toast
Boston · On-site · Full-time
<p>Toast creates technology to help restaurants and local businesses succeed in a digital world, helping business owners operate, increase sales, engage customers, and keep employees happy.</p> <p>Toast's platform runs restaurants: the cloud software, the payments, and the hardware on the counter. Keeping it safe is an engineering problem, and we treat it that way. Instead of reviewing what our teams build after the fact, we embed security engineers alongside developers and build paved roads to deliver secure defaults that teams pick up without asking permission.</p> <p>You'll lead that work as a flagship hire in Toast's new Trust & Security organization — a deliberate shift from a compliance-led, reactive security function toward one that's engineering-led and proactive. Reporting directly to the CISO, you'll be accountable for the security of the product end to end, owning the R&D relationship directly. You'll inherit an existing team of security engineers already doing this work, with plans to grow the team further as scope expands.</p> <p><em>This is not a compliance or audit-oriented role, and not a pure individual-contributor architect seat. You'll be leading and growing a team that already has engineering's attention — not selling security to a skeptical organization from scratch. If your instinct is to review and approve rather than to build and embed, this isn't the right seat.</em></p> <p> </p> <p><strong>A day in the life (Responsibilities) </strong></p> <ul> <li><strong>Enable the Business to Lead with Security:</strong> Work closely with our product and engineering leaders to transform how security is built into our product portfolio, leveraging AI, automation, and innovation to enable both fast and secure capabilities to be delivered to our customers</li> <li><strong>Lead Security Platform Engineering: </strong>Own the shared services, guardrails, and secure defaults that make the safe path the easy path for every product team; consolidate overlapping tooling into a coherent, self-service set of guardrails</li> <li><strong>Drive Application & Cloud Security: </strong>Run our AppSec and CloudSec programs, secure development lifecycle, threat modeling, and software supply chain integrity; maintain a single owned view of product and cloud security posture with vulnerability SLAs met</li> <li><strong>Build Developer Enablement: </strong>Grow embedding, tooling adoption, training, and a security champions network that extends the team's reach; enable paved roads with our highest-leverage R&D teams so engineering leaders describe security as a partner rather than a blocker</li> <li><strong>Run Offensive Security & Vulnerability Manageme
toast
Posted via Greenhouse_public
Apply Now takes you to Rozgoo, where auto-apply can submit your application for this role. Updated today.
Apply Now