Security & Compliance Lead

Toast

Vancouver

On-site

CAD 120,000 - 180,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Stock options
Health coverage
Flexible vacation
Access to CEO

Job summary

Toast, a fast-growing B2B SaaS company, is seeking a Security and Compliance Lead in Vancouver to own data protection, risk management, and trust as we scale.

You will lead SOC 2 Type 2 audits end-to-end, oversee the privacy program, manage subprocessor relationships, and collaborate with IT and Engineering to embed security into systems and processes. Strong communication and cloud security expertise are required.

Qualifications

  • Experience in information security, risk, privacy, and compliance in B2B SaaS or cloud
  • Hands-on SOC 2 Type 2 audit management
  • Knowledge of SOC 2, ISO 27001, and NIST; GDPR/CCPA
  • Excellent communication for security questionnaires and translating complex concepts
  • Sound judgment balancing controls with pragmatic risk-taking
  • Hands-on mindset; can drive progress across teams without direct authority
  • Industry certifications such as CISSP, CISM, or CIPP/E are a plus
  • Experience working with Legal on privacy/security terms in contracts
  • Familiarity with AWS, GCP, or Azure is an asset
  • Interest in applying AI to security and compliance

Responsibilities

  • Serve as internal security expert guiding teams and customers through reviews
  • Own the SOC 2 Type 2 audit process end to end, including evidence collection
  • Oversee the privacy framework and manage subprocessor relationships
  • Lead incident response, business continuity, and disaster recovery testing
  • Partner with IT and Engineering to embed security into systems and processes
  • Build security awareness through training and ongoing education

Skills

SOC 2 Type 2
ISO 27001
NIST
Privacy regulations
Audit coordination
Security programs
Communication skills
Cloud security
Risk management

Tools

AWS
GCP
Azure

Job description

Job Description

Toast is recruiting on behalf of a fast growing B2B SaaS company in the competitive intelligence space. The company uses AI to turn market, competitor, and buyer signals into insights that revenue teams can act on, helping organizations win more competitive deals. Based in Vancouver with hubs in other major cities, the team is small, globally distributed, and scaling quickly, having grown through several recent acquisitions. They are looking for a Security and Compliance Lead to own how the organization protects data, manages risk, and builds trust with customers as it scales.

Responsibilities
  • Serve as the internal expert on security, guiding teams and customers through reviews and removing blockers along the way
  • Own the SOC 2 Type 2 audit process end to end, including evidence collection, auditor coordination, and continuous improvement
  • Oversee the company's privacy framework, manage subprocessor relationships, and ensure compliance with regulations like GDPR and CCPA
  • Lead incident response efforts, including maintaining and testing business continuity and disaster recovery plans
  • Partner with IT and Engineering to embed security into systems and processes as the company grows
  • Build security awareness across the organization through training and ongoing education
Requirements
  • Experience in information security, risk, privacy, and compliance, ideally within a B2B SaaS or cloud-native environment
  • Hands-on experience managing SOC 2 Type 2 audits, from control implementation through auditor coordination
  • Strong working knowledge of security frameworks such as SOC 2, ISO 27001, and NIST, and privacy regulations like GDPR and CCPA
  • Excellent communication skills, with the ability to respond to complex security questionnaires and translate technical concepts for any audience
  • Sound judgment and pragmatism, knowing when to enforce controls and when to enable reasonable risk taking
  • A hands-on, get-things-done mindset that can flex between strategic and tactical work
  • Ability to work independently and drive progress across teams without direct authority
  • Industry certifications such as CISSP, CISM, or CIPP/E would be an asset
  • Experience partnering with Legal on privacy and security terms in contracts or data protection agreements is a plus
  • Familiarity with cloud environments such as AWS, GCP, or Azure is considered an asset
  • An interest in how AI can enhance security and compliance work would be a plus
Benefits
  • Competitive salary aligned with experience, plus participation in an employee stock option plan for all full-time employees
  • Comprehensive extended health and dental coverage starting on day one
  • Flexible, take-the-time-you-need vacation policy
  • Direct access to company leadership, including regular touchpoints with the CEO
  • Working at the center of a growing market category, with the chance to shape how a fast-scaling company protects the trust of its customers and partners
  • Joining a small, high-impact team where this hire's decisions on compliance and risk directly influence the company's ability to win and retain enterprise customers
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security & Compliance Lead — SOC 2 & Privacy Champion
Security & Compliance Lead — SOC 2 & Privacy Champion

Toast • Vancouver

On-site
CAD 120,000 - 180,000
Stock options
Health coverage
Flexible vacation
+1
Sr. Compliance Officer
Sr. Compliance Officer

Raise • Ottawa

Hybrid
CAD 61,000 - 81,000
Senior Security Engineer
Senior Security Engineer

fispan • Vancouver

On-site
CAD 130,000 - 160,000
Extended health and dental benefits
Paid time off
Savings and retirement plan matching
+5
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Calgary

Hybrid
CAD 140,000 - 190,000
Hybrid work environment
Profit sharing
RRSP matching
+2
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Vancouver

Hybrid
CAD 150,000 - 190,000
Hybrid work environment
Competitive salary
Profit sharing
Senior Security Technical Program Manager
Senior Security Technical Program Manager

United States Digital Space LLC • Vancouver

Hybrid
CAD 150,000 - 170,000
Mental health benefits
Career coaching
Family building benefits
+2
Sr. Compliance Officer
Sr. Compliance Officer

Robertson & Company Ltd. • Ottawa

Hybrid
CAD 72,000 - 83,000
Enterprise Security Specialist
Enterprise Security Specialist

Cprvision • Whitchurch-Stouffville

Hybrid
CAD 120,000 - 135,000
Flexible working arrangements
Comprehensive benefits package
Annual bonus program
+1
Senior Corporate Security Analyst
Senior Corporate Security Analyst

Clio • Burnaby, Calgary, Toronto

Hybrid
CAD 106,000 - 144,000
Senior GRC Consultant
Senior GRC Consultant

Scale Up Recruiting Partners • Edmonton

Remote
CAD 90,000 - 130,000