Principal Technical Risk Analyst

1 month ago
Full-time
Lead
Cybersecurity
Toast

Toast

Toast is an all-in-one platform for restaurants, offering tableside ordering, online ordering, and labor management to empower businesses in the food service industry.

Hotels, Restaurants & Leisure
1K-5K
Founded 2012

Description

  • Own the end-to-end cyber risk lifecycle, including identification, assessment, prioritization, mitigation tracking, and reporting.
  • Establish and operationalize a scalable technical risk operating model from discovery through monitoring.
  • Drive adoption of the technical risk program across Security, Product, Engineering, and Infrastructure teams.
  • Lead technical risk management in close partnership with cross-functional stakeholders and enterprise risk teams.
  • Build and scale risk discovery mechanisms using stakeholder input, audits, incidents, assessments, and external signals.
  • Translate technical issues into clear, business-relevant risk narratives and influence stakeholders toward timely mitigation.
  • Evolve the technical risk program’s taxonomy, assessment frameworks, and risk-to-control mapping in partnership with ERM.
  • Own and improve the use of Optro (formerly AuditBoard) RiskOversight as the system of record.
  • Develop executive-ready dashboards, committee materials, and risk reporting for leadership and governance forums.
  • Communicate and escalate risk status, trends, and decisions to the Enterprise Risk and Compliance Committee.

Requirements

  • 8–12+ years of experience in Technical Risk, Security GRC, ERM, or related fields.
  • Proven experience owning and leading a technical or cyber risk program.
  • Strong understanding of cybersecurity domains including cloud, infrastructure, IAM, and application security.
  • Strong understanding of risk frameworks such as NIST CSF and ISO 27001.
  • Experience operating in high-growth, complex, cloud-based environments.
  • Demonstrated ability to build and operationalize programs from 0 to 1 and from 1 to scale.
  • Strong program management discipline, including planning, tracking, and follow-through.
  • Ability to translate technical issues into business impact and prioritize risks by impact and likelihood.
  • Exceptional executive-ready written and verbal communication skills.
  • Experience with GRC tools such as Optro/AuditBoard, ServiceNow GRC, or Workiva.
  • Preferred experience integrating technical risk into ERM programs.
  • Preferred experience building risk dashboards, metrics, and reporting frameworks.
  • Preferred familiarity with automation, AI, or data-driven GRC approaches.
  • Preferred relevant certifications such as CISSP, CISM, CISA, or CRISC.

Benefits

  • Base salary range of $131,000 to $210,000 CAD.
  • Total rewards include cash compensation such as overtime and eligible bonus/commissions.
  • Equity as part of the compensation package.
  • Competitive benefits designed to support a healthy lifestyle and changing needs.
  • Hybrid work model with in-person collaboration and flexibility.
  • Access to AI tools across disciplines to support faster, higher-quality work.
  • Reasonable accommodations available during the hiring process for candidates with disabilities.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Medicaid and Medicare Policy Researcher

American Institutes for Research 1K-5K Professional Services

AIR is hiring a Researcher on its Healthcare Transformation team to lead health policy work focused on Marketplace, Medicaid, and Medicare programs that supports federal and state efforts to improve outcomes for low-income and medically vulnerable populations.

Python R SQL
7 hours, 2 minutes ago

Program Manager, Professional Services - East

Airtable 1K-5K IT Services

Airtable is hiring a Technical Project Manager to lead complex enterprise delivery engagements in its Professional Services organization, driving end-to-end outcomes across customers, partners, and internal teams as the platform expands into AI-assisted workflows.

Agile
7 hours, 17 minutes ago

Hazard Zone Deployment Manager

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Regional Lead for its Air Defense team to deliver and sustain Family of Systems products in hazardous operational environments for SOCOM and other customers.

Agile
7 hours, 17 minutes ago

Manager, Clinical Trials

Natera 1K-5K Pharmaceuticals

Natera is hiring a Manager, Clinical Trials to oversee clinical studies from start-up through close-out and ensure timelines, costs, quality, and compliance are met.

GCP HIPAA
7 hours, 17 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers