ๊ตญ ์žํšŒ์‚ฌ ๋Œ€์ƒ SOC 2ยทHIPAA IT ๊ฐ์‚ฌ ์ง€์›.
Mar 2025 โ€“ Jun 2025 Product ยท WAPPLES

PentaSecurity โ€” Internโ€” ์ธํ„ด

Planning Team 1 / WAPPLES Product

๊ธฐํš 1ํŒ€ / WAPPLES ์ œํ’ˆ

  • Prepared web vulnerability analysis reports and customer-facing documentation.
  • Analyzed PCI-DSS v4.0.1 and other compliance requirements for WAPPLES product strategy.
  • Conducted competitive analysis and supported new business model planning.
  • ์›น ์ทจ์•ฝ์  ๋ถ„์„ ๋ณด๊ณ ์„œ ๋ฐ ๊ณ ๊ฐ์‚ฌ ๋Œ€์‘ ๋ฌธ์„œ ์ž‘์„ฑ.
  • WAPPLES ์ œํ’ˆ ์ „๋žต์„ ์œ„ํ•œ PCI-DSS v4.0.1 ์š”๊ตฌ์‚ฌํ•ญ ๋ถ„์„.
  • ๊ฒฝ์Ÿ์‚ฌ ๋ถ„์„ ๋ฐ ์‹ ๊ทœ ๋น„์ฆˆ๋‹ˆ์Šค ๋ชจ๋ธ ๊ธฐํš ์ง€์›.
Jan 2024 โ€“ Feb 2024 Policy ยท Mobility

Kakao Mobility โ€” Internโ€” ์ธํ„ด

CR Strategy Office / External Affairs Team

CR ์ „๋žต์‹ค / ๋Œ€์™ธํ˜‘๋ ฅํŒ€

  • Authored a report on cyber security and data protection in the autonomous vehicle and mobility industry.
  • ์ž์œจ์ฃผํ–‰ยท๋ชจ๋นŒ๋ฆฌํ‹ฐ ์‚ฐ์—…์˜ ์‚ฌ์ด๋ฒ„๋ณด์•ˆ ๋ฐ ๋ฐ์ดํ„ฐ ๋ณดํ˜ธ์— ๊ด€ํ•œ ๋ณด๊ณ ์„œ ์ž‘์„ฑ.
Jul 2023 โ€“ Aug 2023 CI/CD ยท Cloud

Ericsson-LG R&D โ€” Software Engineering Internโ€” ์†Œํ”„ํŠธ์›จ์–ด ์—”์ง€๋‹ˆ์–ด๋ง ์ธํ„ด

CI/CD Testing Team / vCU7 Team

CI/CD ํ…Œ์ŠคํŒ… ํŒ€ / vCU7 ํŒ€

  • Built a Jenkins-based build pipeline to support namespace cleanup in a Kubernetes environment.
  • Gained experience in agile development, CI/CD workflows, and internal deployment processes.
  • Kubernetes ํ™˜๊ฒฝ ๋„ค์ž„์ŠคํŽ˜์ด์Šค ์ •๋ฆฌ๋ฅผ ์œ„ํ•œ Jenkins ๋นŒ๋“œ ํŒŒ์ดํ”„๋ผ์ธ ๊ตฌ์ถ•.
  • ์• ์ž์ผ ๊ฐœ๋ฐœ, CI/CD ์›Œํฌํ”Œ๋กœ์šฐ, ๋‚ด๋ถ€ ๋ฐฐํฌ ํ”„๋กœ์„ธ์Šค ๊ฒฝํ—˜.

Featured Projects

Team Lead ยท Robot Security ํŒ€์žฅ ยท ๋กœ๋ด‡ ๋ณด์•ˆ

Service Robot Security Consulting

์„œ๋น„์Šค ๋กœ๋ด‡ ๋ณด์•ˆ ์ปจ์„คํŒ…

Led a security consulting project focused on vulnerability assessment, threat modeling, and security requirement derivation for autonomous service robots.

์ž์œจ ์„œ๋น„์Šค ๋กœ๋ด‡ ์ทจ์•ฝ์  ํ‰๊ฐ€, ์œ„ํ˜‘ ๋ชจ๋ธ๋ง, ๋ณด์•ˆ ์š”๊ตฌ์‚ฌํ•ญ ๋„์ถœ ์ปจ์„คํŒ… ํ”„๋กœ์ ํŠธ ๋ฆฌ๋“œ.

  • LG Electronics service robot security consulting
  • Robot security model publication with KIRIA and KISA
  • Policy and standardization discussion around service robot cyber security
  • LG์ „์ž ์„œ๋น„์Šค ๋กœ๋ด‡ ๋ณด์•ˆ ์ปจ์„คํŒ…
  • KIRIAยทKISA์™€ ๋กœ๋ด‡ ๋ณด์•ˆ ๋ชจ๋ธ ๋…ผ๋ฌธ ๊ธฐ์—ฌ
  • ์„œ๋น„์Šค ๋กœ๋ด‡ ์‚ฌ์ด๋ฒ„๋ณด์•ˆ ์ •์ฑ…ยทํ‘œ์ค€ํ™” ๋…ผ์˜ ์ฐธ์—ฌ
Member ยท Space Security ๋ฉค๋ฒ„ ยท ์šฐ์ฃผ ๋ณด์•ˆ

Kinryu Labs (formerly SATCR4K)

Member of Kinryu Labs, an international research collective on CubeSat security with Singapore and Taiwan teams.

์‹ฑ๊ฐ€ํฌ๋ฅดยท๋Œ€๋งŒ ํŒ€๊ณผ ํ•จ๊ป˜ํ•˜๋Š” ๊ตญ์ œ ํ๋ธŒ์ƒ› ๋ณด์•ˆ ์—ฐ๊ตฌ ๊ทธ๋ฃน Kinryu Labs์˜ ๋ฉค๋ฒ„.

  • Presented at DefCamp, Romania
  • Focused on satellite and embedded system security
  • ๋ฃจ๋งˆ๋‹ˆ์•„ DefCamp ์—ฐ๊ตฌ ๋ฐœํ‘œ
  • ์œ„์„ฑ ๋ฐ ์ž„๋ฒ ๋””๋“œ ์‹œ์Šคํ…œ ๋ณด์•ˆ ์—ฐ๊ตฌ
kinryu.sh โ†—
Threat Intelligence ์œ„ํ˜‘ ์ธํ…”๋ฆฌ์ „์Šค

APT Group Profiling Framework

APT ๊ทธ๋ฃน ํ”„๋กœํŒŒ์ผ๋ง ํ”„๋ ˆ์ž„์›Œํฌ

Designed a profiling framework to identify APT groups by combining hash-unit evidence with TTPs.

ํ•ด์‹œ ๋‹จ์œ„ ์ฆ๊ฑฐ์™€ TTP๋ฅผ ๊ฒฐํ•ฉํ•ด APT ๊ทธ๋ฃน์„ ์‹๋ณ„ํ•˜๋Š” ํ”„๋กœํŒŒ์ผ๋ง ํ”„๋ ˆ์ž„์›Œํฌ ์„ค๊ณ„.

  • Published in IEICE Transactions on Information and Systems
  • Best Paper Award at KIISE KSC 2023
  • IEICE Transactions on Information and Systems ๊ฒŒ์žฌ
  • KIISE KSC 2023 ํ•™๋ถ€์ƒ ๋…ผ๋ฌธ ๊ฒฝ์ง„๋Œ€ํšŒ ์žฅ๋ ค์ƒ
AI Security ยท Team Lead AI ๋ณด์•ˆ ยท ํŒ€์žฅ

AI Synthetic Voice Detection System

AI ํ•ฉ์„ฑ์Œ์„ฑ ํƒ์ง€ ์‹œ์Šคํ…œ

Led a deepvoice detection project covering dataset collection, preprocessing, model development, training, and testing.

๋ฐ์ดํ„ฐ์…‹ ์ˆ˜์ง‘, ์ „์ฒ˜๋ฆฌ, ๋ชจ๋ธ ๊ฐœ๋ฐœยทํ•™์Šตยทํ…Œ์ŠคํŠธ ์ „ ๊ณผ์ • ๋ฆฌ๋“œ.

  • SK Telecom CEO Award at the AI Ethics Competition
  • Software patent application and academic publication
  • AI ์œค๋ฆฌ ๊ฒฝ์ง„๋Œ€ํšŒ SKํ…”๋ ˆ์ฝค ๋Œ€ํ‘œ์ด์‚ฌ์ƒ
  • ์†Œํ”„ํŠธ์›จ์–ด ํŠนํ—ˆ ์ถœ์› ๋ฐ ๋…ผ๋ฌธ ๋ฐœํ‘œ

Selected Publications

In Preparation ์ค€๋น„ ์ค‘

R-SPS: A Security, Privacy, and Safety Assessment Framework for Service Robots

Target venue: ETRI Journal. Co-authors: MinYoung Park, HunHee Lee, Kyounggon Kim.

ํˆฌ๊ณ  ์˜ˆ์ •: ETRI Journal. ๊ณต์ €์ž: ๋ฐ•๋ฏผ์˜, ์ดํ›ˆํฌ, ๊น€๊ฒฝ๊ณค.

FORESIGHT: A Unified Framework for Threat Modeling and Risk Assessment in Robotics and IoT

NDSS Symposium co-located workshop SDIoTSec Poster, San Diego, Feb. 2025.

NDSS Symposium ๋ถ€๋Œ€ ์›Œํฌ์ˆ SDIoTSec ํฌ์Šคํ„ฐ, ๋ฏธ๊ตญ ์ƒŒ๋””์—์ด๊ณ , 2025.02.

Practical APT Group Hash Unit Profiling Framework Using TTPs

IEICE Transactions on Information and Systems, vol. E107-D, no. 12, Dec. 2024. SCIE.

IEICE Transactions on Information and Systems, vol. E107-D, no. 12, 2024.12. SCIE.

Privacy Threat Modeling and Verification of LTE Phone Transmission in Autonomous Robots Using LINDDUN

KIISC, Nov. 2024.

์ •๋ณด๋ณดํ˜ธํ•™ํšŒ, 2024.11.

Security Requirements Derivation for Indoor Autonomous Driving Robots Based on STRIDE

IEIE, Nov. 2024.

์ „์ž๊ณตํ•™ํšŒ, 2024.11.

Talks, Lectures & Awards

Talks & Lectures

๋ฐœํ‘œ & ๊ฐ•์—ฐ

  • DefCamp, Romania โ€” Research Presentation, Nov. 2025
  • DefCamp, ๋ฃจ๋งˆ๋‹ˆ์•„ โ€” ์—ฐ๊ตฌ ๋ฐœํ‘œ, 2025.11
  • NIPA Overseas Trainee Invitational Lecture, Sep. 2025
  • NIPA ํ•ด์™ธ ์—ฐ์ˆ˜์ƒ ์ดˆ์ฒญ ๊ฐ•์—ฐ, 2025.09
  • KISEC Hyundai AutoEver Lecture, Aug. 2025
  • KISEC ํ˜„๋Œ€์˜คํ† ์—๋ฒ„ ๊ฐ•์—ฐ, 2025.08
  • NDSS SDIoTSec, San Diego โ€” Poster Presentation, Feb. 2025
  • NDSS SDIoTSec, ์ƒŒ๋””์—์ด๊ณ  โ€” ํฌ์Šคํ„ฐ ๋ฐœํ‘œ, 2025.02

Awards

์ˆ˜์ƒ

  • Future Korea Idea Contest, Finalist, Ministry of Economy and Finance, 2024
  • ๋ฏธ๋ž˜ ํ•œ๊ตญ ์•„์ด๋””์–ด ๊ณต๋ชจ์ „ ๋ณธ์„ , ๊ธฐํš์žฌ์ •๋ถ€, 2024
  • AI Ethics Competition, SK Telecom CEO Award, 2024
  • AI ์œค๋ฆฌ ๊ฒฝ์ง„๋Œ€ํšŒ, SKํ…”๋ ˆ์ฝค ๋Œ€ํ‘œ์ด์‚ฌ์ƒ, 2024
  • Korea Software Congress Undergraduate Paper Competition, Encouragement Award, 2024
  • ํ•œ๊ตญ์†Œํ”„ํŠธ์›จ์–ด์ข…ํ•ฉํ•™์ˆ ๋Œ€ํšŒ ํ•™๋ถ€์ƒ ๋…ผ๋ฌธ ๊ฒฝ์ง„๋Œ€ํšŒ, ์žฅ๋ ค์ƒ, 2024
  • Ericsson-LG Girls in ICT Hackathon, Best Award, 2023
  • ์—๋ฆญ์Šจ-LG Girls in ICT ํ•ด์ปคํ†ค, ์ตœ์šฐ์ˆ˜์ƒ, 2023

Open to research collaboration, projects, talks, and mentoring.

This page is rated TLP:CLEAR โ€” public, share freely. ์ด ํŽ˜์ด์ง€๋Š” TLP:CLEAR ๋“ฑ๊ธ‰ โ€” ๊ณต๊ฐœ ์ •๋ณด, ์ž์œ ๋กญ๊ฒŒ ๊ณต์œ  ๊ฐ€๋Šฅ.