About the job
# About the Team You'll Join
- The Privacy Manager at Toss is part of the Personal Data Protection (PDP) team.
- The PDP team is responsible for establishing and operating the personal information protection management system, ensuring compliance with privacy laws and regulations, and providing safe and reliable services to customers.
- Additionally, the team implements measures to ensure the safety of personal data, supports various certifications and permit evaluations in the realm of personal data protection, and engages in awareness-raising activities through training and campaigns.
- The PDP team collaborates closely with various teams within Toss and shares insights on specialized fields with privacy professionals across the Toss community.
- Team members possess diverse experiences as personal data protection officers and are highly passionate about protecting customers' valuable information.
# Responsibilities You Will Undertake
- Review the appropriateness of processing personal data throughout the collection, use, provision, and disposal stages within Toss services.
- Draft and manage internal regulations and guidelines related to personal data, along with necessary guides and manuals for data handling.
- Evaluate risks and compliance levels based on personal data protection laws concerning Toss services and data processing procedures.
- Review contracts related to personal data used in Toss services and manage consent forms for data collection, use, and provision.
- Conduct information security assessments and manage compliance with ISMS-P, ISO27001, ISO27701, and similar certifications.
- Establish and implement a monitoring system for legal violations and misuse risks in personal data processing.
# Ideal Candidate Profile
- Experience reviewing the appropriateness of personal data lifecycle processes in services that handle personal information is essential.
- Strong knowledge of and high understanding of personal data protection laws and related guidelines is required.
- Experience in establishing and improving access, retention, use, and disposal policies for personal data from various databases is crucial.
- We seek individuals who wish to develop their skills in overseeing the entire personal data lifecycle, extending beyond mere compliance.
- Holding certifications related to personal data protection, such as ISMS-P auditor or CPPG, is advantageous.
- Experience in creating and managing personal data regulations and guidelines based on laws and company operations, as well as developing practical guides for operational use, is a plus.
- Experience in liaising with external organizations, such as the Financial Services Commission, Financial Supervisory Service, Personal Information Protection Commission, and KISA, is also a plus.
# Joining the Toss Journey
- Application submission > Job interview > Cultural fit interview > Reference check > Compensation negotiation and onboarding date scheduling > Final acceptance.
# A Note for Future Colleagues
- “At Toss, we handle a variety of services in a rapidly changing environment, gaining extensive experience along the way.”
- Through sharing challenges and collaborating, we form deep bonds with colleagues. Privacy protection here offers not just work but a chance to learn and grow together.
- By joining the team, you'll gain a wealth of success experiences in protecting personal information across approximately 100 services implemented in the Toss app. If you want to realize your highest potential, we encourage you to apply!
