Lead IT & Privacy Auditor - U.S. Privacy and Data Security Audit

Vesync

Tustin (CA)

On-site

USD 108,000 - 132,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

100% covered Medical/Dental/Vision for
401K with 4% employer match
Generous Sick + Vacation
Life Insurance
Disability Insurance
Critical Illness Coverage
Voluntary Life Insurance
Travel Assistance Program
Fully stocked kitchen

Job summary

VeSync seeks a Lead IT & Privacy Auditor to audit personal information and sensitive data processing across Americas, with cross‑border scope. You will identify control gaps, test design and operating effectiveness, and drive remediation with Legal, IT, and business teams.

You will cover website/app data collection, cookies/tracking, third‑party data sharing, vendor data processing, cross‑border access, and data retention practices, ensuring regulatory compliance and risk mitigation.

Qualifications

  • Bachelor’s degree or above in Information Systems, Computer Science, Information Security, Audit, Law, Compliance, Information Management, or a related field.
  • 5+ years of experience in IT audit, information security audit, privacy compliance audit, data security, GRC, internal controls, or related areas.
  • Strong understanding of IT audit, control testing, risk assessment, audit evidence collection, workpaper documentation, audit finding development, audit reporting, and remediation tracking.
  • Working knowledge of core U.S. privacy and data protection requirements, including CCPA/CPRA, consumer privacy rights, personal information processing, third‑party data sharing, access control, data retention/deletion, and reasonable data security obligations.
  • Ability to translate privacy, data protection, information security, and internal policy requirements into testable audit controls and evaluate control design and operating effectiveness.
  • Ability to independently execute or lead moderately complex audit projects, including scoping, process walkthroughs, interviews, sample testing, evidence analysis, risk assessment, report drafting, and remediation follow‑up.
  • Strong communication, analytical, execution, and risk assessment skills, with the ability to work effectively with Legal, IT, Information Security, Data, Product, Marketing, Operations, and business stakeholders.
  • Ability to develop risk‑based, practical, and actionable control improvement recommendations and drive remediation plans and closure.

Responsibilities

  • Conduct risk-based audits of applications, data warehouses, databases, cloud platforms, business processes, and third‑party data processing activities involving personal information and sensitive data in U.S. business operations.
  • Evaluate whether IT processes, system operations, and data processing activities comply with internal data protection policies, privacy control requirements, information security controls, and applicable regulatory requirements.
  • Test the design and operating effectiveness of controls related to data minimization, notice and consent, consumer privacy rights response, access control, encryption, data masking, data retention, deletion, and destruction.
  • Lead or support U.S. data compliance audit projects covering website and app data collection, cookie and tracking technologies, third‑party data sharing, vendor data processing, cloud data protection, cross‑border data access, and access management.
  • Manage or participate in the full audit lifecycle, including audit scoping, audit planning, data processing activity mapping, risk assessment, control testing, interviews, evidence collection, sample testing, data analysis, workpaper documentation, audit report drafting, and remediation follow‑up.
  • Translate privacy, data protection, information security, and internal policy requirements into testable audit control points, audit procedures, evidence requirements, risk assessment criteria, and remediation tracking mechanisms.
  • Work with Legal, Information Security, IT, Data, Product, Marketing, Operations, and business teams to validate audit findings, assess risk levels, develop remediation plans, and track remediation to closure.
  • Support internal assessment, control testing, external advisor/audit support, and remediation tracking related to EO 14117, the DOJ Data Security Program, and other U.S. data security regulatory requirements.
  • Contribute to the continuous improvement of the company’s privacy and data security audit methodology, control testing checklists, audit workpaper templates, risk rating standards, and remediation tracking process.

Skills

IT audit
Information security audit
Privacy compliance audit
Data security
GRC
Internal controls
Risk assessment
Audit reporting
Remediation tracking
Communication

Education

Bachelor's degree or above in Information Systems, Computer Science, Information Security, Audit, Law, Compliance, Information Management, or related field

Tools

Excel
SQL
Audit tools
Python
Shell

Job description

The Company:

VeSync is a portfolio company with brands that cover different categories of health & wellness products. We wouldn’t be surprised if you have one of our Levoit air purifiers in your living room or a COSORI air fryer whipping up healthy and delicious meals for you every night.

We’re a young and energetic company, we’ve had tremendous success, and we are constantly growing our team. As we garner more industry attention - just check out our accomplishments and awards by CES Innovation, iF Design, IGA, and Red Dot - we also need driven and talented people to join our team.

That brings us to you, and what you’ll be joining. Our teams are smart and diligent and take ownership of their work – they’re confident in their work but know how to collaborate with open ears and a spirit of learning. If you’re down-to-earth, approachable, and easy to strike up a conversation with, this may be a great fit for you.

levoit.com|cosori.com|etekcity.com

The Opportunity:

The Lead IT & Privacy Auditor will focus on audit and control testing of personal information and sensitive data processing activities across the company’s business operations in Americas, with flexibility to cover Europe. This role will assess risks across the data lifecycle, including data collection, storage, transmission, use, sharing, retention, deletion, and destruction.

The role is responsible for identifying control gaps and operational risks related to privacy compliance, data security, third-party data sharing, access management, cross-border data access, and data retention/deletion practices.

This is not a Privacy Counsel, Security Architect, or enterprise Data Governance Owner role. The core responsibility is to conduct risk-based audits, evaluate control design and operating effectiveness, validate evidence, report audit findings, and drive remediation closure in partnership with Legal, IT, Information Security, Data, Product, Marketing, Operations, and business teams.

What you will do at VeSync:
  • Conduct risk-based audits of applications, data warehouses, databases, cloud platforms, business processes, and third‑party data processing activities involving personal information and sensitive data in U.S. business operations.
  • Evaluate whether IT processes, system operations, and data processing activities comply with internal data protection policies, privacy control requirements, information security controls, and applicable regulatory requirements.
  • Test the design and operating effectiveness of controls related to data minimization, notice and consent, consumer privacy rights response, access control, encryption, data masking, data retention, deletion, and destruction.
  • Lead or support U.S. data compliance audit projects covering website and app data collection, cookie and tracking technologies, third‑party data sharing, vendor data processing, cloud data protection, cross‑border data access, and access management.
  • Manage or participate in the full audit lifecycle, including audit scoping, audit planning, data processing activity mapping, risk assessment, control testing, interviews, evidence collection, sample testing, data analysis, workpaper documentation, audit report drafting, and remediation follow‑up.
  • Translate privacy, data protection, information security, and internal policy requirements into testable audit control points, audit procedures, evidence requirements, risk assessment criteria, and remediation tracking mechanisms.
  • Work with Legal, Information Security, IT, Data, Product, Marketing, Operations, and business teams to validate audit findings, assess risk levels, develop remediation plans, and track remediation to closure.
  • Support internal assessment, control testing, external advisor/audit support, and remediation tracking related to EO 14117, the DOJ Data Security Program, and other U.S. data security regulatory requirements.
  • Contribute to the continuous improvement of the company’s privacy and data security audit methodology, control testing checklists, audit workpaper templates, risk rating standards, and remediation tracking process.
What you bring to the role:
  • Bachelor’s degree or above in Information Systems, Computer Science, Information Security, Audit, Law, Compliance, Information Management, or a related field.
  • 5+ years of experience in IT audit, information security audit, privacy compliance audit, data security, GRC, internal controls, or related areas. Experience with U.S. companies, multinational companies, technology, IoT, app, DTC, e-commerce, or consumer data businesses is preferred.
  • Strong understanding of IT audit, control testing, risk assessment, audit evidence collection, workpaper documentation, audit finding development, audit reporting, and remediation tracking.
  • Working knowledge of core U.S. privacy and data protection requirements, including CCPA/CPRA, consumer privacy rights, personal information processing, third‑party data sharing, access control, data retention/deletion, and reasonable data security obligations.
  • Ability to translate privacy, data protection, information security, and internal policy requirements into testable audit controls and evaluate control design and operating effectiveness.
  • Ability to independently execute or lead moderately complex audit projects, including scoping, process walkthroughs, interviews, sample testing, evidence analysis, risk assessment, report drafting, and remediation follow‑up.
  • Strong communication, analytical, execution, and risk assessment skills, with the ability to work effectively with Legal, IT, Information Security, Data, Product, Marketing, Operations, and business stakeholders.
  • Ability to develop risk‑based, practical, and actionable control improvement recommendations and drive responsible teams toward remediation plans and closure.
Preferred:
  • Familiarity with one or more privacy, security, or audit frameworks, such as the NIST Privacy Framework, GDPR, NIST SP 800‑122, ISO 27701, ISO 27001, SOC 2, HIPAA or IAPP privacy management methodologies.
  • Understanding of FTC privacy and data security enforcement expectations, U.S. state privacy laws, EO 14117, the DOJ Data Security Program, or related requirements. Experience with related assessments, audits, vendor risk management, cross‑border data access controls, or remediation is a plus.
  • Experience auditing or supporting compliance for websites, apps, IoT, smart devices, DTC, e-commerce, ad tracking, cookie/tracking technologies, cloud platforms, third‑party data sharing, or consumer data processing activities.
  • Data analysis capability using Excel, audit tools, SQL, or other tools for sample extraction, access list analysis, log review, data flow validation, and anomaly identification. Experience with Python, Shell, or audit automation is a plus.
  • Professional certifications such as CISA, CIPP/US, CIPM, CDPSE, CIPT, CISSP, CISM, CRISC, or other privacy, IT audit, information security, or data governance certifications are preferred.
Location
  • This is an on-site, office-based role in Tustin, CA.
Salary
  • Starting at $120k
Perks and Benefits
  • 100% covered Medical/Dental/Vision for employee AND spouse + dependents!
  • 401K with 4% employer match (eligible after 90 days of employment) and immediate vesting
  • Generous Sick + Vacation policy + paid holidays
  • Life Insurance
  • Voluntary Life Insurance
  • Disability Insurance
  • Critical Illness Coverage
  • Accident Insurance
  • Healthcare FSA
  • Dependent Care FSA
  • Travel Assistance Program
  • Employee Assistance Program (EAP)
  • Fully stocked kitchen
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Analyst
Senior Information Security Analyst

Vesync • Tustin (CA)

On-site
100% covered Medical/Dental/Vision insurance
401K with 4% employer match
Generous PTO policy
+5
Information Security Analyst
Information Security Analyst

Vesync • Tustin (CA)

On-site
USD 120,000 - 144,000
Medical/Dental/Vision insurance for员工和
401K with employer match
Generous PTO
+5
Manager of Marketing Analytics
Manager of Marketing Analytics

VeSync • Tustin (CA)

On-site
USD 135,000 - 165,000
100% covered Medical/Dental/Vision ins
401K with 4% employer match
Generous PTO policy + holidays
+10
Senior Product Counsel – Health
Senior Product Counsel – Health

Vesync • Tustin (CA)

On-site
100% covered Medical/Dental/Vision insurance
401K with 4% employer match
Generous PTO policy
+3
Manager of Marketing Analytics and Ops
Manager of Marketing Analytics and Ops

Vesync Co. • Tustin (CA), Northern (KY)

On-site
USD 135,000 - 165,000
Medical/Dental/Vision insurance for员工及
401K with 4% employer match
Generous PTO and holidays
+3
Creative Services Project Manager
Creative Services Project Manager

VeSync • Tustin (CA)

On-site
USD 90,000 - 110,000
Medical coverage
Dental coverage
Vision coverage
+12
Social Media Manager Vesync Tustin, CA, US Workplace On-site 5 hours ago
Social Media Manager Vesync Tustin, CA, US Workplace On-site 5 hours ago

Content Creators • Tustin (CA), Northern (KY)

Hybrid
USD 81,000 - 99,000
100% covered Medical/Dental/Vision for
401K with 4% employer match (eligible)
Generous Sick + Vacation policy
+5
Social Media Manager
Social Media Manager

Vesync Co. • Tustin (CA)

On-site
USD 81,000 - 99,000
100% covered Medical/Dental/Vision for
401K with 4% employer match (eligible
Generous Sick + Vacation policy + paid
+10
Integrated Marketing Communications Manager (Coffee Category)
Integrated Marketing Communications Manager (Coffee Category)

Vesync Co. • Tustin (CA)

Hybrid
USD 100,000 - 130,000
Medical/Dental/Vision insurance
401K with employer match
Generous PTO
+4
Health Promotion Program Lead
Health Promotion Program Lead

Vesync Co. • Tustin (CA)

On-site
USD 122,000 - 149,000
Medical/Dental/Vision coverage
401K with match
Generous PTO
+9