About the job
About the Team You'll Join
- The Security Division at Toss Securities comprises the Security Policy Team and the Security Engineering Team, with the Security Policy Team including roles such as Information Security Manager and Privacy Manager.
- This division enjoys comprehensive support across the organization to create secure Toss Securities services and collaborates closely with all departments.
- Team members actively exchange experiences and knowledge with peers in similar roles across affiliates to achieve shared goals.
- The team consists of members with diverse experience ranging from 1 to 20 years, most of whom have backgrounds in information security firms and corporate information security roles.
- This year, we are focusing on enhancing our information security management system through global security standard certifications and prioritizing risk management based on data flow and business processes. We will also conduct research activities to advance regulatory frameworks.
Responsibilities You'll Have
- Lead the establishment and operation of information security policies, as well as the acquisition and maintenance of domestic and international security certifications (ISMS-P, ISO/IEC 27001, 27701, 27017, 27018, PCI-DSS, etc.).
- Formulate and amend security policies in response to changes in legislation and regulations, and develop operational processes.
- Oversee internal audits, inspections, and external institution assessments, driving improvement initiatives.
- Establish and lead the security risk assessment and management processes.
- Plan and implement security awareness programs (training, campaigns) to foster a security-centric culture within the organization.
- Mentor junior colleagues and contribute to the growth of team capabilities.
Ideal Candidate Profile
- Over 5 years of experience in information security policy and management system operations within the finance and electronic finance sectors.
- Proven experience leading the acquisition and maintenance of domestic and international security certifications.
- Strong background in responding to external organizations and validated risk management skills.
- Experience in designing and executing organizational policies and processes.
- Ability to identify and lead new security challenges in rapidly changing IT/service environments.
Journey to Joining Toss Securities
- Application submission > Role interview > Cultural fit interview > Reference check > Compensation negotiation > Final acceptance and onboarding.
Please Note
- Any discrepancies found in the resume or supporting documents, or any disciplinary issues in the work history may lead to cancellation of employment.
- Candidates identified as prohibited or disqualified under Toss Securities internal regulations may also have their applications canceled.
- Individuals with disabilities and those eligible for national veteran benefits are given preferential treatment in accordance with relevant laws.
A Message for Future Colleagues
- You can create an information security management system with comprehensive organizational support.
- At Toss Securities, all colleagues share an understanding of the importance of information security, and the Security Division builds the management system based on this shared awareness.
- To establish a high-level information security management system, we not only comply with mandatory requirements but also embrace various challenges to present new cultures and trends. This means you will gain diverse experiences not confined to routine tasks.
- We are looking for passionate colleagues who want to contribute to the security of Toss Securities while experiencing explosive growth in their careers.
