[Remote] Lead Technical Governance Analyst

Remote Full-time
Note: The job is a remote job and is open to candidates in USA. Toast creates technology to help restaurants and local businesses succeed in a digital world. The Lead Technical Governance Analyst is responsible for designing and driving the foundational architecture of the GRC program, building frameworks and systems to ensure security and compliance across various domains.

Responsibilities
• Drive Security and Technical Governance Risk and Compliance Initiatives:
• GRC Platform Ownership: Serve as the primary admin and product owner for the GRC platform (AuditBoard). You will move beyond administration to design advanced workflows, automation, and metrics that centralize risk and compliance data
• Common Controls Framework (CCF) Stewardship: Own and evolve the Common Controls Framework. You will map and maintain complex regulations (NIST CSF, SOC 2, PCI DSS, ISO 27001) to a single source of truth, directly driving compliance efficiencies
• Lead Strategic Initiatives: Independently lead complex, cross-functional "zero-to-one" security programs, taking them from concept to operational maturity
• Customer Trust Optimization: Drive the strategy for our Trust Center, operationalizing our ability to address customer and partner security questionnaires in a more efficient manner,reducing manual efforts and shortening lead times
• Develop and implement governance policies, controls, and best practices to enhance the security posture across corporate IT and workforce systems
• "Compliance by Design" Advisory: Champion the "Shift Left" strategy by co-developing standards that embed GRC checkpoints into the SDLC and Product innovation pipelines, ensuring security is baked in, not bolted on
• Change Events Governance: Define and standardize the process for assessing GRC impacts during major system changes, ensuring consistent intake and triage across all compliance programs
• Track and report on security governance KPIs and risk metrics, driving continuous improvement
• Collaborate with IT and Security:
• Partner closely with the IT team to ensure corporate systems are managed appropriately and meet security objectives
• Work with the Security team to implement monitoring and detection capabilities that support workforce security objectives
• Promote Security Culture:
• Foster a strong security culture within the organization through training, awareness programs, and ongoing communication

Skills
• 8+ Years of progressive experience in Information Security GRC, Audit, or Technical Program Management
• Hands-on experience designing and operationalizing a Common Controls Framework (CCF) to map and consolidate controls across multiple regulatory frameworks (SOX, PCI DSS, SOC 2, NIST CSF, ISO 27001)
• Proven experience serving as an Administrator, Architect, or primary owner of a modern GRC tool (e.g., AuditBoard, ServiceNow GRC, Workiva), including advanced workflow design, configuration, and maintenance
• Expert ability to define, manage, and enforce a clear hierarchy of governance documentation (Policy, Standard, Procedure) and maintain security baselines for corporate IT and workforce tools
• Demonstrated ability to drive the lifecycle of complex security initiatives, such as Data Governance Oversight, SaaS Posture Management, End Protection/Hardware Inventory, and Third-Party Risk Management
• Strong understanding of cybersecurity controls across cloud security, corporate IT security, and identity and access management (IAM). Committed to staying ahead of the curve in the ever-evolving field of cybersecurity
• Proven ability to lead and manage security initiatives and drive complex, cross-functional collaboration efforts without direct authority
• Builds strong relationships with stakeholders across the organization and thrives in a dynamic and rapidly changing environment
• Exceptional written and verbal communication skills, with the ability to translate complex security architecture into clear business risks for non-technical audiences
• A proactive and strategic approach to identifying, mitigating, and documenting risks in a high-growth, fast-paced technology environment
• Experience with scripting (e.g., Python, SQL) or building APIs/integrations to automate evidence collection
• Relevant security certifications such as CISSP, CISM, or CISA
• Experience designing or facilitating training programs (e.g., Compliance Champions) or leading Cyber Tabletop Exercises
• Experience supporting security governance in a remote or hybrid workforce environment

Benefits
• Cash compensation (overtime, bonus/commissions, if eligible)
• Benefits
• Equity (if eligible)

Company Overview
• Toast is a point-of-sale and restaurant management platform designed for businesses in the food service and hospitality industry. It was founded in 2011, and is headquartered in Boston, Massachusetts, USA, with a workforce of 1001-5000 employees. Its website is https://pos.toasttab.com.

Company H1B Sponsorship
• Toast has a track record of offering H1B sponsorships, with 26 in 2025, 32 in 2024, 39 in 2023, 66 in 2022, 29 in 2021, 17 in 2020. Please note that this does not guarantee sponsorship for this specific role.

Apply Now

Apply Now
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Technical Director - (New Game)

Remote Full-time

Provider Relations Recruitment & Retention Representative - Dallas

Remote Full-time

CE Mgr III-Programmatic Activ Social

Remote Full-time

Director, Solution Architecture & Strategy

Remote Full-time

Certified Professional Coder, Special Investigations Unit (Aetna SIU)

Remote Full-time

**Experienced Call Center Customer Service Representative – Delivering Exceptional Service at arenaflex**

Remote Full-time

[Remote-Position] Need Math Instructor and Tutor in Encino, CA

Remote Full-time

AWS Cloud Engineer (Remote) at Mind Computing

Remote Full-time

Sr. Analyst, Falcon Complete (Remote, 3rd Shift)

Remote Full-time

AI-First Product Manager (Ops Transformation)

Remote Full-time
← Back to Home