포지션 상세
Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. We are trusted by 300+ million people in 100+ countries for our industry-leading security, user fund transparency, trading engine speed, deep liquidity, and an unmatched portfolio of digital-asset products. Binance offerings range from trading and finance to education, research, payments, institutional services, Web3 features, and more. We leverage the power of digital assets and blockchain to build an inclusive financial ecosystem to advance the freedom of money and improve financial access for people around the world.
About the Role
Binance is seeking a Chief Information Security Officer to lead the information security function across our Korea operations during a critical period of regulatory growth. This is a high-impact leadership role requiring someone who can bridge enterprise-grade cloud security with the distinct regulatory landscape of Korea. The CISO will be the primary security advocate internally and with regulators, owning both the technical security posture and the compliance narrative.
• Own end-to-end security certifications — from gap assessment through to audit readiness and approval
• Serve as the primary liaison to Korean financial regulators (FSC, FSSC, KISA) on all security and data protection matters
• Translate regulatory requirements into actionable security controls and communicate these effectively to global Binance teams
• Arrange and lead annual IT security risk assessments
[Security Strategy & Operations]
• Define and execute the information security strategy for Korea, aligned with global security standards
• Oversee cloud security architecture and ensure controls meet both global policy and local regulatory expectations
• Lead incident response, threat modeling, and vulnerability management programs across both markets
• Manage InfoSec teams, including hiring, mentoring, and performance management
[Internal & Cross-functional Collaboration]
• Partner closely with global CISO office, engineering, legal, and compliance teams
• Advocate for security requirements at the global level — push back when needed, align when appropriate
• Work with external consultants and third-party auditors supporting certification and audit cycles in both markets
[Stakeholder Communication]
• Report to leadership and maintain transparency on security posture, risk, and regulatory timelines
• Present risk assessments and security updates
[주요업무]
• 규제 및 컴플라이언스 리더십 (Regulatory & Compliance Leadership)
• 전반적인 보안 인증 총괄: 갭 분석(Gap Assessment)부터 심사 대비 및 최종 승인에 이르기까지 보안 인증 프로세스 전반을 총괄
• 한국 금융 규제 기관 대응: 보안 및 데이터 보호(개인정보 보호)에 관한 모든 사항에 대해 한국 금융 당국(금융위원회, 금융감독원, 한국인터넷진흥원 등)과의 주요 소통 창구 역할 수행
• 규제 요구사항의 보안 통제화: 규제 요구사항을 실행 가능한 보안 통제 항목으로 수립·변환하고, 이를 글로벌 바이낸스 팀에 효과적으로 전달 및 공유
• 연례 보안 리스크 평가 주도: 연례 IT 보안 리스크 평가 계획을 수립하고 이를 주도적으로 진행
[보안 전략 및 운영]
• 보안 전략 수립 및 실행: 글로벌 보안 표준에 발맞추어 한국 시장에 최적화된 정보보안 전략을 정의하고 실행
• 클라우드 보안 아키텍처 감독: 클라우드 보안 아키텍처를 감독하고, 보안 통제 항목이 글로벌 정책과 국내 규제 기준을 모두 충족하도록 관리
• 침해 사고 대응 및 위협 관리: 두 시장(글로벌/국내) 전체에 걸쳐 사고 대응(Incident Response), 위협 모델링, 취약점 관리 프로그램을 총괄
• 정보보안 팀 관리: 채용, 멘토링, 성과 관리를 포함한 정보보안(InfoSec) 팀 리딩 및 관리
[내부 및 부서 간 협업]
• 글로벌 및 주요 부서 협력: 글로벌 CISO 오피스, 엔지니어링, 법무, 컴플라이언스 팀과 긴밀히 협력
• 글로벌 차원의 보안 요구사항 대변: 글로벌 조직 내에서 보안 요구사항을 대변하며, 필요에 따라 조율하고 이견을 조정 및 설득
• 외부 기관 협력: 양국 시장의 인증 및 심사 주기를 지원하는 외부 컨설턴트 및 제3자 감사인과 협력
[이해관계자 소통]
• 경영진 보고 및 투명성 유지: 보안 태세, 리스크, 규제 관련 일정을 경영진에 보고하고 투명하게 공유
• 리스크 평가 결과 보고: 리스크 평가 결과 및 보안 업데이트 사항 발표/보고
• 10+ years of information security experience, with at least 3–5 years in a senior leadership role (CISO, Head of Security, or equivalent)
• Hands-on experience with ISMS or ISMS-P certification in Korea — ideally as the accountable owner through a successful audit cycle
• Deep familiarity with Korean financial/digital asset regulatory requirements (FSC guidelines, PIPA, KISA standards)
• Strong understanding of cloud security and modern enterprise security architectures
• Proven ability to collaborate across functions — you work with engineering, compliance, and legal, not around them
• Bilingual English and Korean is required to be able to coordinate with overseas partners and stakeholders
• Strong ownership mindset — you drive outcomes, not status updates
• 학력: 정보기술(IT), 정보보안(Cyber Security) 또는 관련 학과 학사 이상 학위 소지자
• 경력: 정보보안 분야 경력 10년 이상, 최고정보보호책임자(CISO), 보안 총괄(Head of Security) 또는 이에 준하는 리더십 역할 최소 3~5년 이상 경험자
• 인증 자격: 국내 ISMS 또는 ISMS-P 인증 관련 실무 경험자 (성공적인 심사 주기를 완수한 총괄 책임자/담당자 경험 우대)
• 규제 이해도: 한국 금융 및 디지털 자산 관련 규제 요구사항(금융위원회 가이드라인, 개인정보 보호법[PIPA], KISA 기준 등)에 대한 깊은 이해도
• 기술 역량: 클라우드 보안 및 현대적인 기업 보안 아키텍처에 대한 높은 이해도
• 부서 간 협업: 부서 간 뛰어난 협업 능력 (엔지니어링, 컴플라이언스, 법무 팀을 회피하지 않고 함께 긴밀히 협력할 수 있는 분)
• 어학 능력: 영어로의 자유로운 회의 및 의사소통(Native)
• 주도적 태도: 강력한 오너십(Ownership) 마인드 (단순 현황 보고에 그치지 않고, 직접 결과를 도출해 내는 분)
About the Role
Binance is seeking a Chief Information Security Officer to lead the information security function across our Korea operations during a critical period of regulatory growth. This is a high-impact leadership role requiring someone who can bridge enterprise-grade cloud security with the distinct regulatory landscape of Korea. The CISO will be the primary security advocate internally and with regulators, owning both the technical security posture and the compliance narrative.
주요업무
[Regulatory & Compliance Leadership]• Own end-to-end security certifications — from gap assessment through to audit readiness and approval
• Serve as the primary liaison to Korean financial regulators (FSC, FSSC, KISA) on all security and data protection matters
• Translate regulatory requirements into actionable security controls and communicate these effectively to global Binance teams
• Arrange and lead annual IT security risk assessments
[Security Strategy & Operations]
• Define and execute the information security strategy for Korea, aligned with global security standards
• Oversee cloud security architecture and ensure controls meet both global policy and local regulatory expectations
• Lead incident response, threat modeling, and vulnerability management programs across both markets
• Manage InfoSec teams, including hiring, mentoring, and performance management
[Internal & Cross-functional Collaboration]
• Partner closely with global CISO office, engineering, legal, and compliance teams
• Advocate for security requirements at the global level — push back when needed, align when appropriate
• Work with external consultants and third-party auditors supporting certification and audit cycles in both markets
[Stakeholder Communication]
• Report to leadership and maintain transparency on security posture, risk, and regulatory timelines
• Present risk assessments and security updates
[주요업무]
• 규제 및 컴플라이언스 리더십 (Regulatory & Compliance Leadership)
• 전반적인 보안 인증 총괄: 갭 분석(Gap Assessment)부터 심사 대비 및 최종 승인에 이르기까지 보안 인증 프로세스 전반을 총괄
• 한국 금융 규제 기관 대응: 보안 및 데이터 보호(개인정보 보호)에 관한 모든 사항에 대해 한국 금융 당국(금융위원회, 금융감독원, 한국인터넷진흥원 등)과의 주요 소통 창구 역할 수행
• 규제 요구사항의 보안 통제화: 규제 요구사항을 실행 가능한 보안 통제 항목으로 수립·변환하고, 이를 글로벌 바이낸스 팀에 효과적으로 전달 및 공유
• 연례 보안 리스크 평가 주도: 연례 IT 보안 리스크 평가 계획을 수립하고 이를 주도적으로 진행
[보안 전략 및 운영]
• 보안 전략 수립 및 실행: 글로벌 보안 표준에 발맞추어 한국 시장에 최적화된 정보보안 전략을 정의하고 실행
• 클라우드 보안 아키텍처 감독: 클라우드 보안 아키텍처를 감독하고, 보안 통제 항목이 글로벌 정책과 국내 규제 기준을 모두 충족하도록 관리
• 침해 사고 대응 및 위협 관리: 두 시장(글로벌/국내) 전체에 걸쳐 사고 대응(Incident Response), 위협 모델링, 취약점 관리 프로그램을 총괄
• 정보보안 팀 관리: 채용, 멘토링, 성과 관리를 포함한 정보보안(InfoSec) 팀 리딩 및 관리
[내부 및 부서 간 협업]
• 글로벌 및 주요 부서 협력: 글로벌 CISO 오피스, 엔지니어링, 법무, 컴플라이언스 팀과 긴밀히 협력
• 글로벌 차원의 보안 요구사항 대변: 글로벌 조직 내에서 보안 요구사항을 대변하며, 필요에 따라 조율하고 이견을 조정 및 설득
• 외부 기관 협력: 양국 시장의 인증 및 심사 주기를 지원하는 외부 컨설턴트 및 제3자 감사인과 협력
[이해관계자 소통]
• 경영진 보고 및 투명성 유지: 보안 태세, 리스크, 규제 관련 일정을 경영진에 보고하고 투명하게 공유
• 리스크 평가 결과 보고: 리스크 평가 결과 및 보안 업데이트 사항 발표/보고
자격요건
• Bachelor's degree or higher in Information Technology, Cyber Security, or a related field• 10+ years of information security experience, with at least 3–5 years in a senior leadership role (CISO, Head of Security, or equivalent)
• Hands-on experience with ISMS or ISMS-P certification in Korea — ideally as the accountable owner through a successful audit cycle
• Deep familiarity with Korean financial/digital asset regulatory requirements (FSC guidelines, PIPA, KISA standards)
• Strong understanding of cloud security and modern enterprise security architectures
• Proven ability to collaborate across functions — you work with engineering, compliance, and legal, not around them
• Bilingual English and Korean is required to be able to coordinate with overseas partners and stakeholders
• Strong ownership mindset — you drive outcomes, not status updates
• 학력: 정보기술(IT), 정보보안(Cyber Security) 또는 관련 학과 학사 이상 학위 소지자
• 경력: 정보보안 분야 경력 10년 이상, 최고정보보호책임자(CISO), 보안 총괄(Head of Security) 또는 이에 준하는 리더십 역할 최소 3~5년 이상 경험자
• 인증 자격: 국내 ISMS 또는 ISMS-P 인증 관련 실무 경험자 (성공적인 심사 주기를 완수한 총괄 책임자/담당자 경험 우대)
• 규제 이해도: 한국 금융 및 디지털 자산 관련 규제 요구사항(금융위원회 가이드라인, 개인정보 보호법[PIPA], KISA 기준 등)에 대한 깊은 이해도
• 기술 역량: 클라우드 보안 및 현대적인 기업 보안 아키텍처에 대한 높은 이해도
• 부서 간 협업: 부서 간 뛰어난 협업 능력 (엔지니어링, 컴플라이언스, 법무 팀을 회피하지 않고 함께 긴밀히 협력할 수 있는 분)
• 어학 능력: 영어로의 자유로운 회의 및 의사소통(Native)
• 주도적 태도: 강력한 오너십(Ownership) 마인드 (단순 현황 보고에 그치지 않고, 직접 결과를 도출해 내는 분)



