Security GRC Engineer

10 hours, 20 minutes ago
Full-time
Mid Level
DevOps and Infrastructure
CWILL

CWILL

CWILL provides post-purchase and retention solutions specifically designed for Shopify merchants, aiming to enhance customer experiences and increase customer lifetime value through effective engagement strategies.

Professional Services
Founded 2014

Description

  • Support US data compliance requirements, including CCPA and EO 14117.
  • Perform gap analyses and define remediation plans for compliance issues.
  • Design and implement controls for sensitive data classification, access governance, and data lifecycle management.
  • Build processes for data subject rights requests, including deletion, access, and portability.
  • Participate in product and engineering reviews, including DPIAs and new feature assessments.
  • Support compliance reviews for new data use cases, vendors, and cross-border scenarios.
  • Support SOC 2 readiness and audit execution.
  • Conduct access reviews, log validation, and anomaly detection.
  • Maintain audit records and generate compliance reports.
  • Build or improve automated evidence collection and work with internal teams and external auditors to provide audit evidence.

Requirements

  • Authorized to work in the United States.
  • Mandarin is preferred for day-to-day collaboration, and Mandarin is required.
  • Bachelor’s degree or above in Computer Science, Information Security, or a related technical field.
  • 3–5 years of experience in Security, GRC, Data Security, or Data Compliance.
  • Hands-on experience with at least one compliance framework such as SOC 2, CCPA, GDPR, or EO 14117 beyond policy or documentation work.
  • Practical experience in data compliance governance, including sensitive data identification and classification, access control, access governance, and data lifecycle management.
  • Ability to work with data systems such as databases, data flows, and APIs and translate compliance requirements into technical implementations.
  • Basic technical capability in Python, Golang, or scripting to support audit automation, data validation, or tooling.
  • Strong cross-functional communication skills and experience working with engineering, product, data, and infrastructure teams.
  • Preferred certifications such as CISSP, CISM, or CIPP/US, plus experience in SaaS/e-commerce platforms, third-party integrations, data governance, data platforms, analytics, cross-border data transfer compliance, or web accessibility standards such as WCAG and ADA.

Benefits

  • Salary range of $120,000 to $160,000 per year.
  • 401(k) matching.
  • Flexible schedule.
  • Health insurance.
  • Paid time off.
  • Vision insurance.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Incident Response Engineer

Accenture 100K+ Professional Services

Accenture Federal Services is hiring an Incident Response Engineer to lead security incident response and investigation efforts supporting US federal government missions.

Cybersecurity SIEM
9 hours, 35 minutes ago

Senior IAM Architect

Ping Identity 1K-5K IT Services

Ping Identity is hiring a Senior IAM Architect to lead its internal identity and access management practice across workforce and customer environments, with the goal of keeping the company’s identity platforms secure, scalable, and operationally effective.

CI/CD OAuth OpenID Connect REST API SAML Terraform
9 hours, 50 minutes ago

GRC Process Architect

Accenture 100K+ Professional Services

Accenture Federal Services is hiring a Security Architect to strengthen federal security architecture by identifying enterprise risks, guiding secure-by-design solutions, and improving architecture across systems, applications, and cloud environments.

Agile Network Security SFTP TLS
9 hours, 50 minutes ago

Cyber Security Engineer III

Ping Identity 1K-5K IT Services

Ping Identity is hiring a Cyber Security Engineer III to strengthen and automate security operations across its SaaS and enterprise systems, with a focus on incident response, secure system design, and security engineering.

AWS Docker GCP Go Kubernetes
9 hours, 50 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers