About the job
Join Our Security Team!
The security team at Toss Securities is composed of dedicated professionals, including a CISO, Security Engineers, Security Researchers, Information Security Managers, and Privacy Managers. We are committed to creating secure services, receiving robust support from the entire organization, and collaborating effectively across all departments.
Our team members, with diverse experience ranging from 1 to 20 years, primarily come from backgrounds in information security firms and corporate security roles. We actively share knowledge and collaborate to achieve common goals.
To ensure the safe operation of our securities services, we conduct vulnerability assessments across various fields such as applications, cloud, infrastructure, and network. We are also developing automated testing systems using DAST, SAST, and IAST tools to enhance our testing framework.
Your Responsibilities:
- Collaborate with relevant departments from the service planning stage to perform security reviews and provide guidelines for safe service implementation.
- Conduct vulnerability assessments on Toss Securities' internal and external services (WTS, MTS, operational systems, etc.), analyze results, and suggest improvements.
- Perform infrastructure vulnerability assessments as required by electronic financial regulations and domestic/international security certifications (Public/Private Cloud, Server, DBMS, Network, etc.).
- Execute scenario-based internal/external penetration tests and conduct preliminary checks to prevent internal information leaks.
Who We're Looking For:
- Individuals with over 7 years of experience in vulnerability assessments.
- Experience in operating or conducting assessments with infrastructure vulnerability assessment tools.
- Experience in developing tools or automation programs for vulnerability assessments.
- Ability to perform REST API vulnerability assessments based on an understanding of MSA environments.
- Experience in security audits identifying vulnerabilities such as IDOR in Java or Kotlin source code.
- Experience in assessing application vulnerabilities in Android or iOS environments.
- Understanding of electronic financial services and securities systems is a plus.
- Experience or understanding of Attack Surface Management is a bonus.
Application Tips:
- Include any services or programs you've developed or participated in, specifying the language, role, deployment status, and operational environment.
- Detail specific vulnerabilities identified through SAST, DAST, Image Scanning, Secret Scanning, and your corrective actions (company/service names can be anonymized).
- Explain how you assessed and responded to actual security incidents or potential risks, such as secret exposure or high-risk image vulnerabilities.
- Share challenges and solutions encountered during security assessment automation or policy application processes.
Hiring Process at Toss Securities:
- Application submission > Job interview > Cultural fit interview > Reference check > Salary negotiation > Final acceptance and onboarding.
Additional Information:
- Providing false information in your resume or discovering disciplinary actions in your employment history may lead to termination of the recruitment process.

