
Principal Technical Risk Analyst
Toast · Canada
- Hybrid
- Full-time
- CA$170,500 / year
- Canada
Job highlights
- Lead and mature the technical risk program.
- Own cyber risk lifecycle end-to-end.
- Build and scale risk discovery mechanisms.
- Drive program maturity and transformation.
- Enable governance through risk insights.
About the role
Principal Technical Risk Analyst
Toast creates technology to help restaurants and local businesses succeed in a digital world, helping business owners operate, increase sales, engage customers, and keep employees happy.
We are seeking a Principal Technical Risk Analyst to lead and mature Toast’s Technical Risk Program. This role will report to the Sr. Director of Technical Governance, Risk, & Compliance and is part of the Information Security Organization. This is a high-impact, senior individual contributor role responsible for owning the end-to-end cyber risk management program, including risk identification, assessment, reporting, and integration into enterprise risk and leadership decision-making. This role is not about maintaining a process — it is about building, operationalizing, and leading a program that drives real business decisions and outcomes.
You will partner closely with:
- Enterprise Risk Management (ERM)
- Security Engineering, Infrastructure, and Product teams
- Technical Compliance and Governance teams
- Senior leadership and executive forums
You will play a key role in advancing and scaling our Technical Risk program, further strengthening our data-driven approach to risk management and enabling informed, timely decision-making across the business.
A Day In The Life (Responsibilities)
Own and Lead the Technical Risk Program
- Own the end-to-end cyber risk lifecycle: risk identification, assessment, prioritization, mitigation tracking, and reporting
- Establish and operationalize a scalable risk operating model (risk discovery → intake → assessment → reporting → monitoring)
- Ensure the program operates with a predictable cadence, clear ownership, and strong execution rigor
- Drive adoption of the program across Security, Product, Engineering, and Infrastructure teams
Lead Technical Risk Management Across the Lifecycle
- Lead the end-to-end technical risk management lifecycle through close partnership with cross-functional stakeholders
- Establish and scale risk discovery mechanisms, including: Stakeholder engagement across Engineering, Product, Infrastructure, and Security, Inputs from audits, incidents, assessments, and external signals
- Ensure continuous identification and prioritization of emerging and high-impact risks
- Translate technical issues into clear, business-relevant risk narratives
- Act as a trusted partner and challenger, influencing stakeholders to drive timely risk mitigation and resolution
Drive Risk Program Maturity and Transformation
- Lead the evolution of the technical risk program to support scale, consistency, and improved visibility
- In partnership with ERM, operate within, suggest enhancements to, and manage the following: Risk taxonomy and classification models, Risk assessment and prioritization frameworks, Risk-to-control mapping (linking risks to the controls and a Common Controls Framework)
- Own and evolve the use of Optro (fka AuditBoard) RiskOversight as the system of record
- Improve data quality, reporting capabilities, and workflow scalability
- Operationalize the program within AuditBoard RiskOversight (Optro) as the system of record
- Build scalable processes that enable automation, reporting, and AI use cases
Enable Risk Governance and Decision Making Through Risk Insights
- Develop and deliver clear, executive-ready risk reporting and dashboards
- Manage and lead the Technical Risk Subcommittee and related governance forums: Prepare committee materials to ensure meetings are structured, actionable, and decision-oriented, Clearly articulate risks, impacts, and recommended actions
- Provide leadership with: Visibility into top risks, mitigation plan progress, and trends, Clear trade-offs and prioritization inputs
- Partner with Enterprise Risk Management (ERM) to align on risk taxonomy, reporting, and governance
- Communicate, report, and escalate upward to the Enterprise Risk and Compliance Committee (ERCC)
Core Experience
What you'll need to thrive (Requirements)
- 8–12+ years of experience in Technical Risk, Security GRC, ERM, or related fields
- Proven experience owning and leading a technical/cyber risk program
- Strong understanding of: Cybersecurity domains (cloud, infrastructure, IAM, application security), Risk frameworks (NIST CSF, ISO 27001, etc.)
- Experience operating in high-growth, complex, cloud-based environments
Program Leadership & Execution
- Demonstrated ability to: Build and operationalize programs from 0 → 1 and 1 → scale, Drive predictable execution cadence and rigor, Translate ambiguity into structured, executable plans
- Strong program management discipline (planning, tracking, follow-through)
Risk & Analytical Thinking
- Ability to: Translate technical issues into clear risk narratives and business impact, Prioritize risks based on impact and likelihood, Drive data-informed decision-making
Communication & Influence
- Exceptional communication skills: Executive-ready written and verbal communication, Ability to structure updates: What / So What / Now What / Decision Needed
- Proven ability to influence: Senior stakeholders, Cross-functional teams without direct authority
Tooling & Systems
- Experience with GRC tools such as: Optro (fka AuditBoard-preferred), ServiceNow GRC, Workiva, etc.
- Ability to: Drive tool adoption and configuration, Translate business processes into scalable system workflows
Special Sauce or Bonus Ingredients (Nice-to-Haves)
- Experience integrating technical risk into ERM programs
- Experience building risk dashboards, metrics, and reporting frameworks
- Familiarity with automation, AI, or data-driven GRC approaches
- Relevant certifications (CISSP, CISM, CISA, CRISC)
AI at Toast
At Toast, one of our company values is that we're hungry to build and learn. We believe learning new AI tools empowers us to build for our customers faster, more independently, and with higher quality. We provide these tools across all disciplines, from Engineering and Product to Sales and Support, and are inspired by how our Toasters are already driving real value with them. The people who thrive here are those who embrace changes that let us build more for our customers; it’s a core part of our culture.
Our Total Rewards Philosophy
We strive to provide competitive compensation and benefits programs that help to attract, retain, and motivate the best and brightest people in our industry. Our total rewards package goes beyond great earnings potential and provides the means to a healthy lifestyle with the flexibility to meet Toasters’ changing needs. Learn more about our benefits at https://careers.toasttab.com/toast-benefits.
The base salary range for this role is listed below. The starting salary will be determined based on skills, experience, and geographic location. In addition to base salary, our total rewards components include cash compensation (overtime, bonus/commissions if eligible), equity, and benefits.
Pay Range
$131,000—$210,000 CAD
How Toast Uses AI In Its Hiring Process
Throughout the hiring process, our goal is to get to know you. We use AI tools to support our recruiters and interviewers with tasks like note-taking, summarization, and documentation of interviews to ensure they can be fully focused on your conversation. All hiring decisions are made by people. To learn more: https://careers.toasttab.com/ai-in-hiring
Diversity, Equity, and Inclusion is Baked into our Recipe for Success
At Toast, our employees are our secret ingredient—when they thrive, we thrive. The restaurant industry is one of the most diverse, and we embrace that diversity with authenticity, inclusivity, respect, and humility. By embedding these principles into our culture and design, we create equitable opportunities for all and raise the bar in delivering exceptional experiences.
We Thrive Together
We embrace a hybrid work model that fosters in-person collaboration while valuing individual needs. Our goal is to build a strong culture of connection as we work together to empower the restaurant community. To learn more about how we work globally and regionally, check out: https://careers.toasttab.com/locations-toast.
Apply today!
Toast is committed to creating an accessible and inclusive hiring process. As part of this commitment, we strive to provide reasonable accommodations for persons with disabilities to enable them to access the hiring process. If you need an accommodation to access the job application or interview process, please contact candidateaccommodations@toasttab.com.
For roles in the United States, it is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Skills & topics
- Principal Technical Risk Analyst
- Technical Risk
- Cyber Risk
- GRC
- ERM
- Risk Management
- Information Security
- NIST CSF
- ISO 27001
- Cloud Security
- Risk Assessment
- Risk Reporting
- Program Management
- AuditBoard
- Optro
- CISSP
- CISM
- CISA
- CRISC
- Data-driven Risk
How to get hired
- Tailor your resume: Highlight 8-12+ years in Technical Risk or GRC, emphasizing program ownership and leadership.
- Showcase program building skills: Detail experience in operationalizing and scaling risk programs from inception to maturity.
- Quantify impact: Provide examples of how you translated technical risks into business narratives and drove mitigation.
- Highlight GRC tool proficiency: Mention experience with tools like Optro, ServiceNow GRC, or Workiva.
- Prepare for technical and behavioral interviews: Be ready to discuss risk frameworks, cybersecurity domains, and influencing stakeholders.
Technical preparation
Behavioral questions
Frequently asked questions
- What are the key responsibilities for a Principal Technical Risk Analyst at Toast?
- As a Principal Technical Risk Analyst at Toast, you will own and lead the technical risk program, managing the entire cyber risk lifecycle from identification to reporting. You will also drive program maturity, operationalize risk management processes using tools like Optro, and enable informed decision-making through risk insights and executive reporting.
- What experience is required for the Principal Technical Risk Analyst role at Toast?
- Toast requires 8-12+ years of experience in Technical Risk, Security GRC, ERM, or related fields. You should have proven experience owning and leading a technical/cyber risk program, a strong understanding of cybersecurity domains and risk frameworks (NIST CSF, ISO 27001), and experience in high-growth, complex, cloud-based environments.
- What GRC tools does Toast prefer for the Principal Technical Risk Analyst position?
- Toast prefers candidates with experience in GRC tools such as Optro (formerly AuditBoard). Experience with other similar tools like ServiceNow GRC or Workiva is also valuable.
- How does Toast use AI in its hiring process for the Principal Technical Risk Analyst role?
- Toast uses AI tools to support recruiters and interviewers with tasks like note-taking and summarization to ensure they can focus on the conversation. However, all hiring decisions are made by people. You can learn more about their AI in hiring practices at https://careers.toasttab.com/ai-in-hiring.
- What is the salary range for a Principal Technical Risk Analyst at Toast?
- The base salary range for this role is $131,000—$210,000 CAD. The starting salary will depend on your skills, experience, and geographic location. The total rewards package also includes cash compensation, equity, and benefits.
- What is the work arrangement for this Principal Technical Risk Analyst position at Toast?
- Toast embraces a hybrid work model that fosters in-person collaboration while valuing individual needs, aiming to build a strong culture of connection. More information on their work model can be found at https://careers.toasttab.com/locations-toast.
- What are the desired certifications for a Principal Technical Risk Analyst at Toast?
- While not strictly required, relevant certifications like CISSP, CISM, CISA, or CRISC are considered a bonus and can enhance your application for the Principal Technical Risk Analyst role at Toast.