← Back to jobs
Toast
Toast

Lead Technical Governance Analyst

otherfull-timeRemote
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
fintech
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

A day in the life (Responsibilities)

In this role, you will play an integral part in building the frameworks, systems, and transformation programs that enable scale and efficiency across all security and compliance and risk domains. In addition, you will be responsible for supporting the ongoing oversight of certain workforce-related security initiatives and policies, and will collaborate closely with our Security and Business Technology and Transformation teams to ensure the security of Toast’s sensitive data and critical infrastructure. This role requires a proactive and strategic approach to identifying and mitigating risks, as well as a deep understanding of the evolving cybersecurity landscape.

  • Drive Security and Technical Governance Risk and Compliance Initiatives:
    • GRC Platform Ownership: Serve as the primary admin and product owner for the GRC platform (AuditBoard). You will move beyond administration to design advanced workflows, automation, and metrics that centralize risk and compliance data.
    • Common Controls Framework (CCF) Stewardship: Own and evolve the Common Controls Framework. You will map and maintain complex regulations (NIST CSF, SOC 2, PCI DSS, ISO 27001) to a single source of truth, directly driving compliance efficiencies
    • Lead Strategic Initiatives: Independently lead complex, cross-functional "zero-to-one" security programs, taking them from concept to operational maturity.
    • Customer Trust Optimization: Drive the strategy for our Trust Center, operationalizing our ability to address customer and partner security questionnaires in a more efficient manner, reducing manual efforts and shortening lead times.
    • Develop and implement governance policies, controls, and best practices to enhance the security posture across corporate IT and workforce systems.
    • "Compliance by Design" Advisory: Champion the "Shift Left" strategy by co-developing standards that embed GRC checkpoints into the SDLC and Product innovation pipelines, ensuring security is baked in, not bolted on.
    • Change Events Governance: Define and standardize the process for assessing GRC impacts during major system changes, ensuring consistent intake and triage across all compliance programs.
    • Track and report on security governance KPIs and risk metrics, driving continuous improvement.
  • Collaborate with IT and Security:
    • Partner closely with the IT team to ensure corporate systems are managed appropriately and meet security objectives.
    • Work with the Security team to implement monitoring and detection capabilities that support workforce security objectives.
  • Promote Security Culture:
    • Foster a strong security culture within the organization through training, awareness programs, and ongoing communication.

What you'll need to thrive (Requirements)

Core Program & Technical Experience

  • 8+ Years of progressive experience in Information Security GRC, Audit, or Technical Program Management.
  • CCF & Framework Expertise: Hands-on experience designing and operationalizing a Common Controls Framework (CCF) to map and consolidate controls across multiple regulatory frameworks (SOX, PCI DSS, SOC 2, NIST CSF, ISO 27001).
  • GRC Platform Mastery: Proven experience serving as an Administrator and product owner for a leading GRC platform (AuditBoard, ServiceNow GRC, OneTrust, or similar).
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $14.99/mo. Cancel anytime.
Join waitlist
Apply now
Lead Technical Governance Analyst at Toast — Remote