Lead Technical Governance Analyst

1 week, 3 days ago
Full-time
Lead
Cybersecurity
Toast

Toast

Toast is an all-in-one platform for restaurants, offering tableside ordering, online ordering, and labor management to empower businesses in the food service industry.

Hotels, Restaurants & Leisure
1K-5K
Founded 2012

Description

  • Design and drive the foundational architecture of the GRC program.
  • Serve as the primary administrator and product owner for the GRC platform (AuditBoard).
  • Design advanced workflows, automation, and reporting metrics to centralize risk and compliance data.
  • Own and evolve the Common Controls Framework by mapping regulations into a single source of truth.
  • Lead complex, cross-functional security programs from concept through operational maturity.
  • Drive the Trust Center strategy and improve handling of customer and partner security questionnaires.
  • Develop and implement governance policies, controls, and best practices for corporate IT and workforce systems.
  • Embed GRC checkpoints into product and SDLC processes through a "compliance by design" approach.
  • Define and standardize governance for assessing GRC impacts during major system changes.
  • Track, report, and improve security governance KPIs and risk metrics.
  • Partner with IT and Security teams to strengthen monitoring, detection, and security objectives.
  • Foster a strong security culture through training, awareness, and ongoing communication.

Requirements

  • 8+ years of progressive experience in Information Security GRC, Audit, or Technical Program Management.
  • Hands-on experience designing and operationalizing a Common Controls Framework (CCF).
  • Experience mapping and consolidating controls across frameworks such as SOX, PCI DSS, SOC 2, NIST CSF, and ISO 27001.
  • Proven experience owning or administering a modern GRC platform such as AuditBoard, ServiceNow GRC, or Workiva.
  • Strong ability to define and enforce a hierarchy of governance documentation, including Policy, Standard, and Procedure.
  • Demonstrated experience driving complex security initiatives such as Data Governance Oversight, SaaS Posture Management, End Protection/Hardware Inventory, or Third-Party Risk Management.
  • Strong understanding of cybersecurity controls across cloud security, corporate IT security, and identity and access management (IAM).
  • Proven ability to lead cross-functional security initiatives without direct authority.
  • Exceptional written and verbal communication skills, including the ability to translate technical security architecture into business risk.
  • Experience with scripting such as Python or SQL, or building APIs/integrations to automate evidence collection (preferred).
  • Relevant certifications such as CISSP, CISM, or CISA (preferred).
  • Experience designing or facilitating training programs or leading cyber tabletop exercises (preferred).
  • Experience supporting security governance in a remote or hybrid workforce environment (preferred).

Benefits

  • Competitive compensation with base salary ranging from $115,000 to $234,000 depending on pay zone, skills, experience, and location.
  • Additional total rewards including cash compensation such as overtime and eligible bonuses/commissions.
  • Equity as part of the total rewards package.
  • Benefits designed to support a healthy lifestyle and flexible employee needs.
  • Hybrid work model that supports in-person collaboration while valuing individual needs.
  • Reasonable accommodations during the hiring process for candidates with disabilities.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Head of Delivery

Derq 11-50 Road & Rail

Derq is hiring an executive-level leader to own complex client delivery and build its customer success function for AI-powered traffic safety and smart infrastructure programs serving public sector customers.

17 minutes ago

Data Engineering and Management Team Leader

Lingaro 5K-10K IT Services

Lingaro is hiring a Data Engineering and Management Team Leader in Poland to lead a remote team, support customer delivery, and help grow the Data E&M competency and business.

Apache Spark CI/CD Databricks Docker Generative AI Kubernetes Python SQL
1 hour, 26 minutes ago

Staff Technical Program Manager

MongoDB 1K-5K Internet Software & Services

MongoDB is seeking a Staff Technical Program Manager to lead complex cross-functional technical programs that align product vision, engineering execution, and business objectives.

Agile AWS Azure GCP MongoDB
2 hours, 4 minutes ago

Program Manager

Game Plan Tech Internet Software & Services

Game Plan Tech is hiring a Program Manager in the Washington, DC metro area to lead complex IT projects for public sector clients, with a focus on cloud, AI, and software delivery.

Agile AWS Azure GCP Scrum
2 hours, 34 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers