16 Sep
|
Toast
|
Winnipeg
Job Description Toast is recruiting on behalf of a quick growing B2B SaaS company in the competitive intelligence space. The company uses AI to turn market, competitor, and buyer signals into insights that revenue teams can act on, helping organizations win more competitive deals. Based in Vancouver with hubs in other major cities, the team is small, globally distributed, and scaling quickly, having grown through several recent acquisitions. They are looking for a Security and Compliance Lead to own how the organization protects data, manages risk, and builds trust with customers as it scales.
Responsibilities
Serve as the internal expert on security, guiding teams and customers through reviews and removing blockers along the way
Own the SOC 2 Type 2 audit process end to end, including evidence collection, auditor coordination, and continuous improvement
Oversee the company's privacy framework, manage subprocessor relationships, and ensure compliance with regulations like GDPR and CCPA
Lead incident response efforts, including maintaining and testing business continuity and disaster recovery plans
Partner with IT and Engineering to embed security into systems and processes as the company grows
Build security awareness across the organization through training and ongoing education
Requirements
Experience in information security, risk, privacy, and compliance, ideally within a B2B SaaS or cloud-native environment
Hands-on experience managing SOC 2 Type 2 audits, from control implementation through auditor coordination
Strong working knowledge of security frameworks such as SOC 2,
ISO 27001, and NIST, and privacy regulations like GDPR and CCPA
Excellent communication skills, with the ability to respond to complex security questionnaires and translate technical concepts for any audience
Sound judgment and pragmatism, knowing when to enforce controls and when to enable reasonable risk taking
A hands-on, get-things-done mindset that can flex between strategic and tactical work
Ability to work independently and drive progress across teams without direct authority
Industry certifications such as CISSP, CISM, or CIPP/E would be an asset
Experience partnering with Legal on privacy and security terms in contracts or data protection agreements is a plus
Familiarity with cloud environments such as AWS, GCP, or Azure is considered an asset
An interest in how AI can enhance security and compliance work would be a plus
Benefits
Competitive salary aligned with experience, plus participation in an employee stock option plan for all full-time employees
Comprehensive extended health and dental coverage starting on day one
Flexible, take-the-time-you-need vacation policy
Direct access to company leadership, including regular touchpoints with the CEO
Working at the center of a growing market category, with the chance to shape how a fast-scaling company protects the trust of its customers and partners
Joining a small, high-impact team where this hire's decisions on compliance and risk directly influence the company's ability to win and retain enterprise customers
#J-18808-Ljbffr
📌 Security & Compliance Lead (Winnipeg)
🏢 Toast
📍 Winnipeg