Principal Technical Risk Analyst

Toast Toast · Enterprise · USA, Canada · Remote · R & D : Security : Technical Compliance

This role leads and matures Toast’s Technical Risk Program, focusing on end-to-end cyber risk management, including identification, assessment, reporting, and integration into enterprise risk. It involves building and operationalizing a scalable risk operating model, driving adoption across teams, and enabling risk governance through insights. The role requires strong program management, analytical thinking, and communication skills, with experience in GRC tools and a data-driven approach to risk. While the role mentions enabling 'AI use cases' within the risk program and 'data-driven GRC approaches' as a nice-to-have, the core function is technical risk management, not direct AI/ML model development or deployment.

What you'd actually do

  1. Own the end-to-end cyber risk lifecycle: risk identification, assessment, prioritization, mitigation tracking, and reporting
  2. Establish and operationalize a scalable risk operating model (risk discovery → intake → assessment → reporting → monitoring)
  3. Drive adoption of the program across Security, Product, Engineering, and Infrastructure teams
  4. Lead the end-to-end technical risk management lifecycle through close partnership with cross-functional stakeholders
  5. Develop and deliver clear, executive-ready risk reporting and dashboards

Skills

Required

  • 8–12+ years of experience in Technical Risk, Security GRC, ERM, or related fields
  • Proven experience owning and leading a technical/cyber risk program
  • Strong understanding of risk management principles
  • Experience operating in high-growth, complex, cloud-based environments
  • Demonstrated ability to lead and influence cross-functional teams
  • Strong program management discipline (planning, tracking, follow-through)
  • Ability to translate technical issues into clear, business-relevant risk narratives
  • Exceptional communication skills
  • Proven ability to influence stakeholders
  • Experience with GRC tools

Nice to have

  • Experience integrating technical risk into ERM programs
  • Experience building risk dashboards, metrics, and reporting frameworks
  • Familiarity with automation, AI, or data-driven GRC approaches
  • Relevant certifications (CISSP, CISM, CISA, CRISC)

What the JD emphasized

  • building, operationalizing, and leading a program
  • scalable risk operating model
  • strong execution rigor
  • continuous identification and prioritization of emerging and high-impact risks
  • data-driven approach to risk management
  • AI use cases
  • data-driven GRC approaches