Security GRC Engineer: Risk, Audit & Compliance

Whatnot

Seattle (WA)

On-site

USD 175,000 - 230,000

Full time

4 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health Insurance options including US
Work From Home support
Home office setup allowance
Monthly phone and internet allowance
Wellness and childcare allowances
401k with employer match up to 4%
Parental Leave
Dogfooding the app budget

Job summary

Whatnot's Security GRC team leads trust with regulators, customers, employees, and investors by implementing industry standards and continuous improvement. The role focuses on secure configurations, audit readiness, and risk prioritization across cloud-centric environments.

Ideal candidates have 5+ years in governance, risk, and compliance within tech startups. Bachelor's in CS/Info Sec and familiarity with ISO 27001, SOC2, PCI, GDPR/CCPA are required.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Deep knowledge of security best practices and industry standards (ISO 27001, SOC2, PCI, GDPR/CCPA).
  • Experience supporting third party audit projects in cloud environments.
  • Excellent written communication to document, communicate and report security assessments.

Responsibilities

  • Reviewing and implementing secure configurations across tools (Okta, Terraform, AWS, Lumos, Cloudflare, GitHub).
  • Developing security requirements for partner teams and driving execution.
  • Preparing for and running external security audits.
  • Shaping the strategic direction of the Security GRC team.
  • Leading the security risk management program to prioritize risks and mitigations.

Skills

Security governance
Risk management
Compliance
Written communication
Cloud security

Education

Bachelor's degree in CS/Info Security

Job description

Whatnot's Security GRC team leads trust with regulators, customers, employees, and investors by implementing industry standards and continuous improvement. The role focuses on secure configurations, audit readiness, and risk prioritization across cloud-centric environments.

Ideal candidates have 5+ years in governance, risk, and compliance within tech startups. Bachelor's in CS/Info Sec and familiarity with ISO 27001, SOC2, PCI, GDPR/CCPA are required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Engineer — Compliance & Audits
Security GRC Engineer — Compliance & Audits

Whatnot • Los Angeles (CA)

On-site
USD 175,000 - 230,000
Health Insurance
Work From Home Support
Home office setup allowance
+8
Security GRC Analyst: Remote-Ready, High-Impact Compliance
Security GRC Analyst: Remote-Ready, High-Impact Compliance

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Holiday and time off
Health insurance
Work from home
+8
Security GRC Engineer: Risk, Audits and Compliance
Security GRC Engineer: Risk, Audits and Compliance

Whatnot • San Francisco (CA)

On-site
USD 175,000 - 230,000
Health Insurance
Home office setup allowance
Cell phone and internet allowance
+6
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
GRC Manager: Cybersecurity Governance & Risk Leader
GRC Manager: Cybersecurity Governance & Risk Leader

Synergy Business Consulting, Inc. • Fort Lauderdale (FL)

On-site
USD 110,000 - 160,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Senior GRC Analyst
Senior GRC Analyst

Jobtailor • New York (NY)

On-site
USD 140,000 - 190,000
Strategic GRC Lead: Risk & Compliance
Strategic GRC Lead: Risk & Compliance

Applied Intuition • Sunnyvale (CA)

On-site
USD 160,000 - 190,000
Comprehensive health, dental, and vision insurance
401k retirement benefits with employer match
Learning and wellness stipends
+1
Remote GRC Engineer: Lead Compliance & Security
Remote GRC Engineer: Lead Compliance & Security

Jobgether • Illinois

Remote
USD 100,000 - 140,000
GRC Security compliance leader
GRC Security compliance leader

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000