Senior Corporate Security Engineer
Job Summary
Toast creates technology to help restaurants and local businesses succeed in a digital world helping business owners operate increase sales engage customers and keep employees happy.
Toast is seeking a Senior Security Engineer to design implement and operate enterprise Data Loss Prevention and Secure Access Service Edge capabilities. The role will reduce data exfiltration risk enable secure access to web SaaS private applications and cloud services and improve security coverage.
You will be a senior individual contributor and subject matter expert within the Enterprise Security team and will closely partner with IT Network Engineering Legal Privacy Compliance and application owners. Success requires hands-on engineering design operational ownership and clear risk communication.
A day in the life (Responsibilities)
- Own the DLP engineering roadmap and control lifecycle from requirements and architecture through proof of concept testing phased deployment tuning operations and continuous improvement.
- Design and operate controls for sensitive data across managed endpoints email web and network channels SaaS and collaboration applications cloud environments and data repositories.
- Build and maintain data discovery and classification logic using sensitive information types regular expressions data matching document fingerprinting OCR and machine learning where appropriate.
- Translate requirements into precise policies and response actions with documented exceptions.
- Establish safe policy rollout practices with test cases pilot groups change control user impact analysis exception review and measurable acceptance criteria.
- Triage and investigate DLP alerts and incidents determine root cause and business context coordinate containment and remediation and reduce false positives without weakening protection.
- Integrate DLP with SASE services SIEM/SOAR platforms MDM ticketing systems data classification data security posture management and relevant response workflows.
- Define dashboards and metrics for coverage control effectiveness detection precision recurring exfiltration paths policy exceptions incident volume and time to resolution.
- Engineer and operate scalable SASE capabilities for corporate fleet SaaS private apps and cloud environments.
- Configure and optimize core capabilities including secure web gateway cloud access security broker zero trust network access firewall as a service DNS security remote browser isolation DLP digital experience monitoring and SD-WAN or SSE integrations.
- Manage traffic steering and connectivity patterns such as endpoint clients browser or proxy configurations private application connectors IPsec or GRE tunnels and branch or cloud on ramps.
- Lead phased migrations from legacy VPN proxy and perimeter security solutions while maintaining service continuity policy consistency and a reliable end-user experience.
- Create context-aware access and data protection policies using device posture application risk destination data sensitivity and session risk signals.
- Develop TLS inspection standards certificate deployment practices bypass criteria privacy safeguards and documented exception processes in partnership with relevant stakeholders.
- Monitor availability latency tunnel and connector health service edge performance and policy impact; troubleshoot access and application performance issues across endpoint network and cloud layers.
- Design for resilience through regional failover redundant connectivity configuration standards observability tested recovery procedures and controlled automation.
What youll need to thrive (Requirements)
- Education: Bachelors degree in Engineering Cybersecurity or equivalent practical experience.
- Experience: 7 years of experience including substantial hands-on responsibility in enterprise security engineering environments.
- DLP engineering: Ability to architect deploy tune and operate at least one major enterprise DLP platform with strong knowledge of data discovery classification content inspection endpoint controls cloud and SaaS coverage policy actions exceptions investigations and metrics.
- SASE engineering: Ability to design implement migrate and operate at least one major SASE/SSE platform. Practical knowledge of SWG CASB ZTNA FWaaS traffic steering TLS inspection connectors and performance.
- Vulnerability management: Experience assessing prioritizing tracking and validating remediations
- Developer and automation mindset: skills in Python or a comparable language. Working knowledge with REST APIs automation platforms and AI-assisted dev tools such as Claude Copilot Codex or similar.
- Communication: Excellent communication skills and sound judgment.
- Education: Masters in Computer Science Cybersecurity Information Security or a related discipline.
- Security operations integrations: Experience integrating security controls with platforms such as Splunk Datadog Torq Palo Alto Cortex XSOAR or comparable observability and automation tooling.
- AI security and automation: Experience applying AI to improve security detection policy engineering investigation or operational efficiency and familiarity with controls for enterprise generative AI usage.
- Security frameworks: Working knowledge of NIST Cybersecurity Framework CIS Controls and zero trust principles with the ability to translate requirements into operational controls.
- Governance platforms: Familiarity with ServiceNow GRC Optro or similar governance platforms.
- Certifications: CISSP CISM CCSP Security Network cloud security or SASE/DLP vendor certifications.
AI at Toast
At Toast one of our company values is that were hungry to build and learn. We believe learning new AI tools empowers us to build for our customers faster more independently and with higher quality. We provide these tools across all disciplines from Engineering and Product to Sales and Support and are inspired by how our Toasters are already driving real value with them. The people who thrive here are those who embrace changes that let us build more for our customers; its a core part of our culture.
Our Total Rewards Philosophy
We strive to provide competitive compensation and benefits programs that help to attract retain and motivate the best and brightest people in our industry. Our total rewards package goes beyond great earnings potential and provides the means to a healthy lifestyle with the flexibility to meet Toasters changing needs. Learn more about our benefits at Toast Uses AI in its Hiring Process
Throughout the hiring process our goal is to get to know you. We use AI tools to support our recruiters and interviewers with tasks like note-taking summarization and documentation of interviews to ensure they can be fully focused on your conversation. All hiring decisions are made by people. We ask that you complete interviews and assessments on your own without real-time AI tools recording or transcription bots unless we tell you otherwise in advance. To learn more: Approach to Hybrid Working
We embrace a hybrid work model that fosters in-person collaboration while valuing individual needs. Our goal is to build a strong culture of connection as we work together to empower the hospitality community regardless of location. Please visit the Locations page on our career site to learn more about our in-office expectations by region: Are the Secret Ingredient in Our Recipe for Success
At Toast our employees are our secret ingredientwhen they thrive we thrive. The restaurant industry brings together people with a wide range of backgrounds experiences and perspectives and we value that same breadth at Toast. We strive to build a culture grounded in authenticity respect and humility where every Toaster has a real opportunity to grow contribute and do their best workraising the bar in delivering exceptional experiences for our customers and each other.
Apply today!
Toast is committed to creating an accessible and inclusive hiring process. As part of this commitment we strive to provide reasonable accommodations for persons with disabilities to enable them to access the hiring process. If you need an accommodation to access the job application or interview process please contact .
------
For roles in the United States it is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Required Experience:
Senior IC
About Company
Toast is a restaurant point of sale and management system that helps restaurants improve operations, increase sales and create a better guest experience.