Senior Corporate Security Analyst
ToastBengaluru, Karnataka, IndiaPosted 12 March 2026
Job Description
Toast creates technology to help restaurants and local businesses succeed in a digital world, helping business owners operate, increase sales, engage customers, and keep employees happy.
We are seeking a highly motivated Senior Corporate Security Analyst to join Toast’s Corporate Security team in Bangalore. This role is focused on hands-on corporate security execution and risk reduction across endpoints, identities, SaaS platforms, vendors, and data — not SOC monitoring or shift-based operations.
The ideal candidate has strong experience working in enterprise corporate security environments, understands how to balance security controls with business needs, and is comfortable partnering with IT, GRC, Procurement, Legal, and Engineering teams. You will own multiple CorpSec programs end-to-end and act as a senior individual contributor, while mentoring junior analysts and helping scale security practices across the organization.
A Day in Life
(Responsibilities)
1. Corporate Security Execution Risk Management
Own and operate key corporate security controls across endpoint, SaaS, identity, vendor, and data security.
Perform security risk assessments for business initiatives and translate findings into actionable remediation plans.
Act as a security advisor to internal stakeholders, focusing on practical risk reduction.
2. Endpoint SaaS Security
Lead day-to-day security oversight for corporate endpoints and SaaS applications, including:
EDR/XDR, device hardening, encryption, MDM/UEM
Shadow IT discovery and SaaS risk reviews
Partner with IT Operations and Governance teams to resolve alerts, misconfigurations, and policy gaps.
Conduct periodic reviews of high-risk applications, browser extensions, and endpoint findings.
3. Vulnerability Management (Corporate Scope)
Drive vulnerability management for corporate endpoints and internal business systems.
Triage and prioritize vulnerabilities based on business impact and exploitability.
Track remediation with IT teams and validate closure.
4. Identity Access Management (IAM)
Support enterprise IAM governance, including:
Joiner / mover / leaver processes
Access reviews and least-privilege enforcement
MFA, SSO, device trust, and privileged access (PAM)
Assist in access investigations and high-risk access exception reviews.
5. Vendor Third-Party Security
Conduct vendor security assessments for onboarding and periodic reviews.
Review SOC 2 reports, security questionnaires, and supporting evidence.
Track vendor risks, remediation actions, and re-assessments.
Partner with Procurement, Legal, and GRC teams to ensure security requirements are met.
6. Data Protection DLP
Support data protection initiatives across Google Workspace, Slack, and other collaboration platforms.
Assist with the design, tuning, and enforcement of DLP controls.
Participate in investigations related to data exposure or misuse.
7. Security Awareness Process Improvement
Support security awareness training and phishing simulation programs.
Maintain CorpSec policies, SOPs, and runbooks.
Identify opportunities to improve efficiency through automation and tooling.
8. Mentorship Ownership
Mentor P2-level security analysts and provide technical guidance.
Take ownership of CorpSec initiatives and deliver them end-to-end with minimal supervision.
9. Contractor Security Oversight
Establish and enforce contractor access standards, ensuring strict security controls during onboarding and offboarding.
Conduct periodic contractor access and activity audits, identifying and mitigating associated risks.
Work Mode: This role follows a hybrid work model, requiring a minimum of 2 days per week in the office.
What We’re Looking For
Required
6–10 years of experience in information security with strong corporate security exposure.
Hands-on experience with:
Endpoint security and EDR tools (e.g., CrowdStrike)
Vendor security assessments and SOC 2 reviews
IAM concepts (Okta, PAM, access reviews)
SaaS ... (truncated, view full listing at source)
Apply Now
Direct link to company career page
More jobs at Toast
See all →West Coast - Inside Strategic Cuisines Account Executive - Spanish
Los Angeles, CA · 13 March 2026
Principal Product Manager, Voice AI
Remote US · 13 March 2026
Ellettsville, Indiana Territory Account Executive
Ellettsville, IN · 13 March 2026
Principal Software Engineer, Toast IQ
Remote, US · 13 March 2026