Principal Technical Risk Analyst

20 hours, 15 minutes ago
Full-time
Lead
Cybersecurity
Toast

Toast

Toast is an all-in-one platform for restaurants, offering tableside ordering, online ordering, and labor management to empower businesses in the food service industry.

Hotels, Restaurants & Leisure
1K-5K
Founded 2012

Description

  • Own the end-to-end cyber risk lifecycle, including identification, assessment, prioritization, mitigation tracking, and reporting.
  • Establish and operationalize a scalable technical risk operating model from discovery through monitoring.
  • Drive adoption of the technical risk program across Security, Product, Engineering, and Infrastructure teams.
  • Lead technical risk management in close partnership with cross-functional stakeholders and enterprise risk teams.
  • Build and scale risk discovery mechanisms using stakeholder input, audits, incidents, assessments, and external signals.
  • Translate technical issues into clear, business-relevant risk narratives and influence stakeholders toward timely mitigation.
  • Evolve the technical risk program’s taxonomy, assessment frameworks, and risk-to-control mapping in partnership with ERM.
  • Own and improve the use of Optro (formerly AuditBoard) RiskOversight as the system of record.
  • Develop executive-ready dashboards, committee materials, and risk reporting for leadership and governance forums.
  • Communicate and escalate risk status, trends, and decisions to the Enterprise Risk and Compliance Committee.

Requirements

  • 8–12+ years of experience in Technical Risk, Security GRC, ERM, or related fields.
  • Proven experience owning and leading a technical or cyber risk program.
  • Strong understanding of cybersecurity domains including cloud, infrastructure, IAM, and application security.
  • Strong understanding of risk frameworks such as NIST CSF and ISO 27001.
  • Experience operating in high-growth, complex, cloud-based environments.
  • Demonstrated ability to build and operationalize programs from 0 to 1 and from 1 to scale.
  • Strong program management discipline, including planning, tracking, and follow-through.
  • Ability to translate technical issues into business impact and prioritize risks by impact and likelihood.
  • Exceptional executive-ready written and verbal communication skills.
  • Experience with GRC tools such as Optro/AuditBoard, ServiceNow GRC, or Workiva.
  • Preferred experience integrating technical risk into ERM programs.
  • Preferred experience building risk dashboards, metrics, and reporting frameworks.
  • Preferred familiarity with automation, AI, or data-driven GRC approaches.
  • Preferred relevant certifications such as CISSP, CISM, CISA, or CRISC.

Benefits

  • Base salary range of $131,000 to $210,000 CAD.
  • Total rewards include cash compensation such as overtime and eligible bonus/commissions.
  • Equity as part of the compensation package.
  • Competitive benefits designed to support a healthy lifestyle and changing needs.
  • Hybrid work model with in-person collaboration and flexibility.
  • Access to AI tools across disciplines to support faster, higher-quality work.
  • Reasonable accommodations available during the hiring process for candidates with disabilities.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Program Manager

Supplied Talent 1-10 Professional Services

Skaled is hiring a Program Manager to oversee delivery operations across its Revenue Strategy and AI client engagements, ensuring clean setup, realistic execution, early risk detection, and clear portfolio visibility.

Asana CRM JIRA Monday.com
20 minutes ago

Senior Technical Program Manager

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Technical Program Manager to lead ISR system development and deployment across engineering, product, and customer teams for defense and security missions.

Computer Vision
24 minutes ago

Canada- Security Analyst I

PointClickCare 1K-5K Health Care Providers & Services

PointClickCare is hiring a Security Analyst I to protect its corporate and product environments by strengthening security operations, incident response, and vulnerability management in a remote role with occasional travel to the Mississauga office.

Active Directory Bash Cybersecurity DNS Encryption JSON Linux PowerShell Python Shell Scripting TCP/IP YAML
39 minutes ago

Sr. Clinical Research Associate

Alimentiv 251-1K Professional Services

Sr. Clinical Research Associate for Clinical Services at Chișinău, overseeing full clinical site monitoring and project support for one or more complex, potentially multinational studies in a remote, home-based role.

GCP
55 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers