Principal Technical Risk Analyst

Toast Toast · Enterprise · USA, Canada · Remote · R & D : Security : Technical Compliance

This Principal Technical Risk Analyst role at Toast focuses on leading and maturing the company's Technical Risk Program within the Information Security Organization. The individual will own the end-to-end cyber risk management lifecycle, including identification, assessment, reporting, and mitigation tracking. Key responsibilities include establishing and operationalizing a scalable risk operating model, driving adoption across teams, and enabling risk governance through insights. The role emphasizes building, operationalizing, and leading a program that influences business decisions, with a focus on improving data quality, reporting, and workflow scalability, including the potential for AI use cases. While the role is within an AI-aware company and mentions AI use cases, its core function is technical risk management, not direct AI/ML model development or deployment.

What you'd actually do

  1. Own the end-to-end cyber risk lifecycle: risk identification, assessment, prioritization, mitigation tracking, and reporting
  2. Establish and operationalize a scalable risk operating model (risk discovery → intake → assessment → reporting → monitoring)
  3. Drive adoption of the program across Security, Product, Engineering, and Infrastructure teams
  4. Lead the end-to-end technical risk management lifecycle through close partnership with cross-functional stakeholders
  5. Develop and deliver clear, executive-ready risk reporting and dashboards

Skills

Required

  • 8–12+ years of experience in Technical Risk, Security GRC, ERM, or related fields
  • Proven experience owning and leading a technical/cyber risk program
  • Strong understanding of risk management principles
  • Experience operating in high-growth, complex, cloud-based environments
  • Demonstrated ability to lead and influence cross-functional teams
  • Strong program management discipline (planning, tracking, follow-through)
  • Ability to translate technical issues into clear, business-relevant risk narratives
  • Exceptional communication skills
  • Proven ability to influence stakeholders
  • Experience with GRC tools such as Optro (fka AuditBoard)

Nice to have

  • Experience integrating technical risk into ERM programs
  • Experience building risk dashboards, metrics, and reporting frameworks
  • Familiarity with automation, AI, or data-driven GRC approaches
  • Relevant certifications (CISSP, CISM, CISA, CRISC)

What the JD emphasized

  • building, operationalizing, and leading a program that drives real business decisions and outcomes
  • scaling our Technical Risk program
  • data-driven approach to risk management
  • Build scalable processes that enable automation, reporting, and AI use cases