Toss logoToss logo

Security Engineer at Toss | Seoul

TossSeoul
On-site Full-time

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Experience Level

Mid to Senior

Qualifications

5+ years of in-house experience as a Security Engineer; Expertise in AWS cloud security; Proficient in network security solutions; Familiar with SIEM, EDR, and endpoint solutions; Knowledge of security certifications and financial regulations.

About the job

Team and Collaboration

The Security team at Toss brings together a range of professionals: CISO, Security Engineers, Security Researchers, Information Security Managers, Privacy Managers, and IT Managers. This group works closely with the Infra team, product development silos, Legal, and Compliance to build secure services for Toss. Members also connect with security peers across subsidiaries, sharing knowledge and collaborating on specialized areas.

Working here means helping to build and improve security systems that support Toss in delivering reliable services.

What You Will Do

  • Design and operate AWS cloud security architecture, managing cloud security infrastructure such as CSPM and CWPP.
  • Set up detection and response systems using logs, and automate security policies with IaC tools like Terraform.
  • Manage IDS/IPS, WAF, and DDoS protection systems, addressing network vulnerabilities proactively.
  • Design and refine detection policies through traffic and packet analysis, including regular expressions.
  • Collect and respond to security events using SIEM/SOAR, and operate endpoint solutions like EDR and DLP to strengthen organizational security.
  • Lead security design at the service architecture level and support technical compliance requirements.

Requirements

  • At least 5 years of experience as an in-house Security Engineer.
  • Hands-on experience building and operating security systems in AWS cloud environments.
  • Background in constructing and managing network security solutions (IDS/IPS, WAF) and capability in traffic and packet analysis, including optimizing detection policies.
  • Experience with SIEM for event correlation analysis and developing threat hunting and response playbooks is preferred.
  • Familiarity with endpoint security solutions such as EDR, AV, and DLP, as well as handling malware responses and configurations, is a plus.
  • Technical experience with security certifications and financial regulations (ISO27001, PCI-DSS, ISMS-P) is advantageous.

Resume Tips

  • Describe previous roles with clear examples, emphasizing project contributions, technology stacks, and measurable improvements.
  • Share how you approached and solved challenges, including your thought process.
  • Include experiences where you identified and responded to security threats or resolved technical and managerial issues.
  • Highlight specific cases where you learned and applied new security technologies or addressed emerging threats.

Hiring Process

  1. Application
  2. Job Interview
  3. Cultural Fit Interview
  4. Reference Check
  5. Compensation Negotiation
  6. Final Offer and Onboarding

Voices from the Team

"I enjoy working with exceptional colleagues." One team member who joined after serving as the sole security officer at a previous company shared how building Toss's security infrastructure alongside the team has brought stability and a stronger security posture. This collaborative environment has become a source of pride as the team secures valuable assets together.

Toss encourages setting personal goals every half-year, empowering team members to take ownership and collaborate with accomplished peers.

About Toss

Toss is a leading financial technology company committed to providing secure and innovative services to our users. Our mission revolves around creating a safe digital environment through advanced security practices and collaborative teamwork.

Similar jobs

Browse all companies, explore by city & role, or SEO search pages.

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.