Security GRC Engineer [Open]

California, United States · 29 Oct 2025

Employment Type: Full-time

About Us

CWILL (pronounced “quill”) is a leading eCommerce SaaS company trusted by 30,000+ Shopify & DTC brands worldwide. Our post-purchase and retention suite of tools — including order tracking, returns, shipping protection, reviews, loyalty, referrals, and AI-powered growth tools — helps merchants reduce support costs, recover revenue, and turn one-time buyers into loyal customers. 

Role Overview

We’re looking for a hands-on Security GRC Engineer to drive data compliance governance and audit execution. This is an execution-focused role — you’ll work directly with data systems and audit processes, not just write policy documents.

Core focus areas: data access controls, data lifecycle management, product data usage, cross-border data flows, and SOC 2 readiness.

Responsibilities

Data Compliance Governance

  • Support US data compliance requirements (CCPA, EO 14117, and similar)
  • Perform gap analyses and define remediation plans
  • Design and implement controls for sensitive data classification, access governance, and data lifecycle management
  • Build processes for data subject rights — deletion, access, and portability
  • Participate in product and engineering reviews (e.g., DPIAs)
  • Support compliance for new features, data use cases, and vendor/cross-border scenarios

Compliance & Audit Execution

  • Support SOC 2 readiness and end-to-end audit execution
  • Conduct access reviews, log validation, and anomaly detection
  • Maintain audit records and generate compliance reports
  • Build or improve automated evidence collection (scripting, tooling)
  • Work with internal teams and external auditors to deliver audit evidence

Requirements

Must-Haves

  • Authorized to work in the United States — no visa sponsorship available
  • Mandarin fluency preferred for day-to-day collaboration
  • Bachelor’s degree or above in Computer Science, Information Security, or a related technical field
  • 3–5 years of experience in Security, GRC, Data Security, or Data Compliance
  • Hands-on experience with at least one compliance framework (SOC 2, CCPA, GDPR, EO 14117) — beyond policy or documentation
  • Practical experience with sensitive data classification, access control, and data lifecycle management (storage, usage, deletion, portability)
  • Ability to work directly with data systems (databases, data flows, APIs) and translate compliance requirements into technical implementations
  • Basic scripting or programming skills (Python, Go, or similar) for audit automation and data validation
  • Strong cross-functional communication skills — comfortable working closely with engineering, product, data, and infra teams

Nice-to-Haves

  • Relevant certifications: CISSP, CISM, or CIPP/US
  • Experience in SaaS or e-commerce platforms (Shopify ecosystem, third-party integrations)
  • Background in data governance, data platforms, or analytics
  • Familiarity with cross-border data transfer compliance
  • Understanding of web accessibility standards (WCAG, ADA) and related privacy/security considerations

Apply for this Job

First Name
Last Name
Email
Phone number
Country/Region
Message
The form has been submitted successfully!
There has been some error while submitting the form. Please verify all form fields again.
CWILL, the outstanding eCommerce post-purchase and marketing solution platform, especially as a Shopify expert, empowers over 300,000 Shopify and Shopify Plus merchants to grow their brands, like DJI, Unilever, Joseph Joseph, and KACHAVA to achieve substantial growth in online businesses. 
Scroll to Top