About the job
About the Team You Will Join
- The Security Infrastructure team is dedicated to designing security architectures that ensure the safe expansion of Toss's business, implementing and automating these architectures in real-world environments.
- This team covers cloud, network, and endpoint security, directly designing and implementing security policies and controls based on key infrastructure.
- We select technology stacks, create log architectures, and access control models, building a structure that defends against actual threats rather than merely implementing security for security's sake.
- Our team consists of members with diverse experiences, primarily from corporate information security roles and specialized information protection companies.
- We are looking for individuals who start with the question of “Why?” to improve security structures and design safer, more efficient methods while balancing technology and business needs.
Responsibilities You Will Undertake
- Develop and manage information security solutions that protect Toss's services and employee environments.
- Establish and operate an access control system for internal information systems.
- Build a network separation environment and information leak response systems in accordance with financial compliance.
- Plan and operate systems to enhance security visibility and access control systems.
- Conduct modern threat analysis and incorporate global trends while establishing AI-based detection and analysis systems and real-time response strategies.
Additional Responsibilities
- Design, build, and operate infrastructure security architectures across cloud (AWS/GCP/Azure) and on-premises/hybrid environments, covering networks, servers, databases, and containers. You may focus on either cloud or network based on your strengths.
- Design and reliably implement core security policies like IAM, network segmentation, access control, and encryption (KMS) in real environments.
- Structure repetitive security operations based on IaC and automation while collaborating with other teams to establish actionable security standards.
- Analyze security events and breach incidents to design and fundamentally improve security structure, policies, and automation.
Ideal Candidate
- We are searching for individuals with over 3 years of relevant experience.
- You should have experience dealing with infrastructure across cloud, network, and systems, not limited to one area.
- Experience in enhancing detection and response systems using security solutions like CSPM/CNAPP, SIEM, EDR, WAF, and KMS is essential.
- Experience in designing or improving operational efficiency through security automation and IaC with tools like Terraform/CloudFormation, Ansible, and Python is required.
- You should have experience interpreting and integrating security requirements in financial and regulatory environments (ISMS-P, ISO27001, PCI-DSS).

