Security GRC Analyst: Remote-Ready, High-Impact Compliance

Whatnot

Los Angeles (CA)

Hybrid

USD 120,000 - 180,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Holiday and time off
Health insurance
Work from home
Home office setup
Cell phone allowance
Internet allowance
Wellness allowance
Childcare allowance
Pension / 401k
Parental leave
Dogfood budget

Job summary

Whatnot is seeking a Governance, Risk, & Compliance Analyst to strengthen security governance, risk management, and regulatory compliance across our platforms. You will define security requirements, coordinate with partner teams, and lead audit programs to demonstrate trust with regulators and customers.

Ideal candidates bring 5+ years in security governance and a strong track record with ISO 27001, SOC 2, PCI, and GDPR/CCPA, plus cloud-centric audit experience.

Qualifications

  • Minimum 5+ years of relevant experience in security governance, risk, and compliance.
  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • Deep knowledge of security best practices and standards such as ISO 27001, SOC2, PCI, and GDPR/CCPA.
  • Experience at a Big 4 firm or similar audit firm.
  • Experience in supporting complex third party audit projects in a cloud-centric environment.
  • Excellent written communication skills to document, communicate, and report security assessments.
  • Experience creating and running a security risk management program that balances security with business priorities.

Responsibilities

  • Review secure configurations across tools like Okta, Terraform, AWS, Lumos, Cloudflare, and Github.
  • Develop security requirements for partner teams and drive execution.
  • Prepare for and run external security audits.
  • Shape the strategic direction of the Security GRC team.
  • Lead the security risk management program and ensure mitigations are implemented.

Skills

Security governance
Security risk management
ISO 27001
SOC 2
PCI DSS
GDPR/CCPA
Audit experience
Cloud security
Written communication

Education

Bachelor's degree in Computer Science, Information Security, or related field

Tools

None

Job description

Whatnot is seeking a Governance, Risk, & Compliance Analyst to strengthen security governance, risk management, and regulatory compliance across our platforms. You will define security requirements, coordinate with partner teams, and lead audit programs to demonstrate trust with regulators and customers.

Ideal candidates bring 5+ years in security governance and a strong track record with ISO 27001, SOC 2, PCI, and GDPR/CCPA, plus cloud-centric audit experience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Engineer — Lead Compliance & Risk
Security GRC Engineer — Lead Compliance & Risk

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Health Insurance options
Work From Home Support
Home office setup allowance
+3
Security GRC Engineer: Risk, Audits and Compliance
Security GRC Engineer: Risk, Audits and Compliance

Whatnot • San Francisco (CA)

On-site
USD 175,000 - 230,000
Health Insurance
Home office setup allowance
Cell phone and internet allowance
+6
Security GRC Engineer: Risk, Audit & Compliance
Security GRC Engineer: Risk, Audit & Compliance

Whatnot • Seattle (WA)

On-site
USD 175,000 - 230,000
Health Insurance options including US
Work From Home support
Home office setup allowance
+5
GRC Analyst - Cloud Security & Compliance
GRC Analyst - Cloud Security & Compliance

United States Digital Space LLC • United States

Remote
USD 134,000 - 202,000
Equity
Healthcare
Mentorship events
+2
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

Hybrid
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Senior GRC / Information Security Compliance Analyst
Senior GRC / Information Security Compliance Analyst

RecruitHook • Teaneck Township (NJ)

On-site
USD 120,000 - 160,000
GRC Analyst – SecOps
GRC Analyst – SecOps

Bright Defense, LLC. • United States

On-site
USD 70,000 - 90,000
GRC & Risk Analyst – SOC 2, ISO 27001, PCI
GRC & Risk Analyst – SOC 2, ISO 27001, PCI

CloudData • United States

On-site
USD 80,000 - 100,000
Remote GRC Senior Analyst: Risk & Compliance Leader
Remote GRC Senior Analyst: Risk & Compliance Leader

recruit22 • Illinois

On-site
USD 140,000 - 180,000
Bonus opportunities
Comprehensive benefits
Generous paid time off
+1