Toast

We empower the restaurant community to delight guests, do what they love, and thrive.

Staff IAM Engineer, Sailpoint

Security EngineerSecurity EngineerFull TimeRemoteTeam 1,001-5,000Since 2013H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

4 days ago

Salary

$127K - $203K / year

Sail PointOktaIAMIdentity Lifecycle ManagementAccess ControlsUser Access ReviewAccess RequestService NowSOXSOCPCIJavaPythonAPI IntegrationScriptingAuthenticationApplication IntegrationMonitoringAlertingIncident Response

Job Description

Toast creates technology to help restaurants and local businesses succeed in a digital world, helping business owners operate, increase sales, engage customers, and keep employees happy.

We are seeking a highly motivated and experienced Staff IAM Engineer to join our growing IT IAM team. In this role, you will be a key contributor to the development, enhancement, and strategic evolution of our Identity and Access Management (IAM) program, with a focus on Okta and SailPoint Identity Security Cloud (formerly IdentityNow). You will play a critical role in building our identity lifecycle management processes, ensuring security, compliance, and efficiency. This role requires a deep understanding of IAM principles and best practices, as well as hands-on experience with enterprise-grade IAM platforms SailPoint and Okta

A day in the life (Responsibilities) 

  • Design, develop, and deploy SailPoint Identity Security Cloud: This includes building complex workflows, configuring policies, building integrations, developing user lifecycle management workflows between SailPoint and integrated systems, and acting as a subject matter expert for SailPoint. 
  • Drive automation: Develop and implement automated provisioning and de-provisioning processes, and seamlessly integrate SailPoint with diverse applications, leveraging scripting and API knowledge. Focus on scalability and efficiency in automation efforts.
  • Architect and implement access controls: Create, develop, and deploy robust access policies and roles, adhering to the principle of least privilege.
  • Ramp the team and develop comprehensive documentation: Write and maintain detailed documentation for all IAM configurations, processes, runbooks, and governance needs, ensuring clarity and consistency for both technical and non-technical audiences. This documentation should be utilized to guide the team to implement using best practices, deliver scalable solutions, and operate out of SOPs that create repeatable processes. 
  • Champion continuous improvement: Research and evaluate emerging IAM technologies, stay abreast of industry best practices, and proactively drive opportunities to enhance our IAM program. 
  • Ensure platform health and performance: Take ownership of system health checks, proactive monitoring, troubleshooting, and performance tuning for both platforms to ensure optimal performance, reliability, and availability. Develop and implement monitoring and alerting solutions.
  • Enhance security incident response: Develop and implement the security incident response processes related to identity and access. Implement monitoring and alerting to provide system logs and alerts for suspicious activity. Participate in security audits and compliance assessments (e.g., SOX, SOC, PCI).
  • Collaborate with stakeholders: Work closely with business units, application owners, and security teams to gather requirements, design effective solutions, and implement IAM strategies that meet business needs while maintaining security posture. This includes leading requirements gathering sessions and translating business needs into technical specifications.

What you'll need to thrive (Requirements)

  • 10+ years of experience in Identity and Access Management.
  • 7+ years experience with SailPoint Identity Security Cloud, including design, development, configuration, and med-large scale deployment.
  • Proven experience implementing Sailpoint to manage access for large core enterprise applications including Salesforce, Netsuite and Snowflake
  • Proven experience configuring and implementing full end-to-end User Access Review (UAR) capabilities in Sailpoint for integrated and non-integrated applications
  • Proven experience configuring and implementing Access Request functionality in SailPoint. Experience migrating access request capabilities from ServiceNow to SailPoint is ideal.
  • Extensive experience with Okta administration, including user management, authentication, and application integration, and application access workflows.
  • Solid understanding of IAM concepts, best practices, and industry standards.
  • Experience with scripting languages (e.g., Java, Python) for automation.
  • Excellent analytical, problem-solving, and communication skills.

What will help you stand out (Nonessential Skills/Nice to Haves)

  • Relevant certifications (e.g., CISSP, CISM, SailPoint Certified Professional).
  • Compliance Knowledge (SOX, SOC, PCI, UAR)
  • Experience with other IAM solutions (e.g., Azure AD, AWS IAM).
  • Knowledge of IT security frameworks (e.g., NIST, ISO 27001).

AI at Toast

At Toast, one of our company values is that we're hungry to build and learn. We believe learning new AI tools empowers us to build for our customers faster, more independently, and with higher quality. We provide these tools across all disciplines, from Engineering and Product to Sales and Support, and are inspired by how our Toasters are already driving real value with them. The people who thrive here are those who embrace changes that let us build more for our customers; it’s a core part of our culture.

 

Our Total Rewards Philosophy 
We strive to provide competitive compensation and benefits programs that help to attract, retain, and motivate the best and brightest people in our industry. Our total rewards package goes beyond great earnings potential and provides the means to a healthy lifestyle with the flexibility to meet Toasters’ changing needs. Learn more about our benefits at https://careers.toasttab.com/toast-benefits.



The base salary range for this role is listed below. The starting salary will be determined based on skills and experience. In addition to base salary, our total rewards components include cash compensation (overtime, bonus/commissions, if eligible), benefits, and equity (if eligible).

Pay Range
$127,000$203,000 USD

How Toast Uses AI in its Hiring Process

Throughout the hiring process, our goal is to get to know you. We use AI tools to support our recruiters and interviewers with tasks like note-taking, summarization, and documentation of interviews to ensure they can be fully focused on your conversation. All hiring decisions are made by people.

Diversity, Equity, and Inclusion is Baked into our Recipe for Success

At Toast, our employees are our secret ingredient—when they thrive, we thrive. The restaurant industry is one of the most diverse, and we embrace that diversity with authenticity, inclusivity, respect, and humility. By embedding these principles into our culture and design, we create equitable opportunities for all and raise the bar in delivering exceptional experiences.

We Thrive Together

We embrace a hybrid work model that fosters in-person collaboration while valuing individual needs. Our goal is to build a strong culture of connection as we work together to empower the restaurant community. To learn more about how we work globally and regionally, check out: https://careers.toasttab.com/locations-toast.

Apply today!

Toast is committed to creating an accessible and inclusive hiring process. As part of this commitment, we strive to provide reasonable accommodations for persons with disabilities to enable them to access the hiring process. If you need an accommodation to access the job application or interview process, please contact candidateaccommodations@toasttab.com.

------

For roles in the United States, it is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Related Categories

Related Job Pages

More Security Engineer Jobs

Cybersecurity Assessment and Authorization Subject Matter Expert

TekSynap

TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. “Technology moving at the speed of thought” embodies these principles – the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers.

Security Engineer4 days ago
Full TimeRemoteTeam 1,001-5,000

We are seeking a Cybersecurity Assessment and Authorization Subject Matter Expert (SME) to join our Defense Logistics Agency team. Serve as a Cybersecurity Subject Matter Expert (SME) for Assessment and Authorization (A&A) activities supporting Department of Defense (DoD) informa...

United States
Full TimeRemote

We are seeking a motivated and technically curious IT Engineer to help design, build, support, and continuously improve technology solutions that enable our business. This role contributes across the full lifecycle of systems and applications, collaborating with cross-functional ...

MuleSoftREST APIIdentity ManagementAccess ManagementAPI Development
United States
$110K - $182K / year
Security Engineer4 days ago
Full TimeRemote

We are seeking a talented, motivated Threat Detection Engineer to join our global team. This individual will be a self-starter excited to take on ownership of complex projects with a wide degree of autonomy. This role is unique in its schedule, providing critical weekend coverage...

PythonSIEMGoogle SecOpsPandasJupyter Notebookspacket capture analysislog analysisthreat detectionincident responsethreat huntingthreat intelligenceDetection-as-Codeautomation
United States
$500K / year
Full TimeRemoteTeam 10,001

The Senior IT Application Security Engineer will act as a subject matter expert, guiding software development teams in designing and implementing secure solutions by enforcing security checks throughout the SDLC. This role involves leading application security initiatives, defining standards, mentoring team members, and advancing the overall maturity of the application security program.

Application SecurityThreat ModelingSecure CodingOWASP Top 10SDLCCISSPPenetration TestingRisk AssessmentC#JavaC++AgileScrumSAFeCloud SecurityContainerizationMicroservicesCI/CD
United States
$120K - $191K / year