Director, Security Assurance and Compliance
- Company
- Toast
- Location
- Remote - United States
- Work type
- Full Time
- Posted
- 2026-09-29
Job description
This role represents a strategic shift toward engineered, proactive compliance where trust is continuously measured rather than only periodically asserted in documents. Operating as an independent second line of defense, you will balance rigorous assurance with engineering pragmatism, maintaining the autonomy to assess internal teams while helping them scale through automation.
The position spans both internal transformation and external accountability. Internally, you will drive continuous controls monitoring and risk governance; externally, you will own the evidence base that powers our customer trust surface and sales enablement efforts.
A day in the life (Responsibilities)
Drive Engineered Compliance: Build and own continuous controls monitoring, automated evidence collection, and compliance-as-code initiatives so controls are tested once and reused seamlessly across multiple frameworks and certifications.
Lead Enterprise Risk & Continuity Governance: Manage overall organizational security risk, third-party and vendor risk, alongside business continuity and disaster recovery governance.
Own the Assurance Evidence Base: Maintain and safeguard the independent evidence base underlying our Trust Center and customer security reviews, ensuring absolute integrity while partnering with Customer Trust teams on delivery.
Serve as Second Line of Defense: Act as an independent reviewer with the standing and authority to challenge engineering and operational teams, ensuring objective assessment across all security domains.
Evolve Team Capabilities: Mentor and upskill the security compliance organization, driving a successful cultural and technical transition from manual auditing to automated compliance engineering.
What you'll need to thrive (Requirements)
Proven Transformation Leadership: Experience leading a security assurance or risk transformation program rather than solely maintaining a steady-state compliance function.
Deep Framework Expertise: Strong technical command of major regulatory and security frameworks including PCI, SOC, SOX, and ISO.
Hands-on Automation Track Record: Demonstrated success implementing automated controls and continuous evidence collection while upskilling existing team members through the shift.
Technical & Pragmatic Mindset: Ability to balance regulatory rigor with engineering constraints, holding your own in deep technical conversations with engineers.
People Management Experience: Proven track record leading a team of security, risk, or compliance professionals.
What will help you stand out (Nonessential Skills/Nice to Haves)
Background in payments, fintech, or another highly regulated platform business.
Direct experience operating within a two-lines-of-defense governance structure.
Experience scaling automated compliance architecture within fast-growing cloud environments.
Zone A
$204,000—$326,000 USD
Zone B
$177,000—$283,000 USD
Zone C
$159,000—$254,000 USD