Senior Technical Compliance Analyst

Sorry, this job was removed Sorry, this job was removed at 02:45 a.m. (CST) on Friday, Mar 21, 2025
Hiring Remotely in USA
Remote
127K-203K Annually
Cloud • Fintech • Food • Information Technology • Software • Hospitality
We empower the restaurant community to delight guests, do what they love, and thrive.
The Role

Toast is driven by building the restaurant platform that helps restaurants adapt, take control, and get back to what they do best: building the businesses they love.

The Technical Governance, Risk and Compliance (Technical GRC) team enables the growth of Toast as we build secure products and enter new markets while meeting industry and regulatory requirements. Our team is a second-line function, providing oversight and leadership to first-line teams designed for high-velocity product innovation and development.

We are currently seeking a Senior Analyst for Technical Compliance who will be responsible for overseeing and supporting many aspects of Toast's PCI Compliance Program. In this role, you will collaborate with our Principal PCI Compliance Analyst and various teams throughout Toast, including Product, Infrastructure Engineering, IT Security, Developers, Legal, and Merchant Risk to ensure our products and processes are following PCI standards. 

The successful candidate will report directly to the Senior Director of Technical Compliance who is responsible for establishing and maintaining compliance programs across Toast globally.


About this roll* (Responsibilities) 

Audit / Assessment Management 

  • Direct and support the planning and execution of PCI assessments of Toast payment solutions and environments, which includes interpreting and assessing controls using compliance frameworks with a focus on payment card compliance and security (e.g. PCI DSS, PCI SSF, PTS, MPoC, PIN, P2PE).
  • Coordinate with external assessors (QSA, QPA, other), process/control owners, and other key internal / external stakeholders to streamline the assessment process for gained efficiencies, including activities related to collecting and reviewing evidence and refining the relevant runbooks. 
  • Support the monitoring of the implementation and validation of any recommended remediations from internal or external assessments. 

Readiness and other compliance support activities may include:

  • Actively support ongoing PCI program health and maturity.
  • Document and maintain cardholder data environment scope narratives, controls and supporting evidence.
  • Monitor business activities by collaborating with cross-functional team leaders to ensure the organization maintains compliance with external certifications.
  • Evaluate current and evolving processes and technical controls to identify compliance gaps against  one or more security frameworks, and produce actionable feedback for stakeholder review and remediation.
  • Advise and consult with internal teams on PCI-related initiatives and programs, development of a continuous monitoring program and provide general PCI-related support to technical teams.
  • Perform ongoing design and operating effectiveness reviews to identity changes impacting relevant products and infrastructure and work with teams on compliance readiness roadmaps. 
  • Manage and respond to customer requests regarding PCI compliance.
  • Create and maintain documentation to support the PCI Management Program.
  • Develop and deliver training on PCI topics to relevant stakeholders.
  • Collaborate with other members of the GRC team on team-wide initiatives.

Do you have the right ingredients*? (Requirements)

  • Experience (5-7+ years) in Security GRC, IT security, or a related field, with in-depth working knowledge of PCI standards including PCI DSS, preferably inside fast growing companies.
  • Understanding of cloud computing architectures and security patterns, including assessing and implementing PCI controls in such environments. 
  • High levels of curiosity, persistence, and a grounded approach to getting things done
  • Familiarity with GRC (Governance, Risk, and Compliance) solutions, tools, platforms, and Enterprise Risk Management (ERM) processes
  • Knowledge of industry security, audit, and privacy standards, frameworks, and regulations, such as PCI DSS (and other PCI standards), ISO27001, etc. 
  • Relevant industry certifications such as CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager) OR equivalent expertise. QSA / ISA certification / experience preferred.


Bonus ingredients:

  • Experience working with GRC tools such as AuditBoard
  • Experience working with Atlassian tools, including Jira, Confluence, and Atlas
  • Working knowledge and familiarity with enterprise risk management, GDPR, EBA ICT, DORA, SOX, COBIT, SOC/SSAE18
  • Experience working in fintech, payment facilitation / marketplace, merchant processing and/or fraud/risk


Our Spread* of Total Rewards
We strive to provide competitive compensation and benefits programs that help to attract, retain, and motivate the best and brightest people in our industry. Our total rewards package goes beyond great earnings potential and provides the means to a healthy lifestyle with the flexibility to meet Toasters’ changing needs. Learn more about our benefits at https://careers.toasttab.com/toast-benefits.

*Bread puns encouraged but not required

The starting pay rate for this role is below. Please note, there is not a range for this role, the number listed below is the rate.

Pay Rate

$127,000$203,000 USD


We are Toasters

Diversity, Equity, and Inclusion is Baked into our Recipe for Success.

At Toast our employees are our secret ingredient. When they are powered to succeed, Toast succeeds.

The restaurant industry is one of the most diverse industries. We embrace and are excited by this diversity, believing that only through authenticity, inclusivity, high standards of respect and trust, and leading with humility will we be able to achieve our goals.

Baking inclusive principles into our company and diversity into our design provides equitable opportunities for all and enhances our ability to be first in class in all aspects of our industry.

Bready* to make a change? Apply today!

Toast is committed to creating an accessible and inclusive hiring process. As part of this commitment, we strive to provide reasonable accommodations for persons with disabilities to enable them to access the hiring process. If you need an accommodation to access the job application or interview process, please contact candidateaccommodations@toasttab.com.

What the Team is Saying

Person1
Christopher
Senior Onboarding Consultant, E-Commerce
“I love working at Toast for various reasons. Toast is inclusive and always focused on my career growth. Also, working with restaurant owners and them telling you that you’ve made their dreams come true- words cannot explain that feeling. I love it here. “
Christopher
Srishti
JJ
Eden
Jane
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
5,000 Employees
Hybrid Workplace
Year Founded: 2011

What We Do

Toast is the all-in-one platform built for restaurants of all sizes. Toast provides a single platform of software as a service (SaaS) products and financial technology solutions that give restaurants everything they need to run their business, including point of sale, payments, supplier management, digital ordering and delivery, marketing and loyalty, and team management. By serving as the restaurant operating system across dine-in, takeout, and delivery channels, Toast helps restaurants increase revenue, streamline operations and deliver amazing guest experiences.

Why Work With Us

Our recipe for an awesome workplace:

One splash of friendship
A dollop of impact
A sprinkle of no hierarchy &
A heavy spoonful of individuality

Mix these ingredients in a fast-paced and hardworking environment. Best paired with a side of interesting people who always bring their whole selves to work.

*100% Sunday scary free

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Toast Teams

Team
Engineering
Team
Sales
About our Teams

Toast Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Flexible
Company Office Image
HQBoston, MA
Company Office Image
Bengaluru, IN
Company Office Image
Chennai, IN
Chicago, IL
Company Office Image
Dublin, IE
Company Office Image
Lublin, PL
Company Office Image
Omaha, NE
Company Office Image
San Francisco, CA
Learn more

Similar Jobs

Toast Logo Toast

Product Marketing Manager, Commerce

Cloud • Fintech • Food • Information Technology • Software • Hospitality
Remote
US
5000 Employees
115K-184K Annually

Toast Logo Toast

Senior Software Engineer, Android

Cloud • Fintech • Food • Information Technology • Software • Hospitality
Remote
US
5000 Employees
131K-210K Annually

Toast Logo Toast

Senior Revenue Accountant

Cloud • Fintech • Food • Information Technology • Software • Hospitality
Remote
United States
5000 Employees
81K-130K Annually

Toast Logo Toast

Staff Software Engineer, Device Experience

Cloud • Fintech • Food • Information Technology • Software • Hospitality
Remote
2 Locations
5000 Employees
150K-240K Annually
By clicking Apply you agree to share your profile information with the hiring company.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account