Back

Security GRC Engineer-CA/NC-Mandarin preferred(full-time, exempt)

Worldwide Salaried Open

Location North Carolina / California, hybrid or remote

About Us

CWILL a fast-growing Shopify SaaS startup company serving global (primarily US/EU) merchants. With strong product-market fit and expanding US operations, we are building our local security and compliance capabilities to meet global data privacy standards. www.cwill.com Role Overview We are looking for a Security GRC (Governance, Risk, and Compliance) Engineer to drive data compliance governance and audit execution. This role focuses on building practical, enforceable, and auditable controls around data access, data lifecycle, product data usage, and cross-border data flows. This is a hands-on, execution-focused role working directly with data systems and audit processes (not a policy-only role). Responsibilities 1. Data Compliance Governance

  • Support US data compliance requirements (e.g., CCPA, EO 14117)
  • Perform gap analysis and define remediation plans
  • Design and implement controls for: sensitive data classification, access governance, data lifecycle management
  • Build processes for data subject rights (deletion, access, portability)
  • Participate in product and engineering reviews (e.g., DPIA)
  • Support compliance for new features, data use cases, and vendor/cross-border scenarios

2. Compliance & Audit Execution

  • Support SOC 2 readiness and audit execution
  • Conduct access reviews, log validation, and anomaly detection
  • Maintain audit records and generate compliance reports
  • Build or improve automated evidence collection (e.g., scripting)
  • Work with internal teams and external auditors to provide audit evidence

Requirements

This is a hands-on, execution-focused role working directly with data systems and audit processes (not a policy-only role). 1. Must-have:

  • Authorized to work in the United States (no visa sponsorship provided)
  • Mandarin preferred for day-to-day collaboration
  • Bachelor’s degree or above in Computer Science, Information Security, or a related technical field
  • 3–5 years of experience in Security, GRC, Data Security, or Data Compliance
  • Hands-on experience with at least one compliance framework (e.g., SOC 2, CCPA, GDPR, 14117), beyond policy or documentation
  • Practical experience in data compliance governance, including: sensitive data identification and classification, access control and access governance, data lifecycle management (storage, usage, deletion, portability)
  • Ability to work with data systems (e.g., databases, data flows, APIs) and translate compliance requirements into technical implementations
  • Basic technical capability (e.g., Python, Golang, or scripting) to support audit automation, data validation, or tooling
  • Strong cross-functional communication skills, with the ability to work closely with engineering, product, data, and infra teams

2. Nice-to-have:

  • Relevant certifications such as CISSP, CISM, or CIPP/US
  • Experience in SaaS / e-commerce platforms (e.g., Shopify ecosystem) or third-party integrations
  • Background in data governance, data platforms, or analytics
  • Familiarity with cross-border data transfer compliance
  • Understanding of web accessibility standards (e.g., WCAG, ADA) and related privacy/security considerations

Pay: $120,000.00 - $160,000.00 per year Benefits:

  • 401(k) matching
  • Flexible schedule
  • Health insurance
  • Paid time off
  • Vision insurance

Application Question(s):

  • What's your current visa status? Greencard? US Citizen?

Language:

  • Mandarin (Preferred)

Work Location: Remote Apply tot his job Apply To this Job

More jobs

ServiceNow CMDB Specialist (GRC & IRM)

Worldwide Salaried

Cybersecurity Advisor - Risk/Compliance/GRC | Raleigh or Charleston - Remote, USA

Worldwide Salaried

Security GRC Manager

Worldwide Salaried

Technical Program Manager, GRC

Worldwide Salaried

Strategic Account Lead, GRC

Worldwide Salaried

Hiring - Policy & Governance Analyst

Worldwide Salaried

IT GRC Contract Analyst

Worldwide Salaried

Governance, Risk & Compliance Analyst – Remote (PT)

Worldwide Salaried

Senior Security Analyst

Worldwide Salaried

Security Operations Center (SOC) Level 2 Quality Analyst (100% Remote)

Worldwide Salaried

Experienced Customer Service Representative – Remote Work Opportunity for Teenagers at arenaflex

Worldwide Salaried

Finance/Technical Writer

Worldwide Salaried

Intake Administrative Specialist - Allocator

Worldwide Salaried

Experienced Part-Time Remote Data Entry Clerk – Typing – Entry-Level Opportunity at arenaflex

Worldwide Salaried

Experienced Online Remote Customer Service Representative – Delivering Exceptional Travel Experiences at arenaflex

Worldwide Salaried

Experienced Entry-Level Data Entry Specialist – Remote Opportunity for Career Advancement and Growth

Worldwide Salaried

Experienced Data Entry Clerk Wanted – 25 Words Per Minute Input – Remote Opportunity with arenaflex

Worldwide Salaried

Staff Applied AI Engineer

Worldwide Salaried

Experienced Chat Support Specialist – Delivering Exceptional Customer Experience in the USA

Worldwide Salaried

Remote Data Entry & E-Commerce Product Specialist – Part-Time, No Experience Required – Work From Home Opportunity

Worldwide Salaried