About the job
About the Team You Will Join
- The Security Division at Toss Securities comprises the Security Audit Team, Security Policy Team, Security Engineering Team, and IT Innovation Team.
- The security team receives comprehensive support from the entire organization to create secure services at Toss Securities, collaborating closely with all departments.
- Each team member actively engages in sharing experiences and knowledge with peers in the same role across subsidiaries, working together towards common goals.
- The security team consists of members with diverse experience levels, ranging from 1 to 20 years, most of whom have backgrounds in information security firms or corporate information security roles.
- This year, the Security Engineering Team aims to enhance its information security management system to meet international standards, focusing on strengthening technology in areas like SOAR, ZTNA, and Cloud/Container security.
Your Responsibilities Upon Joining
- Understanding CI/CD pipeline structures and integrating security with minimal impact on build and deployment speed.
- Accurately assessing the real risk of security vulnerabilities in Java and Kotlin source code.
- Filtering false positives from SAST/DAST tool results and showing a willingness to improve collaboratively.
- Understanding security responsibility boundaries in AWS and Kubernetes environments and proactively preventing configuration errors during the IaC phase.
The Ideal Candidate
- Comprehends CI/CD pipeline structures and can integrate security without affecting build and deployment speed.
- Has the ability to accurately gauge the actual risk of security vulnerabilities in Java and Kotlin source code.
- Is willing to filter false positives from SAST/DAST tool results and improve together.
- Understands security boundaries in AWS and Kubernetes environments and can prevent configuration errors at the IaC stage.
Resume Recommendations
- Include any services or programs you have developed or operated, detailing the language used, role, deployment status, and operational environment.
- Specify experiences using SAST, DAST, Image Scan, and Secret Scan tools, particularly if integrated with other tools.
- Detail how you approached and resolved challenges during projects, and how you grew from those experiences.
Please Note
- This is a 1-year contractual position.
- Both new graduates and experienced candidates are welcome to apply.
- Employment may be revoked if any falsehoods are found in your resume or if disciplinary issues are confirmed in your work history.
- Applicants who are prohibited from hiring or have disqualifying factors per Toss Securities regulations may have their applications canceled.
- Persons with disabilities and veterans will receive preferential treatment as per relevant laws.
The Journey to Joining Toss Securities
- Application submission > Job interview > Cultural fit interview > Final acceptance and onboarding

