Boston, MA Hybrid Full-time USD 165,000 – 210,000 / year

ezCater is hiring a Staff Security Engineer, GRC (Remote)

Responsibilities

  • Lead the maturity of a control program by designing and maintaining an auditable framework tailored to the company's SaaS, cloud, data, and engineering environment, avoiding generic controls.
  • Define and shape the AI governance strategy in collaboration with Legal, Data, Engineering, and IT stakeholders.
  • Determine how key controls are implemented, tested, evidenced, and improved over time, prioritizing reliability and highly automated, low-friction evidence collection.
  • Collaborate with internal and external audit stakeholders on control design, walkthroughs, exceptions, remediation, and readiness activities related to SOX and similar frameworks.
  • Help consolidate overlapping control requirements from SOC 2, PCI, SOX, and internal policies into a unified operating model.
  • Build continuous control monitoring and automation by identifying opportunities to replace quarterly or annual checks with near-real-time monitoring, especially for high-value controls and failure-prone workflows.
  • Partner with Security Engineering, IT, Data, and platform teams to automate control testing, evidence collection, validation, and recurring compliance workflows.
  • Define the logs, metadata, dashboards, and signals needed to assess control health, making compliance more observable and less reliant on manual screenshots and one-time data pulls.
  • Help shift the program from detective-only controls toward stronger preventive and engineering-embedded control patterns where appropriate.
  • Expand data security policy and program quality by defining and maturing policies, standards, and handling requirements that are clear, enforceable, and tied to actual technical and operational practices.
  • Partner with Data, Engineering, and business stakeholders to ensure data governance is integrated into access patterns, role design, labels, masking, retention, and evidence paths.
  • Establish what a high-quality GRC program looks like by defining operating cadences, ownership models, decision paths, metrics, and continuous improvement loops.
  • Drive clearer documentation, standards, and guidance that both technical teams and auditors can use effectively.
  • Support day-to-day GRC and assurance work where hands-on execution is needed, including control failures, remediation coordination, audit operations, and related follow-through.
  • Improve the team's ability to handle questionnaires, trust requests, vendor and partner reviews, and other recurring work through better structure, reusable materials, and smarter agentic workflows.
  • Act as a practical partner to teams implementing or remediating controls, not just an assessor of whether the control exists on paper.
  • Lead through influence and systems thinking by owning a domain with high autonomy, leading cross-team efforts from start to finish, and improving the quality of systems, controls, and processes.
  • Drive alignment across stakeholders with different incentives and constraints, making pragmatic decisions that balance risk, cost, and operational reality.
  • Mentor others, improve documentation and knowledge sharing, and help raise the overall maturity of the Security Engineering and Compliance team and its partners.

Nice to Have

  • Experience with scaling a unified control framework across multiple governance and compliance frameworks.
  • Experience with continuous control monitoring, policy-as-code, or GRC platforms and evidence tooling.
  • Familiarity with AI governance or emerging technology risk, especially where governance needs to be translated into practical technical guardrails.

Benefits

  • Market competitive salary
  • Stock options
  • 12 paid holidays
  • Flexible PTO
  • 401K with company match
  • Health, dental, and FSA
  • Long-term disability insurance
  • Mental health and family planning resources
  • Remote-hybrid work from the Boston office, home, or a mixture of both
  • A tremendous amount of responsibility and autonomy
  • Wicked awesome co-workers
  • Employee meal program and many more goodies when in the office
  • Knowing that you helped transform the food for work space

Compensation

Market competitive salary, stock options, 401K with company match, health/dental/FSA, long-term disability insurance, mental health and family planning resources

Work Arrangement

Remote-hybrid work from the Boston office, home, or a mixture of both

Team

Security Engineering and Compliance team

Other

  • ezCater does not sponsor applicants for work visas or legal permanent residence.
  • Following a conditional offer of employment, ezCater may require a background check.

ezCater does not sponsor applicants for work visas or legal permanent residence.

Job Details
Location Boston, MA
Work mode Hybrid
Employment Full-time
Salary USD 165,000 – 210,000 / year
Category Security
Posted a day ago
or drop your CV first
About company
ezCater logo
ezCater is the leading food for work technology company in the US, connecting anyone who needs food for their workplace to over 100,000 restaurants nationwide. For workplaces, ezCater provides flexible and scalable solutions for everything from recurring employee meals to one-off meetings. For restaurant partners, ezCater helps them grow their business by bringing them more orders and new high-value customers.
All jobs at ezCater Visit website