Security GRC Engineer: Risk, Audit & Compliance

Whatnot

Seattle (WA)

On-site

USD 175,000 - 230,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health Insurance options including US
Work From Home support
Home office setup allowance
Monthly phone and internet allowance
Wellness and childcare allowances
401k with employer match up to 4%
Parental Leave
Dogfooding the app budget

Job summary

Whatnot's Security GRC team leads trust with regulators, customers, employees, and investors by implementing industry standards and continuous improvement. The role focuses on secure configurations, audit readiness, and risk prioritization across cloud-centric environments.

Ideal candidates have 5+ years in governance, risk, and compliance within tech startups. Bachelor's in CS/Info Sec and familiarity with ISO 27001, SOC2, PCI, GDPR/CCPA are required.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Deep knowledge of security best practices and industry standards (ISO 27001, SOC2, PCI, GDPR/CCPA).
  • Experience supporting third party audit projects in cloud environments.
  • Excellent written communication to document, communicate and report security assessments.

Responsibilities

  • Reviewing and implementing secure configurations across tools (Okta, Terraform, AWS, Lumos, Cloudflare, GitHub).
  • Developing security requirements for partner teams and driving execution.
  • Preparing for and running external security audits.
  • Shaping the strategic direction of the Security GRC team.
  • Leading the security risk management program to prioritize risks and mitigations.

Skills

Security governance
Risk management
Compliance
Written communication
Cloud security

Education

Bachelor's degree in CS/Info Security

Job description

Whatnot's Security GRC team leads trust with regulators, customers, employees, and investors by implementing industry standards and continuous improvement. The role focuses on secure configurations, audit readiness, and risk prioritization across cloud-centric environments.

Ideal candidates have 5+ years in governance, risk, and compliance within tech startups. Bachelor's in CS/Info Sec and familiarity with ISO 27001, SOC2, PCI, GDPR/CCPA are required.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security GRC Engineer — Lead Compliance & Risk
Security GRC Engineer — Lead Compliance & Risk

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Health Insurance options
Work From Home Support
Home office setup allowance
+3
Security GRC Engineer: Risk, Audits and Compliance
Security GRC Engineer: Risk, Audits and Compliance

Whatnot • San Francisco (CA)

On-site
USD 175,000 - 230,000
Health Insurance
Home office setup allowance
Cell phone and internet allowance
+6
Senior GRC Engineer: Cloud Security & Compliance
Senior GRC Engineer: Cloud Security & Compliance

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 240,000
Healthcare benefits
401(k) match
Career development
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
Senior GRC Manager: Risk, Compliance & Audit Lead
Senior GRC Manager: Risk, Compliance & Audit Lead

G2 • Chicago (IL)

On-site
USD 120,000 - 190,000
Security GRC Lead: Scale Compliance & Risk
Security GRC Lead: Scale Compliance & Risk

Whatnot • New York (NY)

On-site
USD 175,000 - 230,000
Health insurance options
Work from home support
Parental leave
+2
Remote GRC Engineer: Lead Compliance & Security
Remote GRC Engineer: Lead Compliance & Security

Jobgether • Illinois

Remote
USD 100,000 - 140,000
Flexible work environment
Employer contributions towards healthcare
Equity in the company
+3
GRC Analyst
GRC Analyst

Apex B2Bi Solutions • Illinois

On-site
USD 90,000 - 130,000
GRC Security compliance leader
GRC Security compliance leader

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000
GRC Specialist: Governance, Risk & Compliance
GRC Specialist: Governance, Risk & Compliance

360CyberX • United States

On-site
USD 70,000 - 90,000