Zhejia Wu — Mint
CISSP- and PMP-certified GRC leader with 7+ years managing regulatory compliance, risk assessment and security governance for multinational enterprises in China — with a track record of passing government on-site audits with zero critical findings.
Compliance leadership, backed by technical depth.
CISSP- and PMP-certified GRC and Security Compliance leader with 7+ years managing regulatory compliance, risk assessment and security governance for multinational enterprises in China.
Deep, hands-on expertise in MLPS 2.0 certification, Cross-Border Data Transfer compliance and China's Cybersecurity Law. I translate regulation into technical controls and bridge China IT, Legal and global security stakeholders — with a technical foundation most compliance-only professionals lack.
Regulatory Compliance
Risk Management
Audit & Certification
Governance & Policy
Stakeholder Management
Technical Foundation
Where I've led security & compliance.
Six years of progressively senior roles — from on-site operations engineer to information security manager owning end-to-end GRC programs.
Led full-cycle MLPS 2.0 certification and end-to-end Cross-Border Data Transfer compliance; built a risk register spanning 100+ China endpoints and piloted an LLM-assisted workflow to triage CVE bulletins and regulatory alerts.
Ran infrastructure security audits to identify and remediate control gaps, strengthened audit-readiness documentation, and led teams through structured governance and milestone tracking.
Directed IT strategic alignment and a compliance-safe migration following the company's acquisition, embedding security checkpoints into the CI/CD pipeline.
Managed internal network and Linux/Windows server environments in a regulated real-estate data context; used MySQL to support data governance and analysis.
Key compliance project highlights.
Four programs that show how I turn regulatory requirements into audit-ready technical controls.
MLPS 2.0 National Certification
Led vulnerability scanning, security audits and remediation — passed with zero high-risk findings.
Cross-Border Data Compliance
End-to-end program under China's Cybersecurity Law, including encryption protocol design and PII data-flow mapping.
Xuhui Cybersecurity Audit
Prepared for and passed a government on-site audit via firewall hardening and IDS deployment.
AI-Assisted Compliance Triage
Piloted an LLM workflow summarizing China-specific CVE bulletins and regulatory alerts into a daily review queue.
Eight credentials, one point of proof.
Click any card to view the original certificate. All credentials are verifiable through the issuing platform.
Let's talk about your next GRC hire.
Open to GRC Manager, Security Compliance and Risk Management roles — in Shanghai or remote.