Simplify Logo

Full-Time

Principal PCI Compliance Analyst

Confirmed live in the last 24 hours

Toast

Toast

5,001-10,000 employees

Technology platform for restaurant operations

Food & Agriculture
Hardware
Consumer Software
Fintech
Financial Services

Compensation Overview

$147k - $235kAnnually

+ Overtime + Bonus + Equity + Benefits

Senior, Expert

Remote in USA

Category
Risk & Compliance
Legal & Compliance
Requirements
  • Experience (8+ years) in Security GRC, IT security, or a related field, with in-depth working knowledge of PCI standards including PCI DSS, preferably inside fast growing companies.
  • A strong understanding of cloud computing architectures and security patterns, including assessing and implementing PCI controls in such environments.
  • High levels of curiosity, persistence, and a grounded approach to getting things done
  • Familiarity with GRC (Governance, Risk, and Compliance) solutions, tools, platforms, and Enterprise Risk Management (ERM) processes.
  • Knowledge of industry security, audit, and privacy standards, frameworks, and regulations, such as PCI DSS (and other PCI standards), ISO27001, COBIT, SSAE18, GDPR, EBA’s ICT, DORA.
  • Relevant industry certifications such as CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager) OR equivalent expertise. QSA certification / experience preferred.
Responsibilities
  • Lead the planning and execution of PCI assessments of the Toast payment solutions and environments, which includes interpreting and assessing controls using compliance frameworks with a focus on payment card compliance and security (e.g. PCI-DSS, PCI-SSF, PTS, PIN Security Requirements, and P2PE).
  • Coordinate with external assessors (QSA / other), process/control owners, and other key internal / external stakeholders to streamline the assessment process for gained efficiencies, including activities related to collecting evidence and refining the relevant runbooks.
  • Own and manage the budget for external assessments including agreeing to fees and tracking.
  • Lead the monitoring of the implementation and validation of any recommended remediations from internal or external assessments.
  • Define and lead activities to support ongoing PCI program health and maturity.
  • Document and maintain cardholder data environment scope narratives and supporting evidence.
  • Monitor business activities by collaborating with cross-functional team leaders to ensure the organization maintains compliance with external certifications.
  • Advise and consult with internal teams on PCI related initiatives and programs, development of a continuous monitoring program and provide general PCI-related support to technical teams.
  • Perform ongoing design and operating effectiveness reviews to identity changes impacting relevant products and infrastructure and work with teams on compliance readiness roadmaps.
  • Manage and respond to customer requests regarding PCI compliance.
  • Create and maintain documentation to support the PCI Management Program.
  • Develop and deliver training on PCI topics to relevant stakeholders.
  • Collaborate with other members of the GRC team on team-wide initiatives.

Toast provides a technology platform tailored for the restaurant industry, offering a variety of products and services that help restaurants improve their operations and customer experiences. The main product is an all-in-one point-of-sale (POS) system that includes features like mobile and online ordering, gift card management, detailed sales reporting, employee management, and customer relationship management (CRM). This integrated approach allows restaurants to minimize their dependence on third-party services, which can lead to cost savings. Unlike many competitors, Toast operates on a subscription model, charging restaurants a recurring fee while also generating revenue through transaction fees and hardware sales. The goal of Toast is to enhance the efficiency and profitability of restaurants, making it easier for them to succeed in a competitive market.

Company Stage

Series F

Total Funding

$1.2B

Headquarters

Boston, Massachusetts

Founded

2011

Growth & Insights
Headcount

6 month growth

2%

1 year growth

6%

2 year growth

35%
Simplify Jobs

Simplify's Take

What believers are saying

  • Toast's innovative solutions, like the Digital Storefront and Marketing Suites, help restaurants attract and retain customers through enhanced digital experiences.
  • The launch of the Restaurant Management Suite and Advanced Restaurant Analytics provides enterprise brands with valuable insights and tools to optimize operations and drive growth.
  • Partnerships with major brands like Caribou Coffee and Choice Hotels demonstrate Toast's ability to secure high-profile clients and expand its market presence.

What critics are saying

  • The competitive landscape in restaurant technology is intense, with rivals like SpotOn continuously enhancing their offerings.
  • Integrating new acquisitions and technologies, such as Delphi Display Systems, may pose operational challenges and require significant resources.

What makes Toast unique

  • Toast offers an all-in-one POS system specifically designed for the restaurant industry, integrating functionalities like mobile ordering, online ordering, and gift card management, unlike generic POS systems.
  • The company's diversified revenue stream, including subscription services, transaction fees, hardware sales, and restaurant loans, provides financial stability and multiple growth avenues.
  • Toast's recent acquisitions and partnerships, such as with Delphi Display Systems and Google, enhance its technological capabilities and market reach.

Benefits

Peer Nominated Toastie Awards

Professional Development Reimbursement Program

Sabbatical

Unlimited Vacation & Flexible Work Hours

Medical, Dental, & Vision Coverage + Wellness Stipend

Commitment to Employee Wellness