Lead IT & Privacy Auditor - U.S. Privacy and Data Security Audit
VeSync - Tustin, CA
Hiring: Lead IT & Privacy Auditor - U.S. Privacy and Data Security Audit Company: VeSync Location: Tustin, CA Job Posted Time: 2026-09-10 10:46:22 Employment Type: On-site Target Skills & Keywords : Data Warehouse, Encryption, GDPR, HIPAA, Microsoft Excel, Python, Risk Management, SOC 2, SQL, Shell About the job Experience: •5+ years of experience in IT audit, information security audit, privacy compliance audit, data security, GRC, internal controls, or related areas. Experience with U.S. companies, multinational companies, technology, IoT, app, DTC, e-commerce, or consumer data businesses is preferred. Required Skills: •Conduct risk-based audits of applications, data warehouses, databases, cloud platforms, business processes, and third-party data processing activities involving personal information and sensitive data in U.S. business operations. •Evaluate whether IT processes, system operations, and data processing activities comply with internal data protection policies, privacy control requirements, information security controls, and applicable regulatory requirements. •Test the design and operating effectiveness of controls related to data minimization, notice and consent, consumer privacy rights response, access control, encryption, data masking, data retention, deletion, and destruction. •Lead or support U.S. data compliance audit projects covering website and app data collection, cookie and tracking technologies, third-party data sharing, vendor data processing, cloud data protection, cross-border data access, and access management. •Manage or participate in the full audit lifecycle, including audit scoping, audit planning, data processing activity mapping, risk assessment, control testing, interviews, evidence collection, sample testing, data analysis, workpaper documentation, audit report drafting, and remediation follow-up. •Translate privacy, data protection, information security, and internal policy requirements into testable audit control points, audit procedures, evidence requirements, risk assessment criteria, and remediation tracking mechanisms. •Interface directly with Legal, Information Security, IT, Data, Product, Marketing, Operations, and business teams to validate audit findings, assess risk levels, develop remediation plans, and track remediation to closure. •Support internal assessment, control testing, external advisor/audit support, and remediation tracking related to EO 14117, the DOJ Data Security Program, and other U.S. data security regulatory requirements. Qualifications: •Operational familiarity with one or more privacy, security, or audit frameworks, such as the NIST Privacy Framework, GDPR, NIST SP 800-122, ISO 27701, ISO 27001, SOC 2, HIPAA or IAPP privacy management methodologies. •Understanding of FTC privacy and data security enforcement expectations, U.S. state privacy laws, EO 14117, the DOJ Data Security Program, or related requirements. Experience with related assessments, audits, vendor risk management, cross-border data access controls, or remediation is a plus. •Data analysis capability using Excel, audit tools, SQL, or other tools for sample extraction, access list analysis, log review, data flow validation, and anomaly identification. Experience with Python, Shell, or audit automation is a plus. •Professional certifications such as CISA, CIPP/US, CIPM, CDPSE, CIPT, CISSP, CISM, CRISC, or other privacy, IT audit, information security, or data governance certifications are preferred. •This is an on-site, office-based role in Tustin, CA. Compensation: •100% covered Medical/Dental/Vision for employee AND spouse + dependents! Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!