Security GRC Engineer
About Us
CWILL a fast-growing Shopify SaaS startup company serving global (primarily US/EU) merchants. With strong product-market fit and expanding US operations, we are building our local security and compliance capabilities to meet global data privacy standards.
Role Overview
We are looking for a Security GRC (Governance, Risk, and Compliance) Engineer to drive data compliance governance and audit execution.
This role focuses on building practical, enforceable, and auditable controls around data access, data lifecycle, product data usage, and cross-border data flows.
This is a hands-on, execution-focused role working directly with data systems and audit processes (not a policy-only role).
Responsibilities
1. Data Compliance Governance
- Support US data compliance requirements (e.g., CCPA, EO 14117)
- Perform gap analysis and define remediation plans
- Design and implement controls for: sensitive data classification, access governance, data lifecycle management
- Build processes for data subject rights (deletion, access, portability)
- Participate in product and engineering reviews (e.g., DPIA)
- Support compliance for new features, data use cases, and vendor/cross-border scenarios
2. Compliance & Audit Execution
- Support SOC 2 readiness and audit execution
- Conduct access reviews, log validation, and anomaly detection
- Maintain audit records and generate compliance reports
- Build or improve automated evidence collection (e.g., scripting)
- Work with internal teams and external auditors to provide audit evidence
Requirements
This is a hands-on, execution-focused role working directly with data systems and audit processes (not a policy-only role).
1. Must-have:
- Authorized to work in the United States
- Mandarin preferred for day-to-day collaboration
- Bachelor’s degree or above in Computer Science, Information Security, or a related technical field
- 3–5 years of experience in Security, GRC, Data Security, or Data Compliance
- Hands-on experience with at least one compliance framework (e.g., SOC 2, CCPA, GDPR, 14117), beyond policy or documentation
- Practical experience in data compliance governance, including: sensitive data identification and classification, access control and access governance, data lifecycle management (storage, usage, deletion, portability)
- Ability to work with data systems (e.g., databases, data flows, APIs) and translate compliance requirements into technical implementations
- Basic technical capability (e.g., Python, Golang, or scripting) to support audit automation, data validation, or tooling
- Strong cross-functional communication skills, with the ability to work closely with engineering, product, data, and infra teams
2. Nice-to-have:
- Relevant certifications such as CISSP, CISM, or CIPP/US
- Experience in SaaS / e-commerce platforms (e.g., Shopify ecosystem) or third-party integrations
- Background in data governance, data platforms, or analytics
- Familiarity with cross-border data transfer compliance
- Understanding of web accessibility standards (e.g., WCAG, ADA) and related privacy/security considerations
Language:
- Mandarin (Required)
Benefits
Pay: $120,000.00 - $160,000.00 per year
- 401(k) matching
- Flexible schedule
- Health insurance
- Paid time off
- Vision insurance
Recommended Jobs
Senior Director, Integrated Communications & Public Relations
ABOUT TURNER TURNER, a Shipyard brand, is an earned-first PR & social media powerhouse with a 25+ year legacy of storytelling that inspires connection and fuels brand love. We represent some of th…
Regional Lead Transportation Design
BKF is a multi-service infrastructure consulting firm providing civil engineering and surveying services across California, the Pacific Northwest, and beyond. With offices throughout California and t…
Dental Assistant for ENDODONTIC Office
: Benefits/Perks Great Doctor Competitive Compensation Vacation and Sick Pay Bonus' Job Summary We are seeking a qualified and caring Dental Assistant to join our team! As a Dental A…
ReStore Manager, Solano-Napa Habitat for Humanity
Job Title : ReStore Manager Solano-Napa Habitat for Humanity is seeking a capable, confident, mission-driven ReStore Manager to provide strategic leadership for our ReStore operations. This rol…
ASSISTANT VFX EDITOR - Los Angeles, California
Gradient Effects, Los Angeles, is looking for an Assistant VFX Editor to join our team. Requirements include: ~Experience with Final Cut Pro ~Good knowledge of file formats, useful software and IT …
Nocturnist Physician Hospitalist - Internal Medicine
Palm Health Resources seeks Internal Medicine residency trained physicians to join a thriving, rapidly growing hospitalist practice in Southeast Alabama. The facility, a 420-bed regional referral cen…
Regional Lead/Principal Engineer & Preconstruction Manager, PE
Regional Lead/Principal Engineer & Preconstruction Manager, PE job in the San Francisco Bay Area This is a permanent, full time position that offers a great salary and benefits. Responsibilitie…
Executive Chef- Senior Living- Redwood City, CA
Executive Chef for Full Scratch Kitchen Needed Our Chefs are the creative force of our growth, the heart of our strength, and the key to our success. We are not looking for good, because we thrive …
Pediatric Dentist
We're searching for an exceptional Experienced Pediatric Dentist to join our team. If you're passionate about creating unforgettable experiences for kids, dedicated to delivering top-notch patient ca…
Administrative Assistant(Mandarin Speaking)
: Benefits: Provides employees discounts to dine at all 1500+ Haidilao Hot Pot locations globally Provides on-site staff meal Provides medical insurance to qualified full-time employees …