companyToss Securities logo

Security Researcher at Toss Securities | Seoul

On-site Full-time

Clicking Apply Now takes you to AutoApply where you can tailor your resume and apply.


Unlock Your Potential

Generate Job-Optimized Resume

One Click And Our AI Optimizes Your Resume to Match The Job Description.

Is Your Resume Optimized For This Role?

Find Out If You're Highlighting The Right Skills And Fix What's Missing

Experience Level

Mid to Senior

Qualifications

Qualifications: 7+ years of experience in vulnerability assessments. Hands-on experience with infrastructure vulnerability assessment tools. Development experience in tools or automation for vulnerability assessments. Understanding of MSA environments and ability to perform REST API vulnerability assessments. Experience in security audits for code vulnerabilities in Java/Kotlin. Experience in Android/iOS application vulnerability assessments. Familiarity with electronic financial services and securities systems. Experience or understanding of Attack Surface Management.

About the job

Join Our Security Team!

The security team at Toss Securities is composed of dedicated professionals, including a CISO, Security Engineers, Security Researchers, Information Security Managers, and Privacy Managers. We are committed to creating secure services, receiving robust support from the entire organization, and collaborating effectively across all departments.

Our team members, with diverse experience ranging from 1 to 20 years, primarily come from backgrounds in information security firms and corporate security roles. We actively share knowledge and collaborate to achieve common goals.

To ensure the safe operation of our securities services, we conduct vulnerability assessments across various fields such as applications, cloud, infrastructure, and network. We are also developing automated testing systems using DAST, SAST, and IAST tools to enhance our testing framework.

Your Responsibilities:

  • Collaborate with relevant departments from the service planning stage to perform security reviews and provide guidelines for safe service implementation.
  • Conduct vulnerability assessments on Toss Securities' internal and external services (WTS, MTS, operational systems, etc.), analyze results, and suggest improvements.
  • Perform infrastructure vulnerability assessments as required by electronic financial regulations and domestic/international security certifications (Public/Private Cloud, Server, DBMS, Network, etc.).
  • Execute scenario-based internal/external penetration tests and conduct preliminary checks to prevent internal information leaks.

Who We're Looking For:

  • Individuals with over 7 years of experience in vulnerability assessments.
  • Experience in operating or conducting assessments with infrastructure vulnerability assessment tools.
  • Experience in developing tools or automation programs for vulnerability assessments.
  • Ability to perform REST API vulnerability assessments based on an understanding of MSA environments.
  • Experience in security audits identifying vulnerabilities such as IDOR in Java or Kotlin source code.
  • Experience in assessing application vulnerabilities in Android or iOS environments.
  • Understanding of electronic financial services and securities systems is a plus.
  • Experience or understanding of Attack Surface Management is a bonus.

Application Tips:

  • Include any services or programs you've developed or participated in, specifying the language, role, deployment status, and operational environment.
  • Detail specific vulnerabilities identified through SAST, DAST, Image Scanning, Secret Scanning, and your corrective actions (company/service names can be anonymized).
  • Explain how you assessed and responded to actual security incidents or potential risks, such as secret exposure or high-risk image vulnerabilities.
  • Share challenges and solutions encountered during security assessment automation or policy application processes.

Hiring Process at Toss Securities:

  • Application submission > Job interview > Cultural fit interview > Reference check > Salary negotiation > Final acceptance and onboarding.

Additional Information:

  • Providing false information in your resume or discovering disciplinary actions in your employment history may lead to termination of the recruitment process.

About Toss Securities

Toss Securities is dedicated to ensuring secure financial services through a collaborative and knowledgeable security team. Our environment fosters innovation and effective communication, enabling the delivery of safe and reliable services to our clients.

Similar jobs

Tailoring 0 resumes

We'll move completed jobs to Ready to Apply automatically.