Security GRC Engineer [Closed]

Employment Type: Full-time

About Us

CWILL (pronounced “quill”) is a leading eCommerce SaaS company trusted by 30,000+ Shopify & DTC brands worldwide. Our post-purchase and retention suite of tools — including order tracking, returns, shipping protection, reviews, loyalty, referrals, and AI-powered growth tools — helps merchants reduce support costs, recover revenue, and turn one-time buyers into loyal customers. 

Role Overview

We’re looking for a hands-on Security GRC Engineer to drive data compliance governance and audit execution. This is an execution-focused role — you’ll work directly with data systems and audit processes, not just write policy documents.

Core focus areas: data access controls, data lifecycle management, product data usage, cross-border data flows, and SOC 2 readiness.

Responsibilities

Data Compliance Governance

  • Support US data compliance requirements (CCPA, EO 14117, and similar)
  • Perform gap analyses and define remediation plans
  • Design and implement controls for sensitive data classification, access governance, and data lifecycle management
  • Build processes for data subject rights — deletion, access, and portability
  • Participate in product and engineering reviews (e.g., DPIAs)
  • Support compliance for new features, data use cases, and vendor/cross-border scenarios

Compliance & Audit Execution

  • Support SOC 2 readiness and end-to-end audit execution
  • Conduct access reviews, log validation, and anomaly detection
  • Maintain audit records and generate compliance reports
  • Build or improve automated evidence collection (scripting, tooling)
  • Work with internal teams and external auditors to deliver audit evidence

Requirements

Must-Haves

  • Authorized to work in the United States — no visa sponsorship available
  • Mandarin fluency preferred for day-to-day collaboration
  • Bachelor’s degree or above in Computer Science, Information Security, or a related technical field
  • 3–5 years of experience in Security, GRC, Data Security, or Data Compliance
  • Hands-on experience with at least one compliance framework (SOC 2, CCPA, GDPR, EO 14117) — beyond policy or documentation
  • Practical experience with sensitive data classification, access control, and data lifecycle management (storage, usage, deletion, portability)
  • Ability to work directly with data systems (databases, data flows, APIs) and translate compliance requirements into technical implementations
  • Basic scripting or programming skills (Python, Go, or similar) for audit automation and data validation
  • Strong cross-functional communication skills — comfortable working closely with engineering, product, data, and infra teams

Nice-to-Haves

  • Relevant certifications: CISSP, CISM, or CIPP/US
  • Experience in SaaS or e-commerce platforms (Shopify ecosystem, third-party integrations)
  • Background in data governance, data platforms, or analytics
  • Familiarity with cross-border data transfer compliance
  • Understanding of web accessibility standards (WCAG, ADA) and related privacy/security considerations

Apply for this Job

First Name
Last Name
Email
Phone number
Country/Region
Message
The form has been submitted successfully!
There has been some error while submitting the form. Please verify all form fields again.
Scroll to Top