Senior Director, Product and Platform Security

Toast · Remote, United States

  • Senior
  • Full-time
  • $275,000 – $440,000
  • Posted 2026-09-24
  • Confirmed live on 25 September 2026

Apply at Toast

Job description

Toast creates technology to help restaurants and local businesses succeed in a digital world, helping business owners operate, increase sales, engage customers, and keep employees happy.

Toast's platform runs restaurants: the cloud software, the payments, and the hardware on the counter. Keeping it safe is an engineering problem, and we treat it that way. Instead of reviewing what our teams build after the fact, we embed security engineers alongside developers and build paved roads to deliver secure defaults that teams pick up without asking permission.

You'll lead that work as a flagship hire in Toast's new Trust & Security organization — a deliberate shift from a compliance-led, reactive security function toward one that's engineering-led and proactive. Reporting directly to the CISO, you'll be accountable for the security of the product end to end, owning the R&D relationship directly. You'll inherit an existing team of security engineers already doing this work, with plans to grow the team further as scope expands.

This is not a compliance or audit-oriented role, and not a pure individual-contributor architect seat. You'll be leading and growing a team that already has engineering's attention — not selling security to a skeptical organization from scratch. If your instinct is to review and approve rather than to build and embed, this isn't the right seat.

A day in the life (Responsibilities)

• Enable the Business to Lead with Security: Work closely with our product and engineering leaders to transform how security is built into our product portfolio, leveraging AI, automation, and innovation to enable both fast and secure capabilities to be delivered to our customers

• Lead Security Platform Engineering: Own the shared services, guardrails, and secure defaults that make the safe path the easy path for every product team; consolidate overlapping tooling into a coherent, self-service set of guardrails

• Drive Application & Cloud Security: Run our AppSec and CloudSec programs, secure development lifecycle, threat modeling, and software supply chain integrity; maintain a single owned view of product and cloud security posture with vulnerability SLAs met

• Build Developer Enablement: Grow embedding, tooling adoption, training, and a security champions network that extends the team's reach; enable paved roads with our highest-leverage R&D teams so engineering leaders describe security as a partner rather than a blocker

• Run Offensive Security & Vulnerability Management: Lead red team and penetration testing in a purple-team rhythm with detection engineering, and decide what gets fixed first; establish a working purple-team cadence with the detection function

• Own Hardware Security: Extend platform security practices into hardware as part of the broader product security remit

• Lead and Grow the Team: Lead the existing security engineering team, developing them and shaping how the function operates; identify and hire additional senior security engineers as scope and priorities expand

What you'll need to thrive (Requirements)

• You've run a multi-team security engineering organization, rather than a single-team application security queue.

• Depth in cloud-native security: infrastructure as code, CI/CD pipeline security, containers, and microservices.

• You've shifted security left through self-service and paved roads, and you can show that developer friction went down while coverage went up.

• Senior engineering leaders have treated you as a peer. You've changed how a product organization builds, not just flagged what it built wrong.

• Judgment about where to automate, where to embed, and where to hold a line.

• A background in engineering or software development rather than traditional audit or consulting, ideally from a modern SaaS or cloud-native company rather than a heavily regulated, policy-driven environment.

What will help you stand out (Nonessential Skills/Nice to Haves)

• A view on securing AI in a product.

• Experience and judgment negotiating compromise with engineering teams in difficult situations, without losing ground on the things that matter.

• Fintech background — helpful, though more relevant to other roles on the Trust & Security team than this one.

AI at Toast

At Toast, one of our company values is that we're hungry to build and learn. We believe learning new AI tools empowers us to build for our customers faster, more independently, and with higher quality. We provide these tools across all disciplines, from Engineering and Product to Sales and Support, and are inspired by how our Toasters are already driving real value with them. The people who thrive here are those who embrace changes that let us build more for our customers; it’s a core part of our culture.

Our Total Rewards Philosophy

We strive to provide competitive compensation and benefits programs that help to attract, retain, and motivate the best and brightest people in our industry. Our total

Interview problems reported for Toast

Reported by candidates and public write-ups, not by Toast. Practise each one here:

More at Toast

All open software jobs