
Job Overview
Location
Boston, MA
Job Type
Full-time
Category
Software Engineering
Date Posted
July 2, 2026
Full Job Description
đź“‹ Description
- • Lead the design and maintenance of an auditable control framework tailored to ezCater’s SaaS, cloud, data, and engineering environment, avoiding generic controls that don’t align with modern systems.
- • Shape and define ezCater’s AI Governance strategy in collaboration with Legal, Data, Engineering, and IT stakeholders to ensure responsible and compliant use of AI and agentic systems.
- • Define how key governance, risk, and compliance (GRC) controls are implemented, tested, evidenced, and improved over time with a strong bias toward automation, reliability, and low-friction evidence paths.
- • Partner with internal and external audit teams on control design, walkthroughs, exceptions, remediation, and readiness activities tied to SOX, SOC 2, PCI-DSS, and other compliance frameworks.
- • Rationalize overlapping control requirements across SOC 2, PCI, SOX, and internal policies into a unified, coherent operating model that reduces redundancy and improves efficiency.
- • Identify opportunities to replace quarterly or annual manual checks with continuous or near-real-time monitoring, especially for high-value or failure-prone controls.
- • Collaborate with Security Engineering, IT, Data, and platform teams to automate control testing, evidence collection, validation, and recurring compliance workflows using scripting, APIs, and platform configurations.
- • Define the necessary logs, metadata, dashboards, and signals to make control health observable, reducing dependence on screenshots and one-off data pulls.
- • Shift the GRC program from detective-only controls toward preventive and engineering-embedded control patterns where feasible and effective.
- • Help define, mature, and enforce data security policies, standards, and handling requirements that are clear, actionable, and tied to technical and operational practices.
- • Partner with Data and Engineering teams to embed data governance into access patterns, role design, data labeling, masking, retention policies, and evidence trails.
- • Establish operating cadences, ownership models, decision paths, metrics, and continuous improvement loops to define what a high-quality GRC program looks like at ezCater.
- • Drive clearer documentation, standards, and guidance that both technical teams and auditors can effectively use to implement and assess controls.
- • Support day-to-day GRC and assurance work including control failures, remediation coordination, audit operations, and follow-through when hands-on execution is required.
- • Improve the team’s ability to handle questionnaires, trust requests, vendor reviews, and other recurring tasks through reusable materials, structured workflows, and smarter agentic automation.
- • Act as a practical partner to engineering and operational teams implementing controls—not just an assessor of paper-based policies—ensuring compliance is embedded in systems, not appended to them.
- • Own a domain with high autonomy, lead cross-team initiatives from inception to completion, and improve the quality of systems, controls, and processes across the organization.
- • Drive alignment across stakeholders with competing incentives by making pragmatic decisions that balance risk, cost, and operational reality.
- • Mentor team members, improve knowledge sharing, and raise the overall maturity of the Security Engineering & Compliance team and its partners.
- • Leverage AI tooling and automated workflows to increase the scale and velocity of GRC operations without compromising rigor or accuracy.
- • Balance strategic, long-term design work with operational execution when the program requires direct hands-on support to maintain momentum.
- • Identify gaps between teams and drive implementation of better ways of working that improve process quality, reduce friction, and enhance compliance outcomes.
🎯 Requirements
- • 8+ years of experience in security GRC, compliance, risk, or security program work in a SaaS or cloud-native environment with meaningful ownership of control design, testing, and program improvement.
- • Strong experience with security compliance frameworks such as ISO-27001, NIST CSF, SOC 2, ITGC, and PCI-DSS, including translating framework requirements into functional controls for real systems.
- • Demonstrated ability to automate or instrument parts of a compliance or assurance program using scripting, APIs, dashboards, platform configuration, or other technical approaches.
- • Implementation of engineering system guardrails for compliance using Policy-as-Code (e.g., Terraform) or secure configurations within cloud environments (AWS, GitHub, etc.).
- • Experience building or improving data security governance, classification, handling rules, or related control practices across business systems, data platforms, or collaboration environments.
- • Familiarity with governing and securing AI/Agentic systems and business processing.
🏖️ Benefits
- • Market competitive salary with bonus target ranging from $165,000–$210,000 annually.
- • Stock options as part of total compensation.
- • 12 paid holidays and flexible PTO.
- • 401K with company match.
- • Health, dental, FSA, and long-term disability insurance.
- • Mental health and family planning resources.
- • Remote-hybrid work options: from Boston office, home, or a mix of both.
- • Employee meal program available when working in the office.
Skills & Technologies
See exactly how your profile matches this role — strengths, skill gaps, and what to do about them.
About ezCater, Inc.
Founded in 2007 and headquartered in Boston, Massachusetts, ezCater operates an online marketplace that connects businesses with local restaurants and caterers for corporate meals, events, and recurring catering needs across the United States. The platform offers ordering, scheduling, invoicing, analytics, and customer support tools designed for office administrators and event planners. ezCater partners with thousands of restaurants and caterers, providing businesses with curated menus, dietary filtering, on-time delivery tracking, and consolidated billing. The company has raised over $320 million in venture capital and serves more than 100,000 companies nationwide, positioning itself as a leading corporate catering solution.
Subscribe to the weekly newsletter for similar remote roles and curated hiring updates.
Newsletter
Weekly remote jobs and featured talent.
No spam. Only curated remote roles and product updates. You can unsubscribe anytime.
Similar Opportunities

Functional Software, Inc.
3 months ago

Cadence Design Systems, Inc.
21 days ago

Sailor Health Inc.
2 months ago
21 days ago
