Apply Edge Start your job search

Senior Manager, Information Security

Toss Securities US LLC · New York, NY

Apply & track with Apply Edge

Senior Manager, Information Security, Toss Securities USToss Securities is one of Korea's fastest growing retail securities and fintech platform, widely regarded as one of the country's most innovative fintech brands. As part of its global expansion, Toss has opened overseas offices in the US and Japan. Toss Securities US LLC (TSUS), a FINRA regulated broker-dealer, is building the next generation of investing products and infrastructure as it actively grows its U.S. operations. As part of the broader Toss ecosystem, TSUS combines a startup mindset with the rigor required of a regulated financial institution.We are seeking an experienced Senior Manager, Information Security to join our growing team. This role offers an exciting opportunity to build and lead the information security function of a dynamic, regulated brokerage firm while advancing your career in the U.S. financial markets.The Senior Manager, Information Security is the senior information security leader for Toss Securities US. This role owns two connected mandates:US Information Security Leadership: end-to-end ownership of TSUS's information security and privacy program — policy, controls, risk assessments, and regulatory readiness — while serving as the primary link between US security operations and the global security division at Toss Securities Korea.Compliance & Risk Partnership: supporting the US compliance organization on regulatory inquiries, examinations, and audits from FINRA and SEC, and acting as the technical and operational lead for cybersecurity, data privacy, and IT controls.This is a highly visible role requiring strong technical security skills, regulatory fluency in broker-dealer and financial-services requirements, and the ability to translate between local US operational needs and group-level security standards.Key ResponsibilitiesOwn TSUS's information security & privacy program end-to-endOwn policies, controls, risk assessments, and regulatory readiness across TSUS's information security and privacy program.Build and maintain privacy compliance aligned to CCPA / CPRA, applicable state privacy laws, and cross-border data transfer requirements between the U.S. and Korea entities.Interpret and operationalize U.S. financial regulations into practical control frameworks.Align global standards with US-specific requirementsAlign continuously with Toss Securities Korea to bring global standards and U.S.-specific requirements into a single coherent framework.Identify gaps and design region-appropriate controls without breaking the global baseline.Be the bridge between US operations and Korean security colleagues, translating security posture across two regulatory contexts, two languages, and two operating cultures.Support compliance, audits, and vendor riskSupport the U.S. compliance team with regulatory inquiries, examinations, and audits from FINRA and SEC, serving as the technical and operational lead for cybersecurity, data privacy, and IT controls.Conduct third-party / vendor risk assessments for TSUS's SaaS, cloud, and third-party technology providers.Provide security review and consultation for new services, features, and infrastructure changes launched at TSUS.Build the function, not just operate itStay current on regulatory and threat-landscape changes affecting broker-dealer information security and privacy obligations.Establish the frameworks, tooling, and processes needed to scale the security function as TSUS grows.Qualifications8+ years of experience in information security, IT audit, or GRC, with meaningful time in U.S. financial services (broker-dealer, investment adviser, exchange, or bank).Direct experience with U.S. cybersecurity regulations.Working knowledge of privacy regulations (CCPA / CPRA, GLBA Safeguards, Reg S-P) and cross-border data transfer considerations.Sound technical fluency across cloud (AWS), SaaS, endpoint, identity, and network segmentation, SIEM, and logging — enough to challenge engineering teams' security designs, not just accept them.Strong written and verbal English communication. Working-level Korean is a strong plus given close daily alignment with Toss Securities Korea.Curious mindset: asks “why are we doing it this way” and builds better technical and security structures, doesn't accept the status quo.Job Specification

Location: New York, NYReports to: CEO, Toss Securities USDirect Reports: IT ManagerPreferredUS securities or fintech background — retail brokerage, crypto, asset management, or trading platforms (e.g., experience at firms like Robinhood, Coinbase, Schwab, SoFi, IBKR, or similar).CISSP, CISA, CISM, CRISC, CIPP/US, or equivalent certifications.Experience building an information security program from zero-to-one at a new U.S. entity or subsidiary.Familiarity with SOC 2, ISO 27001, and PCI DSS in a financial services context.Prior experience working with Korean or APAC parent companies and navigating cross-cultural, cross-time-zone collaboration.Equal Opportunity EmployerTSUS is an Equal Opportunity Employer.

We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status.