About the job
Join Our Team
- The Security Audit Manager at Toss Securities will be part of the Security Division, working within the dedicated Security Audit Team.
- This team is responsible for conducting independent internal audits across the entire information security management system, IT infrastructure, and data management frameworks.
- Collaboration with various teams is essential to create reliable financial services, covering areas including security, infrastructure, platforms, and products.
- The Security Audit Team consists of specialists focusing on Information Security Management Systems and Data Management, supporting the decisions of the CISO and CPO.
Key Responsibilities
- Develop annual audit plans based on information security policies and relevant regulations, auditing the security management status of IT infrastructure and information security systems comprehensively.
- Evaluate the adequacy and compliance of critical information security areas, including access control, security policy implementation, and encryption management.
- Inspect compliance with security requirements in modern IT environments, such as cloud computing and open-source software, including vulnerability management practices.
- Assess the appropriateness of IT disaster recovery and security incident response processes, identifying areas for improvement.
- Objectively analyze audit results, drafting reports and proposing actionable improvement strategies for identified issues.
Ideal Candidate Profile
- Proven experience in information security audits or consulting, with demonstrated leadership skills in evaluating and enhancing information security management systems.
- Expertise in IT infrastructure and security systems (firewalls, IPS/IDS, WAF, etc.), along with experience in vulnerability analysis and assessment.
- Deep understanding of information security management system certification standards (ISMS-P, ISO 27001, etc.) and relevant regulations for conducting audits.
- Proficiency in security auditing within modern technology environments, including MSA, Kubernetes, and Cloud.
- Excellent communication skills to facilitate effective collaboration across diverse teams.
Resume Tips
- Highlight your experience in information security management system audits or internal controls, including specific examples relevant to the role.
- Include experiences of improving IT environments or information security activities through audit responses and self-assessments.
- Detail instances where you identified vulnerabilities and made recommendations that enhanced the organization's security posture.
- If you have security audit experience in cloud environments or emerging technologies, please emphasize that as well as any complex problem-solving experiences with various teams.
Application Process with Toss Securities
- Submit Application > Job Interview > Cultural Fit Interview > Reference Check > Salary Negotiation > Final Offer and Onboarding
Important Notes
- Any discrepancies found in the resume or reports of disciplinary actions during employment may lead to cancellation of the hiring process.
- Individuals disqualified from hiring according to Toss Securities regulations will not be considered.
- Persons with disabilities and national veterans are given preference in accordance with relevant laws.
