Responsibilities
- Lead the maturity of a control program by designing and maintaining an auditable framework tailored to the company's SaaS, cloud, data, and engineering environment, avoiding generic controls.
- Define and shape the AI governance strategy in collaboration with Legal, Data, Engineering, and IT stakeholders.
- Determine how key controls are implemented, tested, evidenced, and improved over time, prioritizing reliability and highly automated, low-friction evidence collection.
- Collaborate with internal and external audit stakeholders on control design, walkthroughs, exceptions, remediation, and readiness activities related to SOX and similar frameworks.
- Help consolidate overlapping control requirements from SOC 2, PCI, SOX, and internal policies into a unified operating model.
- Build continuous control monitoring and automation by identifying opportunities to replace quarterly or annual checks with near-real-time monitoring, especially for high-value controls and failure-prone workflows.
- Partner with Security Engineering, IT, Data, and platform teams to automate control testing, evidence collection, validation, and recurring compliance workflows.
- Define the logs, metadata, dashboards, and signals needed to assess control health, making compliance more observable and less reliant on manual screenshots and one-time data pulls.
- Help shift the program from detective-only controls toward stronger preventive and engineering-embedded control patterns where appropriate.
- Expand data security policy and program quality by defining and maturing policies, standards, and handling requirements that are clear, enforceable, and tied to actual technical and operational practices.
- Partner with Data, Engineering, and business stakeholders to ensure data governance is integrated into access patterns, role design, labels, masking, retention, and evidence paths.
- Establish what a high-quality GRC program looks like by defining operating cadences, ownership models, decision paths, metrics, and continuous improvement loops.
- Drive clearer documentation, standards, and guidance that both technical teams and auditors can use effectively.
- Support day-to-day GRC and assurance work where hands-on execution is needed, including control failures, remediation coordination, audit operations, and related follow-through.
- Improve the team's ability to handle questionnaires, trust requests, vendor and partner reviews, and other recurring work through better structure, reusable materials, and smarter agentic workflows.
- Act as a practical partner to teams implementing or remediating controls, not just an assessor of whether the control exists on paper.
- Lead through influence and systems thinking by owning a domain with high autonomy, leading cross-team efforts from start to finish, and improving the quality of systems, controls, and processes.
- Drive alignment across stakeholders with different incentives and constraints, making pragmatic decisions that balance risk, cost, and operational reality.
- Mentor others, improve documentation and knowledge sharing, and help raise the overall maturity of the Security Engineering and Compliance team and its partners.
Nice to Have
- Experience with scaling a unified control framework across multiple governance and compliance frameworks.
- Experience with continuous control monitoring, policy-as-code, or GRC platforms and evidence tooling.
- Familiarity with AI governance or emerging technology risk, especially where governance needs to be translated into practical technical guardrails.
Benefits
- Market competitive salary
- Stock options
- 12 paid holidays
- Flexible PTO
- 401K with company match
- Health, dental, and FSA
- Long-term disability insurance
- Mental health and family planning resources
- Remote-hybrid work from the Boston office, home, or a mixture of both
- A tremendous amount of responsibility and autonomy
- Wicked awesome co-workers
- Employee meal program and many more goodies when in the office
- Knowing that you helped transform the food for work space
Compensation
Market competitive salary, stock options, 401K with company match, health/dental/FSA, long-term disability insurance, mental health and family planning resources
Work Arrangement
Remote-hybrid work from the Boston office, home, or a mixture of both
Team
Security Engineering and Compliance team
Other
- ezCater does not sponsor applicants for work visas or legal permanent residence.
- Following a conditional offer of employment, ezCater may require a background check.
ezCater does not sponsor applicants for work visas or legal permanent residence.