The Company:
VeSync is a portfolio company with brands that cover different categories of health & wellness products. We wouldn’t be surprised if you have one of our Levoit air purifiers in your living room or a COSORI air fryer whipping up healthy and delicious meals for you every night.
We’re a young and energetic company, we’ve had tremendous success, and we are constantly growing our team. As we garner more industry attention - just check out our accomplishments and awards by CES Innovation, iF Design, IGA, and Red Dot - we also need driven and talented people to join our team.
That brings us to you, and what you’ll be joining. Our teams are smart and diligent and take ownership of their work – they’re confident in their work but know how to collaborate with open ears and a spirit of learning. If you’re down-to-earth, approachable, and easy to strike up a conversation with, this may be a great fit for you.
Check out our brands:
The Opportunity:
The Lead IT & Privacy Auditor will focus on audit and control testing of personal information and sensitive data processing activities across the company’s business operations in Americas, with flexibility to cover Europe. This role will assess risks across the data lifecycle, including data collection, storage, transmission, use, sharing, retention, deletion, and destruction.
The role is responsible for identifying control gaps and operational risks related to privacy compliance, data security, third-party data sharing, access management, cross-border data access, and data retention/deletion practices.
This is not a Privacy Counsel, Security Architect, or enterprise Data Governance Owner role. The core responsibility is to conduct risk-based audits, evaluate control design and operating effectiveness, validate evidence, report audit findings, and drive remediation closure in partnership with Legal, IT, Information Security, Data, Product, Marketing, Operations, and business teams.
What you will do at VeSync:
Conduct risk-based audits of applications, data warehouses, databases, cloud platforms, business processes, and third-party data processing activities involving personal information and sensitive data in U.S. business operations.
Evaluate whether IT processes, system operations, and data processing activities comply with internal data protection policies, privacy control requirements, information security controls, and applicable regulatory requirements.
Test the design and operating effectiveness of controls related to data minimization, notice and consent, consumer privacy rights response, access control, encryption, data masking, data retention, deletion, and destruction.
Lead or support U.S. data compliance audit projects covering website and app data collection, cookie and tracking technologies, third-party data sharing, vendor data processing, cloud data protection, cross-border data access, and access management.
Manage or participate in the full audit lifecycle, including audit scoping, audit planning, data processing activity mapping, risk assessment, control testing, interviews, evidence collection, sample testing, data analysis, workpaper documentation, audit report drafting, and remediation follow-up.
Translate privacy, data protection, information security, and internal policy requirements into testable audit control points, audit procedures, evidence requirements, risk assessment criteria, and remediation tracking mechanisms.
Work with Legal, Information Security, IT, Data, Product, Marketing, Operations, and business teams to validate audit findings, assess risk levels, develop remediation plans, and track remediation to closure.
Support internal assessment, control testing, external advisor/audit support, and remediation tracking related to EO 14117, the DOJ Data Security Program, and other U.S. data security regulatory requirements.
Contribute to the continuous improvement of the company’s privacy and data security audit methodology, control testing checklists, audit workpaper templates, risk rating standards, and remediation tracking process.
What you bring to the role:
Bachelor’s degree or above in Information Systems, Computer Science, Information Security, Audit, Law, Compliance, Information Management, or a related field.
5+ years of experience in IT audit, information security audit, privacy compliance audit, data security, GRC, internal controls, or related areas. Experience with U.S. companies, multinational companies, technology, IoT, app, DTC, e-commerce, or consumer data businesses is preferred.
Strong understanding of IT audit, control testing, risk assessment, audit evidence collection, workpaper documentation, audit finding development, audit reporting, and remediation tracking.
Working knowledge of core U.S. privacy and data protection requirements, including CCPA/CPRA, consumer privacy rights, personal information processing, third-party data sharing, access control, data retention/deletion, and reasonable data security obligations.
Ability to translate privacy, data protection, information security, and internal policy requirements into testable audit controls and evaluate control design and operating effectiveness.
Ability to independently execute or lead moderately complex audit projects, including scoping, process walkthroughs, interviews, sample testing, evidence analysis, risk assessment, report drafting, and remediation follow-up.
Strong communication, analytical, execution, and risk assessment skills, with the ability to work effectively with Legal, IT, Information Security, Data, Product, Marketing, Operations, and business stakeholders.
Ability to develop risk-based, practical, and actionable control improvement recommendations and drive responsible teams toward remediation plans and closure.
Preferred:
Familiarity with one or more privacy, security, or audit frameworks, such as the NIST Privacy Framework, GDPR, NIST SP 800-122, ISO 27701, ISO 27001, SOC 2, HIPAA or IAPP privacy management methodologies.
Understanding of FTC privacy and data security enforcement expectations, U.S. state privacy laws, EO 14117, the DOJ Data Security Program, or related requirements. Experience with related assessments, audits, vendor risk management, cross-border data access controls, or remediation is a plus.
Experience auditing or supporting compliance for websites, apps, IoT, smart devices, DTC, e-commerce, ad tracking, cookie/tracking technologies, cloud platforms, third-party data sharing, or consumer data processing activities.
Data analysis capability using Excel, audit tools, SQL, or other tools for sample extraction, access list analysis, log review, data flow validation, and anomaly identification. Experience with Python, Shell, or audit automation is a plus.
Professional certifications such as CISA, CIPP/US, CIPM, CDPSE, CIPT, CISSP, CISM, CRISC, or other privacy, IT audit, information security, or data governance certifications are preferred.
Location:
This is an on-site, office-based role in Tustin, CA.
Salary:
Starting at $120k
Perks and Benefits:
100% covered Medical/Dental/Vision for employee AND spouse + dependents!
401K with 4% employer match (eligible after 90 days of employment) and immediate vesting
Generous Sick + Vacation policy + paid holidays
Life Insurance
Voluntary Life Insurance
Disability Insurance
Critical Illness Coverage
Accident Insurance
Healthcare FSA
Dependent Care FSA
Travel Assistance Program
Employee Assistance Program (EAP)
Fully stocked kitchen