GRC Analyst - Drive Security, Compliance & Risk Strategy

Whatnot

Los Angeles (CA)

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Flexible Time off Policy
Health Insurance options
Work From Home Support
Parental Leave
401k matching
Pension plans internationally
Dogfood allowance
Care benefits
Company holidays

Job summary

Whatnot is seeking a Governance, Risk & Compliance Analyst to join our Security GRC team in monitoring and improving the security posture across regulatory and business requirements. You will define and implement controls, collaborate with product and business leaders, and prepare for external audits to maintain trust with regulators and customers.

The role emphasizes strong written communication, cloud-centric audit experience, and the ability to translate complex controls into actionable plans

Qualifications

  • 8+ years in security governance, risk and compliance in tech startups.
  • Strong knowledge of security standards (ISO 27001, SOC 2, PCI, GDPR/CCPA).
  • Experience with large audit firms (Big 4) or similar.

Responsibilities

  • Review and implement secure configurations across tools (Okta, Terraform, AWS, Lumos, Cloudflare, Github).
  • Develop security requirements for partner teams and drive implementation.
  • Prepare for and lead external security audits.
  • Shape the strategic direction of the Security GRC team.

Skills

Security governance
Risk management
Compliance
ISO 27001
SOC 2
PCI
GDPR/CCPA
Audit experience
Cloud audits
Written communication

Education

Bachelor’s degree in Computer Science or Information Security

Job description

Whatnot is seeking a Governance, Risk & Compliance Analyst to join our Security GRC team in monitoring and improving the security posture across regulatory and business requirements. You will define and implement controls, collaborate with product and business leaders, and prepare for external audits to maintain trust with regulators and customers.

The role emphasizes strong written communication, cloud-centric audit experience, and the ability to translate complex controls into actionable plans

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Engineer — Lead Compliance & Risk
Security GRC Engineer — Lead Compliance & Risk

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Health Insurance options
Work From Home Support
Home office setup allowance
+3
Security GRC Engineer: Risk, Audits and Compliance
Security GRC Engineer: Risk, Audits and Compliance

Whatnot • San Francisco (CA)

On-site
USD 175,000 - 230,000
Health Insurance
Home office setup allowance
Cell phone and internet allowance
+6
Remote GRC Analyst: Risk, Controls & Compliance
Remote GRC Analyst: Risk, Controls & Compliance

YipitData • Northern (KY)

Hybrid
USD 92,000 - 113,000
GRC Analyst: Risk, Compliance & Security Awareness
GRC Analyst: Risk, Compliance & Security Awareness

Protective • United States

Remote
USD 70,000 - 77,000
Health insurance
Dental insurance
Vision insurance
+5
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Security GRC Engineer: Risk, Audit & Compliance
Security GRC Engineer: Risk, Audit & Compliance

Whatnot • Seattle (WA)

On-site
USD 175,000 - 230,000
Health Insurance options including US
Work From Home support
Home office setup allowance
+5
GRC Security Analyst: Automate Compliance & Risk
GRC Security Analyst: Automate Compliance & Risk

Discord • San Francisco (CA)

Hybrid
USD 144,000 - 162,000
Equity
Relocation assistance
GRC Analyst: Risk, Compliance & Audit Lead
GRC Analyst: Risk, Compliance & Audit Lead

Access Data Consulting Corporation • Phoenix (AZ)

Hybrid
USD 80,000 - 100,000
GRC Analyst: Security Policy & Risk Lead
GRC Analyst: Security Policy & Risk Lead

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 80,000 - 130,000
Remote GRC Analyst: Drive Compliance & Risk
Remote GRC Analyst: Drive Compliance & Risk

YipitData (Alternative) • United States

Remote
USD 92,000 - 113,000
Flexible work hours
Flexible vacation
401K match
+5