Still hiring?
14 checksNo red flags
Browse
All Tech JobsThe whole board, newest first.Roles That Fit MeAnswer a few questions, see your matches.Early WindowFound before the big boards.Direct ApplyStraight to the manager, past the ATS.By specialty
Your materials
CV AnalyzerWhat an ATS sees, and what to fix.Tailor CVBrought in line with one posting.Cover LetterWritten from your CV and the role.You and the process
Hey, I’m Wayjo. I find roles before the big boards.
Free to browse. An account unlocks the rest.
Jobs
All Tech JobsThe whole board, newest first.Roles That Fit MeAnswer a few questions, see your matches.Early WindowFound before the big boards.Direct ApplyStraight to the manager, past the ATS.$175,000 - 230,000/ year
The whole posting in a few lines. Sign up to read it here and on every role you open.
Sign Up to ReadJoin the Future of Commerce with Whatnot!
Whatnot is the largest live shopping platform in North America and Europe to buy, sell, and discover the things you love. Whether it's trading cards, fashion, electronics, or live plants, our sellers are building real businesses across hundreds of categories. We're building live commerce at a scale that's never been done in the West, and there's no playbook to copy. The people here are shaping how an entirely new industry develops.
As a remote co-located team, we're inspired by our <u>values</u> (https://www.whatnot.com/careersprinciples) and anchored in hubs across the US, UK, Ireland, Poland, Germany, and Australia. We move fast, stay close to our users, and focus on the work that drives the most impact.
We're one of the <u>fastest growing marketplaces</u> (https://www.nytimes.com/2025/10/28/business/dealbook/whatnot-livestream-shopping-fundraise.html) and were recently named the <u>1 Best Startup Employer in America</u> (https://www.forbes.com/lists/americas-best-startup-employers/) by Forbes. Check out the latest Whatnot updates on our <u>news</u> (https://blog.teamwhatnot.com/) and <u>engineering blogs</u> (https://medium.com/whatnot-engineering) and join us as we enable anyone to turn their passion into a business and bring people together through commerce.
Role
Whatnot's Security GRC team is dedicated to building trust with regulators, customers, employees, and investors by demonstrating commitment to industry standards and continuous improvement. We defend and protect our users' data and information as if it were our own. As part of the Security GRC team, you can expect to be responsible for:
Reviewing and implementing secure configurations across various tools like Okta, Terraform, AWS, Lumos, Cloudflare, and Github.
Developing security requirements for partner teams and driving progress towards the execution of those requirements.
Preparing for and running our external security audits.
Shaping the strategic direction of the Security GRC team.
Leading our security risk management program to prioritize security risks and ensure proper mitigations are implemented.
Team members in this role are required to be within commuting distance of our Los Angeles, CA, San Francisco, CA, Seattle, WA or New York, NY hubs.
You
Curious about who thrives at Whatnot? We’ve found that low ego, a growth mindset, and leaning into action and high impact goes a long way here.
As our Governance, Risk, & Compliance Analyst you should have a minimum of 5+ years of relevant experience in security governance, risk, and compliance, preferably in a tech startup environment, plus:
A Bachelor’s degree in Computer Science, Information Security, or a related field.
The successful candidate will have a deep knowledge of security best practices and industry standards, such as ISO 27001, SOC2, PCI, and GDPR/ CCPA.
Experience at a Big 4 firm or similar reputable audit firm.
Experience in supporting complex third party audit projects in a cloud centric environment, with a strong aptitude to understand emerging technologies to ensure regulatory and compliance requirements are met.
Excellent written communication skills with the ability to document, communicate, and report security assessments as well as the status of the implementation and effectiveness of cybersecurity controls with product and business leaders.
Experience creating and running a security risk management program that adeptly balances security risks with business priorities.
Fully remote
No visa sponsorship
You must already be able to work in the United States
Whatnot
70 of their 74 open roles are remote
Worth a look before you spend an evening tailoring a CV for it.
Still hiring?
14 checksNo red flags
How crowded?
8 checks1 red flag
How well does this role fit you?
Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.
Something wrong with this vacancy?