IT Security Engineer, Governance Risk & Compliance, Data Protection and Privacy Support

Orrick, Herrington & Sutcliffe LLP

Austin (TX)

On-site

USD 63,000 - 80,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Comprehensive health benefits
401K program
Paid Time Off program

Job summary

Orrick, Herrington & Sutcliffe LLP offers an excellent opportunity for an IT Security Engineer focusing on Governance Risk & Compliance (GRC). The position can be based in any US office or be 100% remote.

This role involves assisting the IT Security team in maintaining security standards, supporting audits, and implementing data protection strategies. Candidates should have a foundation in cybersecurity and project management.

The expected salary range for this role varies depending on location, with comprehensive benefits including health, wellness programs, and flexible hours.

Qualifications

  • 1–2 years of experience in information security support.
  • Foundational knowledge of data protection and cybersecurity.
  • Interest in the legal or financial services industries.

Responsibilities

  • Assist in maintaining enterprise security documents.
  • Support ISO 27001 Certification program.
  • Monitor data protection measures.

Skills

Network security tools
Cybersecurity concepts
Data protection
Project management
Communication

Education

Associate’s or Bachelor’s degree in computer science or cybersecurity

Tools

Audit tools
Incident Response Plan

Job description

Orrick

Orrick currently has an excellent opportunity for an IT Security Engineer, Governance Risk & Compliance (GRC), Data Protection and Privacy Support. This position could be based in any of our U.S. offices and consideration given for 100% remote US locations.

Responsibilities

The IT Security Engineer, Governance Risk & Compliance (GRC), Data Protection and Privacy Support, assists the IT Security team in ensuring the firm meets its security objectives, regulatory requirements, and maintains strong data protection and privacy standards. This position supports client audits, third-party supplier security assessments, and data protection and privacy initiatives under the guidance of senior team members.

Governance, Risk & Compliance Support
  • Assist in maintaining enterprise security documents (policies, standards, baselines, guidelines, and procedures) as directed by senior staff.
  • Help in testing and updating the firm's Incident Response Plan.
  • Support the firm's ISO 27001 Certification program through documentation and evidence collection.
  • Participate in client audits and third-party supplier security assessments by gathering information and preparing initial responses.
  • Provide administrative and technical support for GRC compliance projects.
Data Protection and Privacy Support
  • Assist in implementing data protection and privacy strategies as directed by senior engineers.
  • Collaborate with legal, compliance, and privacy teams to support privacy policy alignment with regulations.
  • Monitor data protection measures under supervision and recommend minor improvements as identified.
  • Help create training materials and support team members in delivering data protection best practices.
Cybersecurity Support
  • Maintain awareness of trends in cybersecurity, security solutions, and threat vectors.
  • Assist in the deployment and configuration of security solutions, following established procedures.
  • Monitor security solutions for proper operation and report issues to senior staff.
  • Perform initial reviews of security logs, escalating findings as appropriate.
Operational Management
  • Ensure devices are configured per established security baselines under supervision.
  • Support monitoring of security solutions for efficient operations.
  • Participate in routine vulnerability assessments and security audits as directed.
  • Provide basic support for end users and IT staff on security-related issues.
Qualifications
  • 1–2 years of experience working with network security tools or in an information security support role.
  • Foundational knowledge of cybersecurity, data protection, and privacy concepts.
  • Experience assisting with audits or assessments preferred but not required.
  • Interest in legal, financial, or business services industries is a plus.
  • Basic understanding of Access Control Management and encryption concepts.
  • Demonstrated project management skills: ability to coordinate tasks, track deliverables, and assist with multiple, simultaneous projects under supervision.
Formal Education & Certifications
  • Associate’s degree or Bachelor’s degree in computer science, cybersecurity, or a related field (or equivalent experience).
  • Entry-level certifications such as CompTIA Security+ or Microsoft Certifications preferred but not required.
Skills & Abilities
  • Willingness to learn from senior team members and adapt to new challenges.
  • Good teamwork and communication skills; ability to explain technical details to non-technical audiences with guidance.
  • Ability to handle shifting priorities in a dynamic environment with supervision.
  • Strong organizational skills with the ability to assist in managing project timelines, deliverables, and project documentation.
Additional Requirements
  • Ability to work flexible hours if needed and respond to basic security-related issues under supervision.
  • May occasionally be asked to assist with multiple projects or work with vendors under direction.
Compensation and Benefits
  • New York City, Silicon Valley, and San Francisco $70,000 - $88,000
  • Washington DC, Los Angeles, Orange County, Santa Monica, Sacramento, Boston, and Seattle $66,000 - $85,000
  • All Other US Locations $63,000 - $80,000

We offer a full range of elective health benefits including medical, dental, vision and life; robust mental well-being programs; child, family, elder, and pet care benefits; short- and long-term disability and industry leading parental leave benefits, health savings account contributions (w/applicable medical plan), flexible spending accounts, and a 401K program. This role will receive compensated time off through our Paid Time Off program and paid holidays.

We are an Equal Opportunity Employer.

Consistent with the SF Fair Chance Ordinance, an arrest and conviction record will not automatically disqualify a qualified applicant from consideration.

Qualified applicants with criminal histories will be considered for the position in a manner consistent with the requirements of the Los Angeles Fair Chance Initiative for Hiring.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Engineer, Governance Risk & Compliance, Data Protection and Privacy Support
IT Security Engineer, Governance Risk & Compliance, Data Protection and Privacy Support

Orrick, Herrington & Sutcliffe LLP • Seattle (WA)

Remote
USD 66,000 - 85,000
Health benefits
Mental well-being programs
Parental leave
+5
Remote IT Security Engineer: GRC, Data Privacy & Compliance
Remote IT Security Engineer: GRC, Data Privacy & Compliance

Orrick, Herrington & Sutcliffe LLP • Seattle (WA)

On-site
USD 66,000 - 85,000
Remote IT Security Engineer | GRC & Data Privacy
Remote IT Security Engineer | GRC & Data Privacy

Orrick, Herrington & Sutcliffe LLP • Austin (TX)

On-site
Senior IT Security Engineer, Threat Response
Senior IT Security Engineer, Threat Response

Orrick, Herrington & Sutcliffe LLP • Washington

Remote
USD 150,000 - 187,000
Comprehensive health benefits
401K program
Paid Time Off and holidays
Senior IT Security Engineer, Threat Response
Senior IT Security Engineer, Threat Response

Orrick, Herrington & Sutcliffe LLP • United States

Hybrid
USD 150,000 - 202,000
Comprehensive health benefits
401K program
Paid Time Off
Cybersecurity & Incident Response Managing Associate
Cybersecurity & Incident Response Managing Associate

Orrick, Herrington & Sutcliffe LLP • Town of Boston (NY), Northern (KY)

Hybrid
USD 260,000 - 365,000
Health benefits
Mental well-being programs
Family care benefits
+3
Senior Business Development Manager - Cyber & Data Privacy Regulatory
Senior Business Development Manager - Cyber & Data Privacy Regulatory

Orrick, Herrington & Sutcliffe LLP • San Francisco (CA)

On-site
USD 147,000 - 220,000
Comprehensive health benefits
401K program
Flexible Time Off program
Senior Business Development Manager - Cyber & Data Privacy Regulatory
Senior Business Development Manager - Cyber & Data Privacy Regulatory

Orrick, Herrington & Sutcliffe LLP • Washington

Hybrid
USD 132,000 - 210,000
Medical, dental, and vision benefits
Flexible time off
401K program
Legal Solutions Architect
Legal Solutions Architect

Orrick, Herrington & Sutcliffe LLP • California (MO)

On-site
USD 101,000 - 140,000
Legal Solutions Architect
Legal Solutions Architect

Orrick, Herrington & Sutcliffe LLP • Austin (TX)

On-site
USD 101,000 - 140,000