Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Staff Security Engineer (Product Security & IAM) image - Rise Careers
Job details

Staff Security Engineer (Product Security & IAM)

Toast is driven by building the restaurant platform that helps restaurants adapt, take control, and get back to what they do best: building the businesses they love.

Product Security at Toast isn't just about running tools and reporting vulnerabilities – we're the vigilant chefs ensuring the Toast never gets burned. We bake security into every layer of our products, from the first sprinkle of an idea to the final serving of a fully-baked solution. Our team is the secret ingredient that makes Toast's digital recipe both delicious and secure. We collaborate closely with R&D, seasoning the development process with robust security measures that protect the services and applications our customers rely on to run their businesses. 

Like master chefs, we blend cutting-edge technology with strategic thinking, kneading security into the dough of every product we create. By joining our Product Security team, you'll be part of the kitchen crew that keeps our customers' trust from going stale. You'll tackle complex challenges that have real-world impact, helping to serve up a safer, more secure digital experience for businesses that count on Toast every day. It's not just about finding vulnerabilities – it's about crafting a recipe for digital trust that keeps our customers coming back for more.

About this roll (Responsibilities)

  • Identify, triage, and provide remediation guidance for application vulnerabilities, with a specific focus on IAM-related issues.
  • Select, implement, design, or build tools to manage and secure identity and access across Toast platforms.
  • Improve developer tooling and adoption to build a more robust SSDLC with respect to IAM best practices.
  • Practice a #OneTeam attitude to help other Toast teams make informed, security-conscious decisions when building new software with IAM considerations.
  • Support and expand the Security Champions program, providing IAM-specific training and guidance.
  • Assist incident response teams with application security expertise and tools, especially related to IAM incidents.
  • Build threat models on IAM applications and architecture.
  • Guide in the design and maintenance of secure authentication and authorization mechanisms.
  • Provide signals for IAM events to the SOC for better alerting and response.

Do you have the right ingredients? (Requirements)

  • Minimum 7+ years of experience in application security
  • Experience reading, reviewing, and providing security guidance for complex code in a variety of languages and frameworks (Java/Kotlin, Javascript/ES6, React, and Python are a priority), with a strong emphasis on IAM implementations.
  • Strong understanding of cloud application architecture and common IAM weaknesses (e.g., insecure authentication, authorization flaws, privilege escalation).
  • Experience identifying and helping to resolve common application security flaws (e.g., OWASP, SANS) related to IAM.
  • Successful history of being a subject matter expert to guide products and lines of business to better security outcomes related to IAM.
  • Previous security experience working with fintech applications and associated IAM requirements.
  • Strong understanding of privacy, security, and cryptography patterns and when to apply them, especially within IAM (such as PKIs, access management, data tokenization, and anonymization).
  • Deep understanding of IAM concepts (e.g., OAuth, OIDC, SAML).

Special Sauce (Nonessential Skills/Nice to Haves)*

  • Cloud and container security technologies.
  • SSDLC tooling (e.g., SAST/DAST/SCA), particularly those focused on IAM.
  • AWS IAM.
  • Infrastructure-as-code (IaC) technologies like Terraform to manage cloud security services.
  • Mobile apps/threats (iOS, Android), and their related IAM challenges.
  • Securing financial technologies and associated IAM requirements.
  • Directory services (e.g., LDAP, Active Directory).

**This is a hybrid role, requiring two days in the office per week**

Our Spread* of Total Rewards
We strive to provide competitive compensation and benefits programs that help to attract, retain, and motivate the best and brightest people in our industry. Our total rewards package goes beyond great earnings potential and provides the means to a healthy lifestyle with the flexibility to meet Toasters’ changing needs. Learn more about our benefits at https://careers.toasttab.com/toast-benefits.



*Bread puns encouraged but not required



 

Diversity, Equity, and Inclusion is Baked into our Recipe for Success

At Toast, our employees are our secret ingredient—when they thrive, we thrive. The restaurant industry is one of the most diverse, and we embrace that diversity with authenticity, inclusivity, respect, and humility. By embedding these principles into our culture and design, we create equitable opportunities for all and raise the bar in delivering exceptional experiences.

We Thrive Together

We embrace a hybrid work model that fosters in-person collaboration while valuing individual needs. Our goal is to build a strong culture of connection as we work together to empower the restaurant community. To learn more about how we work globally and regionally, check out: https://careers.toasttab.com/locations-toast.

Apply today!

Toast is committed to creating an accessible and inclusive hiring process. As part of this commitment, we strive to provide reasonable accommodations for persons with disabilities to enable them to access the hiring process. If you need an accommodation to access the job application or interview process, please contact candidateaccommodations@toasttab.com.

Average salary estimate

$130000 / YEARLY (est.)
min
max
$120000K
$140000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Staff Security Engineer (Product Security & IAM), Toast

Join Toast as a Staff Security Engineer (Product Security & IAM) in the vibrant city of Dublin, Ireland! At Toast, we believe in building a restaurant platform that empowers our partners to thrive, and we take product security seriously. Our Product Security team is not just about identifying vulnerabilities; we’re all about integrating security seamlessly throughout the product lifecycle. Here, you'll collaborate with our R&D teams to bake security into every application we develop, ensuring our clients can focus on running their restaurants without worrying about their digital safety. You'll tackle complex challenges—after all, safeguarding our customers' trust is paramount. With responsibilities ranging from identifying and remediating IAM-related vulnerabilities to enhancing our developer tooling for a secure software development lifecycle, your expertise will be invaluable. You’ll also enrich the Security Champions program and assist various teams with your IAM knowledge. Plus, you’ll have the opportunity to create effective authentication mechanisms while working closely with incident response teams. If you have a rich background in application security, especially surrounding IAM solutions, this role could be the perfect blend of your skills and career aspirations. Step into a place where every team member contributes to the recipe for digital trust. Join us and be a part of something truly special at Toast!

Frequently Asked Questions (FAQs) for Staff Security Engineer (Product Security & IAM) Role at Toast
What are the primary responsibilities of a Staff Security Engineer (Product Security & IAM) at Toast?

As a Staff Security Engineer (Product Security & IAM) at Toast, your primary responsibilities include identifying and remediating application vulnerabilities with a strong focus on IAM issues. You will be implementing, designing, and selecting tools to secure identity and access across our platforms. Additionally, you will enhance developer tooling and practices for a robust Software Security Development Lifecycle (SSDLC) while practicing a #OneTeam approach to assist other teams in making informed security decisions.

Join Rise to see the full answer
What qualifications do I need to apply for the Staff Security Engineer position at Toast?

To apply for the Staff Security Engineer (Product Security & IAM) position at Toast, you generally need a minimum of 7+ years of application security experience. You should have strong knowledge of IAM implementations and be able to review complex code across various languages and frameworks like Java, JavaScript, and Python. Additionally, familiarity with cloud application architecture, common IAM weaknesses, and identification of application security flaws is essential.

Join Rise to see the full answer
How does the Staff Security Engineer contribute to the incident response process at Toast?

The Staff Security Engineer (Product Security & IAM) plays a crucial role in the incident response process at Toast by providing expert application security insight related to IAM incidents. You will support incident response teams with your expertise, ensuring that IAM-related vulnerabilities are addressed efficiently and robustly. Your work will ensure that the systems are not only secure but also resilient to future threats.

Join Rise to see the full answer
What tools and technologies will I work with as a Staff Security Engineer at Toast?

In the Staff Security Engineer (Product Security & IAM) role at Toast, you will work with a variety of tools and technologies aimed at managing and securing identity and access within our applications. This includes using SSDLC tooling such as SAST, DAST, and SCA, particularly those focused on IAM. Additionally, familiarity with AWS IAM and Infrastructure-as-Code technologies like Terraform will be beneficial.

Join Rise to see the full answer
Is the Staff Security Engineer role at Toast remote or hybrid?

The Staff Security Engineer (Product Security & IAM) position at Toast is a hybrid role, requiring two days in the office per week. This model allows for valuable in-person collaboration while also accommodating the flexibility of remote work, promoting both personal and professional growth.

Join Rise to see the full answer
Common Interview Questions for Staff Security Engineer (Product Security & IAM)
Can you describe your experience with IAM and how it relates to application security?

When answering this question, you should provide specific examples of your experience with Identity and Access Management systems, detailing instances where you've implemented security measures or mitigated IAM-related vulnerabilities. Be sure to touch on any frameworks or languages you’ve worked with and how those experiences position you to contribute to Toast.

Join Rise to see the full answer
What is your process for identifying vulnerabilities in an application?

Discuss your systematic approach to vulnerability identification, including code reviews, security testing, and using security tools. Provide insights into how you prioritize vulnerabilities based on risk and impact, and mention any specific tools or methodologies you prefer, such as OWASP guidelines.

Join Rise to see the full answer
How do you stay updated on the latest security trends and threats?

Demonstrate your passion for continuous learning by mentioning specific resources, such as security conferences, online courses, blogs, or communities. Explain how staying informed allows you to effectively protect your organization's assets and enhance the security posture at Toast.

Join Rise to see the full answer
Can you explain a challenging security incident you managed and what you learned from it?

Share a concise story about a specific security incident, focusing on the steps you took to resolve it and the lessons learned. Highlight any improvements you made to processes or systems to prevent recurrence, showcasing your analytical thinking and problem-solving skills.

Join Rise to see the full answer
Describe your experience with secure coding practices?

In your response, outline key secure coding practices you advocate for, including input validation, proper error handling, and the principle of least privilege. Provide examples of how you have integrated these practices into development processes in previous roles.

Join Rise to see the full answer
What tools have you used for application security testing?

Make a list of specific tools you're familiar with, such as static and dynamic analysis tools, SAST, DAST, and SCA, explaining your experience with each. Discuss how you have utilized these tools to enhance security at previous organizations and the results achieved.

Join Rise to see the full answer
How would you approach building threat models for IAM applications?

Detail your process for creating threat models, including identifying assets, potential threats, and attack vectors specific to IAM systems. Emphasize the importance of collaboration with different teams and how such models can help in proactively securing applications.

Join Rise to see the full answer
What are some common IAM weaknesses you have encountered?

Identify several common IAM weaknesses such as insecure authentication methods, authorization flaws, and privilege escalation. Discuss your experiences in diagnosing and resolving these weaknesses in past projects to underpin your knowledge and skills.

Join Rise to see the full answer
How would you implement a security champions program in an organization?

When responding, outline steps such as defining the program's objectives, creating training materials, and ensuring champions receive ongoing support. Mention previous examples where you've led similar initiatives and the positive outcomes from those experiences.

Join Rise to see the full answer
How do you ensure compliance with security best practices while developing applications?

Explain how you incorporate security best practices from the initial stages of software development and use various compliance frameworks as guidelines. Stress the importance of cross-team collaboration and regular audits to maintain compliance at Toast.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Toast Remote Remote, United States
Posted 14 days ago
Photo of the Rise User

Join Caseware as a Director of IT & Enterprise Systems to lead technology strategy and manage enterprise systems for a growing global SaaS organization.

Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 9 days ago
NXTGIG Remote No location specified
Posted 12 days ago
Photo of the Rise User

Join TTEC Digital as a Senior AWS Presales Solution Architect to drive customer experience enhancements with AWS technologies.

Photo of the Rise User

Join HealthEquity as a Site Reliability Engineer II and contribute to empowering healthcare consumers through automation and system reliability.

Photo of the Rise User

We are looking for a talented Network Administrator to maintain and enhance our critical networking infrastructure for the Special Operations Command.

Restaurant

381 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 3, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
S
8 people applied to SOC Intern at SHEIN
Photo of the Rise User
Someone from OH, Beachwood just viewed Legal Counsel (Intellectual Property) at Mars
o
Someone from OH, Columbus just viewed Marketing and Communications Specialist at osu
Photo of the Rise User
Someone from OH, Cincinnati just viewed Data Analyst at Apple
Photo of the Rise User
Someone from OH, Dublin just viewed Manager-Financial Systems at American Express
Photo of the Rise User
Someone from OH, Akron just viewed Financial Analyst (Project Controls Analyst) at Nava
Photo of the Rise User
Someone from OH, Fairfield just viewed Finance Rotation Analyst at Huntington National Bank
A
Someone from OH, Canton just viewed Remote Sales- NO COLD CALLING at AO Globe Life
Photo of the Rise User
Someone from OH, Athens just viewed Digital Customer Experience Improvment (UX) at Advansys
Photo of the Rise User
Someone from OH, Akron just viewed Mobile Business Analyst at E.L.F. BEAUTY
Photo of the Rise User
Someone from OH, Lisbon just viewed Associate Cybersecurity Analyst - IAM at Visa
Photo of the Rise User
Someone from OH, Cincinnati just viewed Associate Buyer - Hardgoods at Huckberry
Photo of the Rise User
Someone from OH, Cleveland just viewed Inside Sales Representative at Elvtr
Photo of the Rise User
Someone from OH, Dayton just viewed Risk Operations Specialist at Imprint
A
Someone from OH, Cleveland just viewed Traffic Control Flagger at AWP Safety
Photo of the Rise User
Someone from OH, Sylvania just viewed Talent Sourcer at CEQUENS
Photo of the Rise User
Someone from OH, Sylvania just viewed Talent Sourcer (6 month contract) at Jerry
T
6 people applied to Intern-Tech at TDS Telecom
A
Someone from OH, Cleveland just viewed Junior Communications Specialist at Alphabe Insight Inc
Photo of the Rise User
Someone from OH, Columbus just viewed Telecom Coordinator at The Cheesecake Factory
Photo of the Rise User
Someone from OH, Cincinnati just viewed Staff Data Engineer at Visa
Photo of the Rise User
Someone from OH, Mason just viewed R&D Mechanical Engineer at Traeger Wood Pellet Grills
Photo of the Rise User
37 people applied to Security Analyst Jr at DEUNA