About the job
# Join Our Team
- As a Security Audit Manager at Toss Securities, you will play a pivotal role within our Security Audit Team in the Security Division.
- The Security Audit Team is responsible for conducting independent internal audits across the entirety of our information security management system, IT infrastructure, information security systems, and overall data management frameworks.
- Collaboration with various teams is essential to create reliable financial services, encompassing diverse areas such as security, infrastructure, platforms, and products.
- The Security Audit Team consists of specialists focusing on [Information Security Management] and [Data Protection and Management], providing in-depth audits and supporting the decision-making processes of the CISO (CPO, CIAP).
# Responsibilities
- Develop audit plans based on relevant regulations, including the Personal Information Protection Act and the Credit Information Act, and conduct comprehensive audits of personal data processing systems and customer data management.
- Evaluate compliance and safety measures throughout the entire lifecycle of personal data processing, including collection, usage, provision, and disposal.
- Assess the security management status and regulatory compliance in the latest personal data processing environments, such as pseudonymized information and AI-based services.
- Evaluate the adequacy of data breach prevention and response systems while identifying areas for improvement.
- Objectively analyze audit results and prepare reports, offering specific recommendations for enhancing the level of personal data protection.
# We Are Looking For
- Candidates with experience in establishing and managing personal data protection systems, and who have addressed various personal data issues in services.
- A deep understanding and practical application of relevant laws, including the Personal Information Protection Act, the Credit Information Act, and the Act on Promotion of Information and Communications Network Utilization.
- Specialized knowledge in data lifecycle management and methodologies for Personal Data Impact Assessments (PIA).
- Audit capabilities related to new personal data processing environments, including pseudonymized information and AI-based services.
- Excellent communication skills for effective collaboration with diverse teams.
# How to Apply
- Please share specific examples of your experience in personal data protection and data management audits.
- Include your achievements in improving personal data processing environments or data management activities through audit responses and self-assessments.
- Detail your experience in interpreting and applying personal data protection regulations.
- Highlight your audit experience in new personal data processing environments, such as AI technology, MyData, and pseudonymized information.
- If you have experience collaborating with various teams to resolve complex issues, be sure to showcase that.
