JobBobsReal-time global job discoveryLive

Staff GRC Engineer (Remote)

Ezcaterinc · Boston, MA · 2026-07-14

executiveRemote
Apply on the employer's site

About this role

<div class="content-intro"><p><span style="font-family: helvetica, arial, sans-serif;">ezCater is the #1 food tech platform for workplaces in the US. The company makes it easy for any organization to manage its food needs and order from over 125,000 restaurants nationwide. For workplaces, ezCater provides flexible and scalable solutions for everything from employee meal programs to one-off meetings, all backed by beyond helpful 24/7 service and business-grade reliability. For restaurant partners, ezCater helps grow their business by bringing them new high-value customers and large orders.</span></p></div><p class="wnfdntt _1ibi0s3f5 _1ibi0s3ce _1ibi0s3ea" style="line-height: 1.5;" data-pm-slice="1 1 []"><span style="font-size: 10pt;">e<span style="font-family: helvetica, arial, sans-serif; font-size: 12pt;">zCater is looking for a Staff GRC Engineer to join the Security Engineering & Compliance team as a technical leader who can help mature our governance, risk, compliance, and data security capabilities in a way that is durable, measurable, and embedded into how our systems operate day to day. This is not a narrow audit coordinator or policy only role. We’re looking for a balanced builder-operator who can raise the quality and maturity of our security controls by expanding control monitoring, strengthening data security governance, automating and instrumenting the program where stronger evidence and better monitoring are needed, and improving the operational follow through that makes the program scalable, sustainable, and effective.</span></span><br><br></p> <p style="line-height: 1.5;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><strong>What You'll Do:</strong></span></p> <ul> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"> <h2><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Lead control program maturity</span></h2> <ul> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Design and maintain an auditable control framework that fits ezCater’s SaaS, cloud, data, and engineering environment rather than forcing generic controls onto modern systems.</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Shape and define ezCater’s AI Governance strategy with stakeholders across the Legal, Data, Engineering, and IT domains. </span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Define how key controls are implemented, tested, evidenced, and improved over time, with a strong bias toward reliability and highly-automated, low/no friction evidence paths.</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Partner with internal and external audit stakeholders on control design, walkthroughs, exceptions, remediation, and readiness activities tied to SOX and related frameworks.</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Help rationalize overlapping control requirements across SOC 2, PCI, SOX, and internal policy expectations into a coherent operating model.</span></li> </ul> </li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"> <h2><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Build continuous control monitoring and automation</span></h2> <ul> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Identify where quarterly or annual checks should become continuous or near-real-time monitoring, especially for high-value controls and failure-prone workflows.</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Partner with Security Engineering, IT, Data, and platform teams to automate control testing, evidence collection, validation, and recurring compliance workflows.</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Define the logs, metadata, dashboards, and signals needed to assess control health and make compliance more observable and less dependent on screenshots and one-off pulls.</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Help shift the program from detective-only controls toward stronger preventive and engineering-embedded control patterns where appropriate.</span></li> </ul> </li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"> <h2><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Expand data…

Skills asked for

Apply on the employer's site

Your next role is already in here.

Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.