About The RoleWe're building our first formal IT change management practice from the ground up. Today, changes to production systems, infrastructure, and business-critical applications move fast and informally - which has served us well as a startup, but won't scale as we grow into an enterprise. We're not looking to bolt on a heavyweight, bureaucratic change process. We need a "lite," ITIL-aligned model that a fast-moving engineering and IT organization will actually use - one that captures the right approvals and audit trail without slowing teams down. This role starts as an internal advisor and consultant: you'll design the model, prove its value team by team, and only formalize/mandate adoption once you've earned trust and demonstrated real benefit. Over time, this process becomes a key control supporting our establishing enterprise level structure that will meet ITIL and Soc2 standards readiness and audit requirements.
Design & own the change management model- Design a lightweight, ITIL 4-aligned change enablement model appropriate for a fast-growing company - standard, normal, and emergency change categories; risk-based approval paths; delegated authority for low-risk/standard changes.
- Define the roles, responsibilities, and RACI for requesting, reviewing, approving, and closing changes across Engineering, IT, and Security.
- Build the roadmap for evolving the process over time: advisory and opt-in in year one, progressively more structured and eventually mandatory as the organization matures toward establishing enterprise level structure that will meet ITIL and Soc2 standards.
Lead through influence, not authority- Act as an internal consultant/advisor to engineering and IT teams - explain the "why" behind change management, tailor the pitch to each team, and win voluntary adoption before any process is mandated.
- Partner with engineering leaders to pilot the process on select teams, gather feedback, and iterate quickly.
- Build the case (with data) for why broader, eventually mandatory adoption benefits the business - fewer failed changes, faster audits, establishing enterprise level structure that will meet ITIL and Soc2 standards readiness - and present it to leadership.
Build and automate the tooling- Select and configure the tooling stack (e.g., Jira/Jira Service Management, Monday.com, or similar) to capture change requests, approvals, risk assessments, and implementation records.
- Design and build automated workflows - routing, notifications, approval gates, status transitions, and escalations - so the process runs with minimal manual overhead.
- Stand up AI-assisted agents/automations that generate structured, auditable change logs (who changed what, when, why, and who approved it) to support future compliance and audit needs.
- Build a change calendar, freeze-window management, and conflict detection across teams and systems.
Govern, measure, and report- Define and track change management KPIs: change success rate, failed/rolled-back change rate, emergency change percentage, cycle time, and audit findings.
- Run lightweight change advisory reviews for higher-risk changes; keep the bar for standard/low-risk changes fast and largely automated.
- Partner with Security, Compliance, and (eventually) Internal Audit to ensure the process satisfies SOX ITGC change-management control expectations.
- Continuously refine the process based on incident retrospectives, audit feedback, and stakeholder input.
What You'll Bring- 7+ years in IT service management, IT change management, or a closely related discipline, ideally including building a change process from scratch (0-to-1) at a scaling company.
- Working knowledge of ITIL 4 change enablement principles (standard/normal/emergency changes, risk-based approval, delegated change authority); ITIL 4 Foundation certification preferred.
- Hands-on experience configuring and administering Jira (Jira Service Management), Monday.com, or comparable ITSM/work-management platforms - including building automation rules and workflows, not just using out-of-the-box features.
- Comfort with low-code/no-code automation (Jira Automation, Workato, Zapier, or similar); experience applying AI tools or agents to generate documentation, summaries, or audit trails is a strong plus.
- Familiarity with SOX IT general controls (ITGC), audit evidence requirements, or prior experience at a company preparing for a SOC 2 audit.
- Demonstrated ability to drive adoption of a new process through influence and relationship-building rather than positional authority - you'll need buy-in before you'll have a mandate.
- Strong written and verbal communication skills; able to translate technical processes into clear, concise guidance for engineers and executives alike.
- Experience operating in a high-growth technology company transitioning from startup to enterprise-grade operating rigor.
Nice to Have- Background in DevOps/SRE practices and CI/CD pipelines, and how change enablement integrates with continuous delivery.
- Experience with GRC or audit-management tooling (e.g., Vanta, Drata, ServiceNow GRC).
- Prior experience building IT controls in preparation for an IPO or SOC 2 Type II audit.
- Healthcare, fintech, or other regulated-industry experience.