Available for new opportunities · Shanghai, China

Zhejia Wu — Mint

吴哲佳
Governance, Risk & Compliance (GRC) Manager

CISSP- and PMP-certified GRC leader with 7+ years managing regulatory compliance, risk assessment and security governance for multinational enterprises in China — with a track record of passing government on-site audits with zero critical findings.

Certified & recognized by Click an icon to learn more ↗
Worked with Click to learn more ↗
7+Years in GRC & security
0Critical findings in gov. audits
100+Endpoints under governance
35%MTTR reduction
About

Compliance leadership, backed by technical depth.

CISSP- and PMP-certified GRC and Security Compliance leader with 7+ years managing regulatory compliance, risk assessment and security governance for multinational enterprises in China.

Deep, hands-on expertise in MLPS 2.0 certification, Cross-Border Data Transfer compliance and China's Cybersecurity Law. I translate regulation into technical controls and bridge China IT, Legal and global security stakeholders — with a technical foundation most compliance-only professionals lack.

Regulatory Compliance

MLPS 2.0 Cross-Border Data (CBDT) Cybersecurity Law PII Governance

Risk Management

Risk Register CVSS Prioritization Contingency Planning

Audit & Certification

Gov. On-Site Audits Zero Critical Findings Audit-Readiness Docs

Governance & Policy

SOPs Remediation Playbooks Vendor Risk Review

Stakeholder Management

Legal Global Security HQ Cross-Functional IT

Technical Foundation

Nessus EDR / XDR / SIEM Python / Shell AI-Assisted Triage
Experience

Where I've led security & compliance.

Six years of progressively senior roles — from on-site operations engineer to information security manager owning end-to-end GRC programs.

Information Systems Security Manager (GRC Focus)
Dec 2022 — Present
Max Mara · Luxury Fashion

Led full-cycle MLPS 2.0 certification and end-to-end Cross-Border Data Transfer compliance; built a risk register spanning 100+ China endpoints and piloted an LLM-assisted workflow to triage CVE bulletins and regulatory alerts.

Zero critical findings in gov. audit MTTR cut by 35% Annual savings ¥500K+
Operations & Security Manager
Dec 2021 — Dec 2022
Nana Tech · China's Leading Sports Data Platform

Ran infrastructure security audits to identify and remediate control gaps, strengthened audit-readiness documentation, and led teams through structured governance and milestone tracking.

Security incidents −30% Delivery timeline −30%
Operation Project Leader
Jul 2021 — Dec 2021
Xiangtu Tech · KPMG Top 50 Automotive Tech

Directed IT strategic alignment and a compliance-safe migration following the company's acquisition, embedding security checkpoints into the CI/CD pipeline.

Manual intervention −15%
IT Operations Engineer
May 2019 — Nov 2020
Dongzhou & Jinhong Appraisal · Real Estate Consulting

Managed internal network and Linux/Windows server environments in a regulated real-estate data context; used MySQL to support data governance and analysis.

Case Studies

Key compliance project highlights.

Four programs that show how I turn regulatory requirements into audit-ready technical controls.

01 · Compliance

MLPS 2.0 National Certification

Led vulnerability scanning, security audits and remediation — passed with zero high-risk findings.

NessusMLPS 2.0
Outcome: national certification passed, zero high-risk findings.
02 · Governance

Cross-Border Data Compliance

End-to-end program under China's Cybersecurity Law, including encryption protocol design and PII data-flow mapping.

EncryptionPII Mapping
Outcome: fully compliant cross-border data flows.
03 · Audit

Xuhui Cybersecurity Audit

Prepared for and passed a government on-site audit via firewall hardening and IDS deployment.

FirewallIDS
Outcome: passed on the first attempt.
04 · Innovation

AI-Assisted Compliance Triage

Piloted an LLM workflow summarizing China-specific CVE bulletins and regulatory alerts into a daily review queue.

LLMCVE Triage
Outcome: reduced analyst workload, wider monitoring coverage.
Certifications

Eight credentials, one point of proof.

Click any card to view the original certificate. All credentials are verifiable through the issuing platform.

Education
Xianda College of Economics and Humanities, Shanghai International Studies University
B.A., Business Administration
2011 — 2015
Languages Chinese — Native · English — Professional (written & spoken)
Contact

Let's talk about your next GRC hire.

Open to GRC Manager, Security Compliance and Risk Management roles — in Shanghai or remote.

Shanghai, China Open to relocation / remote Response within 24h