Security GRC Engineer — Lead Compliance & Risk

Whatnot

Los Angeles (CA)

Hybrid

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health Insurance options
Work From Home Support
Home office setup allowance
Monthly cell phone/internet allowance
Parental leave
401k with employer match

Job summary

Whatnot is seeking an experienced Governance, Risk & Compliance Analyst to join its Security GRC team. You will focus on security governance, risk management, and regulatory compliance across cloud environments and partner ecosystems.

With 5+ years in a tech startup or similar setting, you will help establish security controls, support external audits, and drive the company toward best-practice standards such as ISO 27001, SOC2, PCI, GDPR/CCPA.

Qualifications

  • Minimum 5+ years of experience in security governance, risk, and compliance.
  • A Bachelor’s degree in Computer Science, Information Security, or a related field.
  • Deep knowledge of security best practices and standards (ISO 27001, SOC2, PCI, GDPR/CCPA).
  • Experience at a Big 4 firm or equivalent audit firm preferred.
  • Proven ability to manage complex third-party audits in cloud environments.

Responsibilities

  • Review secure configurations across tools like Okta, Terraform, AWS, Lumos, Cloudflare, and Github.
  • Develop security requirements for partner teams and drive compliance progress.
  • Prepare for and run external security audits.
  • Shape the strategic direction of the Security GRC team.
  • Lead the security risk management program balancing risk and business priorities.

Skills

Security governance
Risk management
Compliance
Security controls
Regulatory standards

Education

Bachelor's degree in Computer Science or Information Security

Tools

Okta
Terraform
AWS
Lumos
Cloudflare
Github

Job description

Whatnot is seeking an experienced Governance, Risk & Compliance Analyst to join its Security GRC team. You will focus on security governance, risk management, and regulatory compliance across cloud environments and partner ecosystems.

With 5+ years in a tech startup or similar setting, you will help establish security controls, support external audits, and drive the company toward best-practice standards such as ISO 27001, SOC2, PCI, GDPR/CCPA.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Analyst: Remote-Ready, High-Impact Compliance
Security GRC Analyst: Remote-Ready, High-Impact Compliance

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Holiday and time off
Health insurance
Work from home
+8
Security GRC Engineer: Risk, Audit & Compliance
Security GRC Engineer: Risk, Audit & Compliance

Whatnot • Seattle (WA)

On-site
USD 175,000 - 230,000
Health Insurance options including US
Work From Home support
Home office setup allowance
+5
Security GRC Engineer: Risk, Audits and Compliance
Security GRC Engineer: Risk, Audits and Compliance

Whatnot • San Francisco (CA)

On-site
USD 175,000 - 230,000
Health Insurance
Home office setup allowance
Cell phone and internet allowance
+6
Senior GRC Engineer: Cloud Security & Compliance
Senior GRC Engineer: Cloud Security & Compliance

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 240,000
Healthcare benefits
401(k) match
Career development
Senior GRC Engineer - Automate Compliance & Security
Senior GRC Engineer - Automate Compliance & Security

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 241,000
Senior GRC / Information Security Compliance Analyst
Senior GRC / Information Security Compliance Analyst

RecruitHook • Teaneck Township (NJ)

On-site
USD 120,000 - 160,000
GRC Analyst - Cloud Security & Compliance
GRC Analyst - Cloud Security & Compliance

United States Digital Space LLC • United States

Remote
USD 134,000 - 202,000
Equity
Healthcare
Mentorship events
+2
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
GRC & Risk Analyst – SOC 2, ISO 27001, PCI
GRC & Risk Analyst – SOC 2, ISO 27001, PCI

CloudData • United States

On-site
USD 80,000 - 100,000
GRC Lead, Cloud Security & Compliance
GRC Lead, Cloud Security & Compliance

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 250,000
Healthcare coverage
Vision & dental coverage
HSA & FSA
+7