IT Security Engineer, Governance Risk & Compliance, Data Protection and Privacy Support

Orrick, Herrington & Sutcliffe LLP

Seattle (WA)

Remote

USD 66,000 - 85,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
Mental well-being programs
Parental leave
401K program
HSA contributions
Flexible spending accounts
Disability benefits
Paid holidays

Job summary

Orrick, Herrington & Sutcliffe LLP is seeking an IT Security Engineer specializing in Governance, Risk & Compliance, Data Protection and Privacy Support. This role can be based in any US office or remotely within the United States, supporting client audits, third-party assessments and privacy initiatives under senior guidance.

The position emphasizes collaboration with legal, compliance and IT teams, and involves maintaining security documents, contributing to the Incident Response plan, ISO

Qualifications

  • Foundational knowledge of cybersecurity, data protection, and privacy concepts.
  • Experience assisting with audits or assessments is preferred but not required.
  • Interest in legal or financial services is a plus.

Responsibilities

  • Assist in maintaining enterprise security documents (policies, standards, baselines, guidelines, procedures).
  • Support the firm's ISO 27001 Certification program through documentation and evidence collection.
  • Participate in client audits and third-party supplier security assessments by gathering information and preparing initial responses.
  • Provide administrative and technical support for GRC compliance projects.
  • Assist in implementing data protection and privacy strategies under supervision.
  • Collaborate with legal, compliance, and privacy teams to align policies with regulations.

Skills

Cybersecurity knowledge
Data protection concepts
Privacy concepts
Project management
Teamwork & communication
Adaptability
Security incident awareness

Education

Associate’s degree in computer science / cybersecurity
Bachelor’s degree in computer science / cybersecurity
Entry-level certifications (CompTIA Security+ / Microsoft Certifications)

Tools

Network security tools

Job description

Orrick

Orrick currently has an excellent opportunity for an IT Security Engineer, Governance Risk & Compliance (GRC), Data Protection and Privacy Support. This position could be based in any of our U.S. offices and consideration given for 100% remote US locations.

Responsibilities

The IT Security Engineer, Governance Risk & Compliance (GRC), Data Protection and Privacy Support, assists the IT Security team in ensuring the firm meets its security objectives, regulatory requirements, and maintains strong data protection and privacy standards. This position supports client audits, third-party supplier security assessments, and data protection and privacy initiatives under the guidance of senior team members.

Governance, Risk & Compliance Support
  • Assist in maintaining enterprise security documents (policies, standards, baselines, guidelines, and procedures) as directed by senior staff.
  • Help in testing and updating the firm's Incident Response Plan.
  • Support the firm's ISO 27001 Certification program through documentation and evidence collection.
  • Participate in client audits and third-party supplier security assessments by gathering information and preparing initial responses.
  • Provide administrative and technical support for GRC compliance projects.
Data Protection and Privacy Support
  • Assist in implementing data protection and privacy strategies as directed by senior engineers.
  • Collaborate with legal, compliance, and privacy teams to support privacy policy alignment with regulations.
  • Monitor data protection measures under supervision and recommend minor improvements as identified.
  • Help create training materials and support team members in delivering data protection best practices.
Cybersecurity Support
  • Maintain awareness of trends in cybersecurity, security solutions, and threat vectors.
  • Assist in the deployment and configuration of security solutions, following established procedures.
  • Monitor security solutions for proper operation and report issues to senior staff.
  • Perform initial reviews of security logs, escalating findings as appropriate.
Operational Management
  • Ensure devices are configured per established security baselines under supervision.
  • Support monitoring of security solutions for efficient operations.
  • Participate in routine vulnerability assessments and security audits as directed.
  • Provide basic support for end users and IT staff on security-related issues.
Qualifications
  • 1–2 years of experience working with network security tools or in an information security support role.
  • Foundational knowledge of cybersecurity, data protection, and privacy concepts.
  • Experience assisting with audits or assessments preferred but not required.
  • Interest in legal, financial, or business services industries is a plus.
  • Basic understanding of Access Control Management and encryption concepts.
  • Demonstrated project management skills: ability to coordinate tasks, track deliverables, and assist with multiple, simultaneous projects under supervision.
Formal Education & Certifications
  • Associate’s degree or Bachelor’s degree in computer science, cybersecurity, or a related field (or equivalent experience).
  • Entry-level certifications such as CompTIA Security+ or Microsoft Certifications preferred but not required.
Skills & Abilities
  • Willingness to learn from senior team members and adapt to new challenges.
  • Good teamwork and communication skills; ability to explain technical details to non-technical audiences with guidance.
  • Ability to handle shifting priorities in a dynamic environment with supervision.
  • Strong organizational skills with the ability to assist in managing project timelines, deliverables, and project documentation.
Additional Requirements
  • Ability to work flexible hours if needed and respond to basic security-related issues under supervision.
  • May occasionally be asked to assist with multiple projects or work with vendors under direction.
Compensation and Benefits
  • New York City, Silicon Valley, and San Francisco $70,000 - $88,000
  • Washington DC, Los Angeles, Orange County, Santa Monica, Sacramento, Boston, and Seattle $66,000 - $85,000
  • All Other US Locations $63,000 - $80,000

We offer a full range of elective health benefits including medical, dental, vision and life; robust mental well-being programs; child, family, elder, and pet care benefits; short- and long-term disability and industry leading parental leave benefits, health savings account contributions (w/applicable medical plan), flexible spending accounts, and a 401K program. This role will receive compensated time off through our Paid Time Off program and paid holidays.

We are an Equal Opportunity Employer.

Consistent with the SF Fair Chance Ordinance, an arrest and conviction record will not automatically disqualify a qualified applicant from consideration.

Qualified applicants with criminal histories will be considered for the position in a manner consistent with the requirements of the Los Angeles Fair Chance Initiative for Hiring.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Engineer, Governance Risk & Compliance, Data Protection and Privacy Support
IT Security Engineer, Governance Risk & Compliance, Data Protection and Privacy Support

Orrick, Herrington & Sutcliffe LLP • Austin (TX)

On-site
USD 63,000 - 80,000
Comprehensive health benefits
401K program
Paid Time Off program
Remote IT Security Engineer: GRC, Data Privacy & Compliance
Remote IT Security Engineer: GRC, Data Privacy & Compliance

Orrick, Herrington & Sutcliffe LLP • Seattle (WA)

On-site
USD 66,000 - 85,000
Remote IT Security Engineer | GRC & Data Privacy
Remote IT Security Engineer | GRC & Data Privacy

Orrick, Herrington & Sutcliffe LLP • Austin (TX)

On-site
Senior IT Security Engineer, Threat Response
Senior IT Security Engineer, Threat Response

Orrick, Herrington & Sutcliffe LLP • United States

Hybrid
USD 150,000 - 202,000
Comprehensive health benefits
401K program
Paid Time Off
Senior IT Security Engineer, Threat Response
Senior IT Security Engineer, Threat Response

Orrick, Herrington & Sutcliffe LLP • Washington

Remote
USD 150,000 - 187,000
Comprehensive health benefits
401K program
Paid Time Off and holidays
Cybersecurity & Incident Response Managing Associate
Cybersecurity & Incident Response Managing Associate

Orrick, Herrington & Sutcliffe LLP • Town of Boston (NY), Northern (KY)

Hybrid
USD 260,000 - 365,000
Health benefits
Mental well-being programs
Family care benefits
+3
Senior Business Development Manager - Cyber & Data Privacy Regulatory
Senior Business Development Manager - Cyber & Data Privacy Regulatory

Orrick, Herrington & Sutcliffe LLP • Washington

Hybrid
USD 132,000 - 210,000
Medical, dental, and vision benefits
Flexible time off
401K program
Senior Business Development Manager - Cyber & Data Privacy Regulatory
Senior Business Development Manager - Cyber & Data Privacy Regulatory

Orrick, Herrington & Sutcliffe LLP • San Francisco (CA)

On-site
USD 147,000 - 220,000
Comprehensive health benefits
401K program
Flexible Time Off program
Legal Solutions Architect
Legal Solutions Architect

Orrick, Herrington & Sutcliffe LLP • California (MO)

On-site
USD 101,000 - 140,000
Legal Solutions Architect
Legal Solutions Architect

Orrick, Herrington & Sutcliffe LLP • Austin (TX)

On-site
USD 101,000 - 140,000