Staff Security Engineer (Product Security & IAM)

Posted 4 Hours Ago
Be an Early Applicant
Dublin
Senior level
Cloud • Fintech • Food • Information Technology • Software • Hospitality
We empower the restaurant community to delight guests, do what they love, and thrive.
The Role
The Staff Security Engineer will enhance application security with a focus on identity and access management (IAM) by identifying vulnerabilities, guiding remediation, and improving developer tools. Responsibilities include supporting incident response, building threat models, and providing security guidance to teams.
Summary Generated by Built In

Toast is driven by building the restaurant platform that helps restaurants adapt, take control, and get back to what they do best: building the businesses they love.

Product Security at Toast isn't just about running tools and reporting vulnerabilities – we're the vigilant chefs ensuring the Toast never gets burned. We bake security into every layer of our products, from the first sprinkle of an idea to the final serving of a fully-baked solution. Our team is the secret ingredient that makes Toast's digital recipe both delicious and secure. We collaborate closely with R&D, seasoning the development process with robust security measures that protect the services and applications our customers rely on to run their businesses. 

Like master chefs, we blend cutting-edge technology with strategic thinking, kneading security into the dough of every product we create. By joining our Product Security team, you'll be part of the kitchen crew that keeps our customers' trust from going stale. You'll tackle complex challenges that have real-world impact, helping to serve up a safer, more secure digital experience for businesses that count on Toast every day. It's not just about finding vulnerabilities – it's about crafting a recipe for digital trust that keeps our customers coming back for more.

About this roll (Responsibilities)

  • Identify, triage, and provide remediation guidance for application vulnerabilities, with a specific focus on IAM-related issues.
  • Select, implement, design, or build tools to manage and secure identity and access across Toast platforms.
  • Improve developer tooling and adoption to build a more robust SSDLC with respect to IAM best practices.
  • Practice a #OneTeam attitude to help other Toast teams make informed, security-conscious decisions when building new software with IAM considerations.
  • Support and expand the Security Champions program, providing IAM-specific training and guidance.
  • Assist incident response teams with application security expertise and tools, especially related to IAM incidents.
  • Build threat models on IAM applications and architecture.
  • Guide in the design and maintenance of secure authentication and authorization mechanisms.
  • Provide signals for IAM events to the SOC for better alerting and response.

Do you have the right ingredients? (Requirements)

  • Minimum 5+ years of experience in application security
  • Experience reading, reviewing, and providing security guidance for complex code in a variety of languages and frameworks (Java/Kotlin, Javascript/ES6, React, and Python are a priority), with a strong emphasis on IAM implementations.
  • Strong understanding of cloud application architecture and common IAM weaknesses (e.g., insecure authentication, authorization flaws, privilege escalation).
  • Experience identifying and helping to resolve common application security flaws (e.g., OWASP, SANS) related to IAM.
  • Successful history of being a subject matter expert to guide products and lines of business to better security outcomes related to IAM.
  • Previous security experience working with fintech applications and associated IAM requirements.
  • Strong understanding of privacy, security, and cryptography patterns and when to apply them, especially within IAM (such as PKIs, access management, data tokenization, and anonymization).
  • Deep understanding of IAM concepts (e.g., OAuth, OIDC, SAML).

Special Sauce (Nonessential Skills/Nice to Haves)*

  • Cloud and container security technologies.
  • SSDLC tooling (e.g., SAST/DAST/SCA), particularly those focused on IAM.
  • AWS IAM.
  • Infrastructure-as-code (IaC) technologies like Terraform to manage cloud security services.
  • Mobile apps/threats (iOS, Android), and their related IAM challenges.
  • Securing financial technologies and associated IAM requirements.
  • Directory services (e.g., LDAP, Active Directory).

Our Spread* of Total Rewards
We strive to provide competitive compensation and benefits programs that help to attract, retain, and motivate the best and brightest people in our industry. Our total rewards package goes beyond great earnings potential and provides the means to a healthy lifestyle with the flexibility to meet Toasters’ changing needs. Learn more about our benefits at https://careers.toasttab.com/toast-benefits.

*Bread puns encouraged but not required


We are Toasters

Diversity, Equity, and Inclusion is Baked into our Recipe for Success.

At Toast our employees are our secret ingredient. When they are powered to succeed, Toast succeeds.

The restaurant industry is one of the most diverse industries. We embrace and are excited by this diversity, believing that only through authenticity, inclusivity, high standards of respect and trust, and leading with humility will we be able to achieve our goals.

Baking inclusive principles into our company and diversity into our design provides equitable opportunities for all and enhances our ability to be first in class in all aspects of our industry.

Bready* to make a change? Apply today!

Toast is committed to creating an accessible and inclusive hiring process. As part of this commitment, we strive to provide reasonable accommodations for persons with disabilities to enable them to access the hiring process. If you need an accommodation to access the job application or interview process, please contact [email protected].

Top Skills

Java
JavaScript
Kotlin
Python
React

What the Team is Saying

Christopher
Srishti
JJ
Eden
Jane
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
5,000 Employees
Hybrid Workplace
Year Founded: 2011

What We Do

Toast is the all-in-one platform built for restaurants of all sizes. Toast provides a single platform of software as a service (SaaS) products and financial technology solutions that give restaurants everything they need to run their business, including point of sale, payments, supplier management, digital ordering and delivery, marketing and loyalty, and team management. By serving as the restaurant operating system across dine-in, takeout, and delivery channels, Toast helps restaurants increase revenue, streamline operations and deliver amazing guest experiences.

Why Work With Us

Our recipe for an awesome workplace:

One splash of friendship
A dollop of impact
A sprinkle of no hierarchy &
A heavy spoonful of individuality

Mix these ingredients in a fast-paced and hardworking environment. Best paired with a side of interesting people who always bring their whole selves to work.

*100% Sunday scary free

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Toast Teams

Team
Engineering
Team
Sales
About our Teams

Toast Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Flexible
Company Office Image
HQBoston, MA
Company Office Image
Bengaluru, IN
Company Office Image
Chennai, IN
Company Office Image
Dublin, IE
Company Office Image
Lublin, PL
Company Office Image
Omaha, NE
Company Office Image
San Francisco, CA
Learn more

Similar Jobs

Toast Logo Toast

Security Operations Center Engineer (SOC)

Cloud • Fintech • Food • Information Technology • Software • Hospitality
Dublin, IRL
5000 Employees

Toast Logo Toast

Senior Technical Compliance Analyst

Cloud • Fintech • Food • Information Technology • Software • Hospitality
Dublin, IRL
5000 Employees

Toast Logo Toast

POS Menu Coordinator

Cloud • Fintech • Food • Information Technology • Software • Hospitality
Dublin, IRL
5000 Employees

Toast Logo Toast

Senior Engineering Manager

Cloud • Fintech • Food • Information Technology • Software • Hospitality
Dublin, IRL
5000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account