yandex
T
toast
Страна
США
Зарплата
127 000 $ – 203 000 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
LeadУдалённоПолная занятость

Lead Technical Governance Analyst

Оценка ИИ

Высокая оценка обусловлена прозрачным диапазоном зарплаты, удаленным форматом работы и возможностью влиять на архитектуру безопасности крупного продукта. Компания Toast известна своей культурой и инновационным подходом к AI.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует глубокой экспертизы (8+ лет) в GRC, владения специфическими инструментами (AuditBoard) и умения выстраивать процессы с нуля в быстрорастущей среде. Высокая сложность обусловлена необходимостью совмещать технические навыки с лидерством без прямого подчинения.

Анализ зарплаты

Медиана165 000 $
Рынок135 000 $ – 210 000 $
Оценка ИИ

Предлагаемый диапазон $127k – $203k полностью соответствует рыночным ожиданиям для позиции Lead уровня в США. Нижняя граница подходит для кандидатов, переходящих на уровень Lead, а верхняя — для экспертов с уникальным опытом в автоматизации GRC.

Сопроводительное письмо

I am writing to express my strong interest in the Lead Technical Governance Analyst position at Toast. With over 8 years of experience in Information Security GRC and a proven track record of managing complex GRC platforms like AuditBoard, I am confident in my ability to drive the foundational architecture of your governance program. My expertise in operationalizing Common Controls Frameworks (CCF) and mapping regulations such as NIST CSF, SOC 2, and PCI DSS aligns perfectly with Toast's mission to scale security and compliance efficiently.

Throughout my career, I have championed 'Compliance by Design' by embedding GRC checkpoints directly into the SDLC, a strategy I am eager to bring to Toast. I am particularly drawn to your 'Shift Left' approach and the opportunity to optimize the Trust Center to enhance customer transparency. My technical background, combined with a strategic mindset for risk mitigation, enables me to translate complex security requirements into actionable business insights. I look forward to the possibility of contributing to Toast’s innovative culture and helping protect the data of the restaurant community.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в toast уже сейчас

Присоединяйтесь к Toast и станьте архитектором безопасности, определяющим будущее GRC в динамично развивающейся финтех-экосистеме!

Описание вакансии

Toast creates technology to help restaurants and local businesses succeed in a digital world, helping business owners operate, increase sales, engage customers, and keep employees happy.

The Lead Technical Governance Analyst is a high-impact, autonomous role responsible for designing and driving the foundational architecture of our world-class GRC program.

A day in the life (Responsibilities)

In this role, you will play an integral part in building the frameworks, systems, and transformation programs that enable scale and efficiency across all security and compliance and risk domains. In addition, you will be responsible for supporting the ongoing oversight of certain workforce-related security initiatives and policies, and will collaborate closely with our Security and Business Technology and Transformation teams to ensure the security of Toast’s sensitive data and critical infrastructure. This role requires a proactive and strategic approach to identifying and mitigating risks, as well as a deep understanding of the evolving cybersecurity landscape.

  • Drive Security and Technical Governance Risk and Compliance Initiatives:
  • GRC Platform Ownership: Serve as the primary admin and product owner for the GRC platform (AuditBoard). You will move beyond administration to design advanced workflows, automation, and metrics that centralize risk and compliance data.
  • Common Controls Framework (CCF) Stewardship: Own and evolve the Common Controls Framework. You will map and maintain complex regulations (NIST CSF, SOC 2, PCI DSS, ISO 27001) to a single source of truth, directly driving compliance efficiencies
  • Lead Strategic Initiatives: Independently lead complex, cross-functional "zero-to-one" security programs, taking them from concept to operational maturity.
  • Customer Trust Optimization: Drive the strategy for our Trust Center, operationalizing our ability to address customer and partner security questionnaires in a more efficient manner,reducing manual efforts and shortening lead times.
  • Develop and implement governance policies, controls, and best practices to enhance the security posture across corporate IT and workforce systems.
  • "Compliance by Design" Advisory: Champion the "Shift Left" strategy by co-developing standards that embed GRC checkpoints into the SDLC and Product innovation pipelines, ensuring security is baked in, not bolted on.
  • Change Events Governance: Define and standardize the process for assessing GRC impacts during major system changes, ensuring consistent intake and triage across all compliance programs.
  • Track and report on security governance KPIs and risk metrics, driving continuous improvement.
  • Collaborate with IT and Security:
  • Partner closely with the IT team to ensure corporate systems are managed appropriately and meet security objectives.
  • Work with the Security team to implement monitoring and detection capabilities that support workforce security objectives.
  • Promote Security Culture:
  • Foster a strong security culture within the organization through training, awareness programs, and ongoing communication. .

What you'll need to thrive (Requirements)

Core Program & Technical Experience

  • 8+ Years of progressive experience in Information Security GRC, Audit, or Technical Program Management.
  • CCF & Framework Expertise: Hands-on experience designing and operationalizing a Common Controls Framework (CCF) to map and consolidate controls across multiple regulatory frameworks (SOX, PCI DSS, SOC 2, NIST CSF, ISO 27001).
  • GRC Platform Mastery: Proven experience serving as an Administrator, Architect, or primary owner of a modern GRC tool (e.g., AuditBoard, ServiceNow GRC, Workiva), including advanced workflow design, configuration, and maintenance.
  • Policy Architecture: Expert ability to define, manage, and enforce a clear hierarchy of governance documentation (Policy, Standard, Procedure) and maintain security baselines for corporate IT and workforce tools.
  • Program Ownership: Demonstrated ability to drive the lifecycle of complex security initiatives, such as Data Governance Oversight, SaaS Posture Management, End Protection/Hardware Inventory, and Third-Party Risk Management.
  • Technical Acumen: Strong understanding of cybersecurity controls across cloud security, corporate IT security, and identity and access management (IAM). Committed to staying ahead of the curve in the ever-evolving field of cybersecurity.

Leadership & Collaboration

  • Proven ability to lead and manage security initiatives and drive complex, cross-functional collaboration efforts without direct authority.
  • Builds strong relationships with stakeholders across the organization and thrives in a dynamic and rapidly changing environment.
  • Exceptional written and verbal communication skills, with the ability to translate complex security architecture into clear business risks for non-technical audiences.
  • A proactive and strategic approach to identifying, mitigating, and documenting risks in a high-growth, fast-paced technology environment.

Special Sauce (Nice-to-Haves)

  • Controls Engineering Experience: Experience with scripting (e.g., Python, SQL) or building APIs/integrations to automate evidence collection.
  • Advanced Certifications: Relevant security certifications such as CISSP, CISM, or CISA.
  • Teaching/Enablement: Experience designing or facilitating training programs (e.g., Compliance Champions) or leading Cyber Tabletop Exercises.
  • Experience supporting security governance in a remote or hybrid workforce environment.

AI at Toast

At Toast, one of our company values is that we're hungry to build and learn. We believe learning new AI tools empowers us to build for our customers faster, more independently, and with higher quality. We provide these tools across all disciplines, from Engineering and Product to Sales and Support, and are inspired by how our Toasters are already driving real value with them. The people who thrive here are those who embrace changes that let us build more for our customers; it’s a core part of our culture.

Our Total Rewards Philosophy

We strive to provide competitive compensation and benefits programs that help to attract, retain, and motivate the best and brightest people in our industry. Our total rewards package goes beyond great earnings potential and provides the means to a healthy lifestyle with the flexibility to meet Toasters’ changing needs. Learn more about our benefits at https://careers.toasttab.com/toast-benefits.

#LI-Remote

The base salary range for this role is listed below. The starting salary will be determined based on skills and experience. In addition to base salary, our total rewards components include cash compensation (overtime, bonus/commissions, if eligible), benefits, and equity (if eligible).

Pay Range

$127,000—$203,000 USD

How Toast Uses AI in its Hiring Process

Throughout the hiring process, our goal is to get to know you. We use AI tools to support our recruiters and interviewers with tasks like note-taking, summarization, and documentation of interviews to ensure they can be fully focused on your conversation. All hiring decisions are made by people.

**Diversity, Equity, and Inclusion is Baked into our Recipe for Success**

At Toast, our employees are our secret ingredient—when they thrive, we thrive. The restaurant industry is one of the most diverse, and we embrace that diversity with authenticity, inclusivity, respect, and humility. By embedding these principles into our culture and design, we create equitable opportunities for all and raise the bar in delivering exceptional experiences.

We Thrive Together

We embrace a hybrid work model that fosters in-person collaboration while valuing individual needs. Our goal is to build a strong culture of connection as we work together to empower the restaurant community. To learn more about how we work globally and regionally, check out: https://careers.toasttab.com/locations-toast.

Apply today!

Toast is committed to creating an accessible and inclusive hiring process. As part of this commitment, we strive to provide reasonable accommodations for persons with disabilities to enable them to access the hiring process. If you need an accommodation to access the job application or interview process, please contact candidateaccommodations@toasttab.com.

------

For roles in the United States, it is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Python
  • SOC 2
  • ISO 27001
  • PCI DSS
  • SQL
  • CISA
  • CISSP
  • CISM
  • Information Security
  • IAM
  • Cloud Security
  • GRC
  • SOX
  • NIST CSF
  • AuditBoard

Возможные вопросы на собеседовании

Кандидат должен быть экспертом в GRC-платформах. Этот вопрос проверяет практический опыт настройки автоматизации.

Опишите ваш опыт администрирования AuditBoard или аналогичной GRC-системы: какие сложные воркфлоу вы проектировали для автоматизации сбора доказательств?

Центральная часть роли — работа с CCF. Важно понять, как кандидат справляется с наложением разных стандартов.

Как вы подходите к маппингу контролей между NIST CSF, SOC 2 и PCI DSS в рамках единого фреймворка (CCF), чтобы избежать дублирования работы?

Вакансия делает упор на 'Compliance by Design'. Вопрос проверяет умение интегрировать безопасность в разработку.

Каким образом вы внедряли контрольные точки GRC в жизненный цикл разработки ПО (SDLC), чтобы обеспечить соответствие требованиям на ранних этапах?

Роль предполагает лидерство через влияние. Проверка навыков коммуникации с техническими и бизнес-командами.

Приведите пример, когда вам нужно было убедить команду разработчиков или ИТ внедрить новый стандарт безопасности, который они считали избыточным. Как вы добились результата?

Toast ценит проактивность в управлении рисками. Вопрос на стратегическое мышление.

Как вы приоритизируете риски в условиях быстрого роста компании и постоянных изменений в ИТ-инфраструктуре?

Похожие вакансии

N
Navio
от 300 000 ₽

Ведущий специалист по безопасности приложений (AppSec)

LeadГибридРоссия
AppSec · SAST · SCA · ASOC · AntiDDoS · WAF · Kubernetes · Cloud Infrastructure · Linux · Jira · GitLab · Artifactory · Network Security
+13 навыков
Т
Т-Банк
от 430 000 ₽

Red Team Lead

LeadВ офисеРоссия
Red Teaming · Offensive Security · Python · Go · C++ · PowerShell · Linux · Windows · Active Directory · MITRE ATT&CK · SIEM · EDR · WAF · Threat Intelligence · Purple Teaming · PKI · Cryptography
+17 навыков
N
netskope
147 000 $ – 299 500 $

Principal Engineer, Cloud Firewall

LeadУдалённоСША
C++ · TCP/IP · SSL/TLS · Firewall · IPS/IDS · Wireshark · TCPDump · GTest · PyTest · Ansible · Kubernetes · SQL · NoSQL · CI/CD · Jenkins · Distributed Systems
+16 навыков
J
JETLYN
210 000 ₽ – 260 000 ₽

Специалист по защите информации (Mobile Security Engineer)

SeniorУдалённоРоссия
iOS · Cryptography · Jailbreak · HTTPS · REST API · gRPC · TCP · UDP · HTTP · Protobuf · JSON · Avro · MessagePack · Reverse Engineering
+14 навыков
AG
Atom group
4 000 $ – 5 000 $

Senior Information Security (ИБ)

SeniorУдалённоБеларусь
Information Security · DevSecOps · SDLC · Risk Management · Security Policy · DevOps
+6 навыков
I
iherb
177 000 $ – 225 000 $

Principal Application Security Engineer

LeadУдалённоСША
Python · C++ · .NET · JavaScript · Node.js · Java · AWS · Docker · SAST · DAST · SCA · Threat Modeling · Cryptography · API Design · Microservices · Cloudflare · OWASP Top 10
+17 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

T
toast
Страна
США
Зарплата
127 000 $ – 203 000 $