Ezcaterinc

Ezcaterinc

Staff GRC Engineer (Remote)

Boston, MA · Staff+

Sponsorship not specifiedDetected 8 days ago
GitAWSTerraformAgentic AICybersecurityComplianceAuditingCommunicationCollaborationInternal Audit

About the role

  • For workplaces, ezCater provides flexible and scalable solutions for everything from employee meal programs to one-off meetings, all backed by 24/7 service and business-grade reliability.
  • This is not a narrow audit coordinator or policy only role.

Responsibilities

  • Lead control program maturity
  • Design and maintain an auditable control framework that fits ezCater's SaaS, cloud, data, and engineering environment rather than forcing generic controls onto modern systems.
  • Partner with internal and external audit stakeholders on control design, walkthroughs, exceptions, remediation, and readiness activities tied to SOX and related frameworks.
  • Build continuous control monitoring and automation
  • Partner with Security Engineering, IT, Data, and platform teams to automate control testing, evidence collection, validation, and recurring compliance workflows.
  • Partner with Data, Engineering, and business stakeholders to ensure data governance shows up in meaningful places such as access patterns, role design, labels, masking, retention, and evidence paths.
  • Drive clearer documentation, standards, and guidance that both technical teams and auditors can use effectively.
  • Drive operational quality improvements
  • Support day-to-day GRC and assurance work where hands-on execution is needed to keep the program moving, including control failures, remediation coordination, audit operations, and related follow-through.
  • Improve the team's ability to handle questionnaires, trust requests, vendor and partner reviews, and other recurring work through better structure, reusable materials, and smarter agentic workflows.

Requirements

  • Strong experience with security compliance frameworks such as ISO-27001, NIST CSF, SOC 2, ITGC, and PCI-DSS, including how to translate framework requirements into controls that work in real systems and teams.
  • Demonstrated ability to automate or instrument parts of a compliance or assurance program through scripting, APIs, dashboards, platform configuration, or other technical approaches.
  • Familiarity with governing and securing AI/Agentic systems and business processing.
  • Strong written communication and cross-functional influence skills, with the ability to explain controls, trade-offs, and program expectations to both technical and non-technical audiences.

Compensation

  • Identify where quarterly or annual checks should become continuous or near-real-time monitoring, especially for high-value controls and failure-prone workflows.

Benefits

  • Define the logs, metadata, dashboards, and signals needed to assess control health and make compliance more observable and less dependent on screenshots and one-off pulls.

This listing is sourced directly from Ezcaterinc's careers page and normalized into a canonical job model.