Senior Corporate Security Analyst

Toast Toast · Enterprise · Bangalore, India · R & D : Security : Cybersecurity

This role is for a Senior Corporate Security Analyst at Toast, focusing on hands-on execution and risk reduction across endpoints, identities, SaaS, vendors, and data. The candidate will own corporate security programs, partner with various teams, and mentor junior analysts. While the role is not AI-centric, it requires experience with AI tools for security functions and familiarity with various security platforms.

What you'd actually do

  1. Own and operate key corporate security controls across endpoint, SaaS, identity, vendor, and data security.
  2. Perform security risk assessments for business initiatives and translate findings into actionable remediation plans.
  3. Lead day-to-day security oversight for corporate endpoints and SaaS applications, including: EDR/XDR, device hardening, encryption, MDM/UEM
  4. Drive vulnerability management for corporate endpoints and internal business systems.
  5. Support enterprise IAM governance, including: Joiner / mover / leaver processes

Skills

Required

  • 6–10 years of experience in information security with strong corporate security exposure.
  • Endpoint security and EDR tools (e.g., CrowdStrike)
  • Vendor security assessments and SOC 2 reviews
  • IAM concepts (Okta, PAM, access reviews)
  • SaaS and Shadow IT security
  • Strong understanding of security frameworks (NIST CSF, ISO 27001, CIS Controls).
  • Experience working closely with IT and governance teams.
  • Strong written and verbal communication skills.

Nice to have

  • Experience with Google Workspace security and DLP.
  • Exposure to GRC processes or platforms (ServiceNow GRC, OneTrust).
  • Bachelor's degree in Computer Science, Information Security, or a related field; Master's degree preferred.
  • Proven experience in developing and implementing security policies, procedures, and frameworks.
  • Demonstrated experience in developing and delivering security awareness training and phishing exercises.
  • Possess excellent skills and experience in leveraging AI tools for threat detection, incident response, vulnerability management, and other security functions.
  • Familiarity with Google Workspace security features.
  • Proficiency with security tools such as Reco.AI, Torq, Splunk, DataDog, bug bounty platforms, Okta Device Trust, BeyondTrust, BeyondCorp, and other SIEM, SOAR and Security tools commonly used in the market.
  • Ability to work autonomously and prioritize multiple tasks in a fast-paced environment.
  • Excellent verbal and written communication skills, with the ability to effectively communicate technical information to both technical and non-technical audiences.
  • Proven ability to collaborate effectively with cross-functional teams.
  • Quick learner and adaptable to new security tools and technologies as they are procured and implemented.
  • Ability to adapt to environments, understand requirements, and actively collaborate within the team, with other teams, and with vendors.
  • Provide technical guidance and mentorship to P2 security analysts, fostering their professional growth and ensuring alignment with corporate security objectives.
  • Take initiative in leading security programs.

What the JD emphasized

  • strong experience working in enterprise corporate security environments
  • strong corporate security exposure
  • Hands-on experience with: Endpoint security and EDR tools
  • Hands-on experience with: Vendor security assessments and SOC 2 reviews
  • Hands-on experience with: IAM concepts (Okta, PAM, access reviews)
  • Hands-on experience with: SaaS and Shadow IT security
  • Strong understanding of security frameworks (NIST CSF, ISO 27001, CIS Controls)
  • Experience working closely with IT and governance teams
  • Possess excellent skills and experience in leveraging AI tools for threat detection, incident response, vulnerability management, and other security functions.