IT Security Engineer, Governance Risk & Compliance, Data Protection and Privacy Support

Orrick Herrington & Suttcliffe

Wheeling (WV)

Hybrid

USD 63,000 - 80,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401(k) program
Paid time off
Parental leave benefits

Job summary

Orrick Herrington & Sutcliffe is seeking an IT Security Engineer focused on Governance, Risk & Compliance (GRC), Data Protection, and Privacy Support. This role can be based in various U.S. offices or fully remote. Responsibilities include supporting audits, maintaining security documents, and collaborating with teams on compliance initiatives.

The ideal candidate will have relevant experience in network security tools and a strong foundational knowledge of cybersecurity principles. A comprehensive compensation package including health benefits awaits the right individual.

Qualifications

  • 1-2 years of experience in information security support.
  • Foundational knowledge of data protection and privacy concepts.
  • Interest in legal, financial, or business services industries.

Responsibilities

  • Support the IT Security team in regulatory requirements.
  • Assist in audits and third-party supplier assessments.
  • Maintain security compliance documents and procedures.

Skills

Network security tools
Cybersecurity knowledge
Project management skills
Teamwork and communication

Education

Associate's degree or Bachelor's degree in computer science, cybersecurity, or related field
CompTIA Security+ or Microsoft Certifications

Job description

Overview

Orrick currently has an excellent opportunity for an IT Security Engineer, Governance Risk & Compliance (GRC), Data Protection and Privacy Support. This position could be based in any of our U.S. offices and consideration given for 100% remote US locations.

Responsibilities

The IT Security Engineer supports the IT Security team in ensuring the firm meets its security objectives, regulatory requirements, and maintains strong data protection and privacy standards. This role supports client audits, third‑party supplier security assessments, and data protection and privacy initiatives under the guidance of senior team members.

  • Assist in maintaining enterprise security documents (policies, standards, baselines, guidelines, and procedures) as directed by senior staff.
  • Help in testing and updating the firm's Incident Response Plan.
  • Support the firm's ISO 27001 Certification program through documentation and evidence collection.
  • Participate in client audits and third‑party supplier security assessments by gathering information and preparing initial responses.
  • Provide administrative and technical support for GRC compliance projects.
  • Assist in implementing data protection and privacy strategies as directed by senior engineers.
  • Collaborate with legal, compliance, and privacy teams to support privacy policy alignment with regulations.
  • Monitor data protection measures under supervision and recommend minor improvements as identified.
  • Help create training materials and support team members in delivering data protection best practices.
  • Maintain awareness of trends in cybersecurity, security solutions, and threat vectors.
  • Assist in the deployment and configuration of security solutions, following established procedures.
  • Monitor security solutions for proper operation and report issues to senior staff.
  • Perform initial reviews of security logs, escalating findings as appropriate.
  • Ensure devices are configured per established security baselines under supervision.
  • Support monitoring of security solutions for efficient operations.
  • Participate in routine vulnerability assessments and security audits as directed.
  • Provide basic support for end users and IT staff on security‑related issues.
Qualifications
  • 1‑2 years of experience working with network security tools or in an information security support role.
  • Foundational knowledge of cybersecurity, data protection, and privacy concepts.
  • Experience assisting with audits or assessments preferred but not required.
  • Interest in legal, financial, or business services industries is a plus.
  • Basic understanding of Access Control Management and encryption concepts.
  • Demonstrated project management skills: ability to coordinate tasks, track deliverables, and assist with multiple, simultaneous projects under supervision.
Formal Education & Certifications
  • Associate's degree or Bachelor's degree in computer science, cybersecurity, or a related field (or equivalent experience).
  • Entry‑level certifications such as CompTIA Security+ or Microsoft Certifications preferred but not required.
Skills & Abilities
  • Willingness to learn from senior team members and adapt to new challenges.
  • Good teamwork and communication skills; ability to explain technical details to non-technical audiences with guidance.
  • Ability to handle shifting priorities in a dynamic environment with supervision.
  • Strong organizational skills with the ability to assist in managing project timelines, deliverables, and project documentation.
Additional Requirements
  • Ability to work flexible hours if needed and respond to basic security-related issues under supervision.
  • May occasionally be asked to assist with multiple projects or work with vendors under direction.
Compensation and Benefits

The expected salary range for this position is:

  • New York City, Silicon Valley, and San Francisco $70,000 - $88,000
  • Washington DC, Los Angeles, Orange County, Santa Monica, Sacramento, Boston, and Seattle $66,000 - $85,000
  • All Other US Locations $63,000 - $80,000

Orrick is committed to providing a comprehensive, competitive, and thoughtful total compensation package to our attorneys and staff, wherever they work. The compensation and benefits information is based on Orrick's estimate as of the date of publication and may be modified in the future. The level of pay within the range will depend on a variety of job‑related factors. Other compensation may include an annual discretionary merit bonus determined by firm and individual performance.

We offer a full range of elective health benefits, including medical, dental, vision and life; robust mental well‑being programs; child, family, elder, and pet care benefits; short‑ and long‑term disability and industry‑leading parental leave benefits, health savings account contributions (w/applicable medical plan), flexible spending accounts, and a 401(k) program. This role will receive compensated time off through our Paid Time Off program and paid holidays.

Equal Opportunity Employer

We are an Equal Opportunity Employer.

Consistent with the SF Fair Chance Ordinance, an arrest and conviction record will not automatically disqualify a qualified applicant from consideration.

Qualified applicants with criminal histories will be considered for the position in a manner consistent with the requirements of the Los Angeles Fair Chance Initiative for Hiring.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Engineer, Governance Risk & Compliance, Data Protection and Privacy Support
IT Security Engineer, Governance Risk & Compliance, Data Protection and Privacy Support

Orrick, Herrington & Sutcliffe LLP • United States

Hybrid
USD 63,000 - 88,000
IT Security Engineer, Governance Risk & Compliance, Data Protection and Privacy Support
IT Security Engineer, Governance Risk & Compliance, Data Protection and Privacy Support

Orrick, Herrington & Sutcliffe LLP • Seattle (WA)

Remote
USD 66,000 - 85,000
Health benefits
Mental well-being programs
Parental leave
+5
Remote IT Security Engineer: GRC, Data Privacy & Compliance
Remote IT Security Engineer: GRC, Data Privacy & Compliance

Orrick, Herrington & Sutcliffe LLP • Seattle (WA)

On-site
USD 66,000 - 85,000
Senior IT Security Engineer, Threat Response
Senior IT Security Engineer, Threat Response

Orrick, Herrington & Sutcliffe LLP • United States

Hybrid
USD 150,000 - 202,000
Comprehensive health benefits
401K program
Paid Time Off
Senior IT Security Engineer, Threat Response
Senior IT Security Engineer, Threat Response

Orrick, Herrington & Sutcliffe LLP • Washington

Remote
USD 150,000 - 187,000
Comprehensive health benefits
401K program
Paid Time Off and holidays
Cybersecurity & Incident Response Managing Associate
Cybersecurity & Incident Response Managing Associate

Orrick, Herrington & Sutcliffe LLP • Town of Boston (NY), Northern (KY)

Hybrid
USD 260,000 - 365,000
Health benefits
Mental well-being programs
Family care benefits
+3
Cybersecurity & Incident Response Managing Associate
Cybersecurity & Incident Response Managing Associate

Orrick Herrington & Suttcliffe • Washington

On-site
USD 260,000 - 365,000
Legal Solutions Architect
Legal Solutions Architect

Orrick, Herrington & Sutcliffe LLP • Austin (TX)

Hybrid
USD 101,000 - 140,000
Health benefits
401K program
Flexible Time Off
Legal Solutions Architect
Legal Solutions Architect

Orrick, Herrington & Sutcliffe LLP • Northern (KY)

Hybrid
USD 101,000 - 140,000
Health benefits
401K program
Flexible Time Off
+2
Remote IT Security & GRC Specialist - Data Privacy & Audits
Remote IT Security & GRC Specialist - Data Privacy & Audits

Orrick Herrington & Suttcliffe • Wheeling (WV)

Hybrid
USD 63,000 - 80,000
Health insurance
401(k) program
Paid time off
+1