Lead Technical Governance Analyst

Toast Toast · Enterprise · United States · Remote · R & D : Security : Technical Compliance

This role is focused on designing and driving the foundational architecture of a GRC (Governance, Risk, and Compliance) program, including frameworks, systems, and transformation programs. It involves supporting security initiatives, collaborating with IT and Security teams, and ensuring the security of sensitive data and critical infrastructure. The role requires expertise in GRC platforms, policy architecture, and cybersecurity controls, as well as leadership and collaboration skills.

What you'd actually do

  1. Drive Security and Technical Governance Risk and Compliance Initiatives
  2. Collaborate with IT and Security
  3. Promote Security Culture

Skills

Required

  • 8+ Years of progressive experience in Information Security GRC, Audit, or Technical Program Management
  • Hands-on experience designing and operationalizing a Common Controls Framework (CCF)
  • Proven experience serving as an Administrator, Architect, or primary owner of a modern GRC tool
  • Expert ability to define, manage, and enforce a clear hierarchy of governance documentation
  • Demonstrated ability to drive the lifecycle of complex security initiatives
  • Strong understanding of cybersecurity controls across cloud security, corporate IT security, and identity and access management (IAM)
  • Proven ability to lead and manage security initiatives and drive complex, cross-functional collaboration efforts without direct authority
  • Exceptional written and verbal communication skills

Nice to have

  • Experience with scripting (e.g., Python, SQL) or building APIs/integrations to automate evidence collection
  • Relevant security certifications such as CISSP, CISM, or CISA
  • Experience designing or facilitating training programs
  • Experience supporting security governance in a remote or hybrid workforce environment

What the JD emphasized

  • designing and driving the foundational architecture
  • Common Controls Framework (CCF)
  • GRC Platform Mastery
  • Policy Architecture
  • Data Governance Oversight
  • SaaS Posture Management
  • End Protection/Hardware Inventory
  • Third-Party Risk Management
  • lead and manage security initiatives
  • translate complex security architecture into clear business risks