Toast is a technology company that helps restaurants and local businesses succeed in a digital world. They are seeking a Senior Product Security Engineer to manage and deliver security intelligence across their platforms, identify and remediate application vulnerabilities, and improve security practices while collaborating with various teams.
Responsibilities:
- Select, implement, design, and build services and tools to manage and deliver security intelligence across Toast platforms
- Identify, triage, and provide remediation guidance for application vulnerabilities, with a specific focus on anti-abuse activities
- Improve developer tooling and adoption to build a more robust SSDLC which integrates security and anti-abuse features
- Practice a #OneTeam attitude to help other Toast teams make informed, security-conscious decisions when building new public-facing software
- Assist incident response teams with application security expertise and tools, especially related to abuse and fraud
- Build threat models on Toast applications and use cases
- Guide in the design and maintenance of robust and resilient network and application architecture
- Collaborate to improve information gathering and sharing across all Toast products
- Leverage cutting edge AI tools to enhance your development workflow, improve velocity, and help pioneer new approaches to building - contributing to a culture of innovation and productivity across the team
Requirements:
- Minimum 5+ years of experience in application security and security engineering
- Experience building and maintaining scaled Java web services in production
- Experience developing script applications in Python for scheduling and backend data handling
- Experience leveraging LLM AI features for software development and/or security operations
- Strong understanding of cloud application architecture
- Successful history of being a subject matter expert to guide colleagues toward better security outcomes, especially related to abuse, fraud and legal concerns
- Previous security experience working with fintech applications and associated requirements
- Strong understanding of privacy, security, and cryptography patterns and when to apply them, especially when handling customer information (such as PKIs, access management, data tokenization, and anonymization)
- Offensive security training and certifications (e.g. OSCP, OSWE, OSEP)
- Edge Security solution like WAF, API Security
- Adversary Emulation proficiency (red/purple teaming)
- Cloud and container security technologies
- SSDLC tooling (e.g., SAST/DAST/SCA)
- Scaled data handling in RDBMS, streaming, and columnar stores
- Metrics and charting software proficiency
- Mobile apps/threats (iOS, Android), and their particular abuse vectors
- Knowledge in security of operating systems, networking and protocols
- Securing financial technologies and associated requirements