Security GRC Engineer: Risk, Audits and Compliance

Whatnot

San Francisco (CA)

On-site

USD 175,000 - 230,000

Full time

40 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health Insurance
Home office setup allowance
Cell phone and internet allowance
Wellness stipend
Childcare allowance
Family planning allowance
401k with company match
Pension plans internationally
Parental leave (16 weeks)

Job summary

Whatnot is seeking a Governance, Risk, & Compliance Analyst to strengthen security governance, risk management, and regulatory compliance across the organization. You will help shape security controls, partner with teams, and support external audits to protect user data and trust.

As part of a remote co-located team with hubs in Los Angeles, San Francisco, Seattle, and New York, you will drive security requirements, manage third-party audits, and guide the strategic direction of the GRC

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • Deep knowledge of security best practices and industry standards such as ISO 27001, SOC2, PCI, and GDPR/ CCPA.
  • Experience at a Big 4 firm or similar reputable audit firm.
  • Experience in supporting complex third party audit projects in a cloud centric environment, with a strong aptitude to understand emerging technologies to ensure regulatory and compliance requirements are met.
  • Excellent written communication skills with the ability to document, communicate, and report security assessments as well as the status of the implementation and effectiveness of cybersecurity controls with product and business leaders.
  • Experience creating and running a security risk management program that adeptly balances security risks with business priorities.

Responsibilities

  • Reviewing and implementing secure configurations across tools like Okta, Terraform, AWS, Lumos, Cloudflare, and Github.
  • Developing security requirements for partner teams and driving progress towards the execution of those requirements.
  • Preparing for and running our external security audits.
  • Shaping the strategic direction of the Security GRC team.
  • Leading our security risk management program to prioritize security risks and ensure proper mitigations are implemented.

Skills

Security governance
Risk management
Compliance
ISO 27001
SOC 2
PCI DSS
Data privacy
Audit support
Technical writing
Cloud security

Education

Bachelor’s degree in CS/InfoSec

Job description

Whatnot is seeking a Governance, Risk, & Compliance Analyst to strengthen security governance, risk management, and regulatory compliance across the organization. You will help shape security controls, partner with teams, and support external audits to protect user data and trust.

As part of a remote co-located team with hubs in Los Angeles, San Francisco, Seattle, and New York, you will drive security requirements, manage third-party audits, and guide the strategic direction of the GRC

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Analyst: Remote-Ready, High-Impact Compliance
Security GRC Analyst: Remote-Ready, High-Impact Compliance

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Holiday and time off
Health insurance
Work from home
+8
Security GRC Engineer — Lead Compliance & Risk
Security GRC Engineer — Lead Compliance & Risk

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Health Insurance options
Work From Home Support
Home office setup allowance
+3
Security GRC Engineer: Risk, Audit & Compliance
Security GRC Engineer: Risk, Audit & Compliance

Whatnot • Seattle (WA)

On-site
USD 175,000 - 230,000
Health Insurance options including US
Work From Home support
Home office setup allowance
+5
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Remote GRC Senior Analyst: Risk & Compliance Leader
Remote GRC Senior Analyst: Risk & Compliance Leader

recruit22 • Illinois

On-site
USD 140,000 - 180,000
Bonus opportunities
Comprehensive benefits
Generous paid time off
+1
GRC Analyst - Cloud Security & Compliance
GRC Analyst - Cloud Security & Compliance

United States Digital Space LLC • United States

Remote
USD 134,000 - 202,000
Equity
Healthcare
Mentorship events
+2
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

Hybrid
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Remote GRC Analyst - Compliance, Audits & Security
Remote GRC Analyst - Compliance, Audits & Security

Mosaec • Northern (KY)

Hybrid
USD 134,000 - 202,000
Strategic GRC Analyst: Governance, Risk & Compliance
Strategic GRC Analyst: Governance, Risk & Compliance

Glocomms • Dallas (TX)

Hybrid
USD 90,000 - 150,000
Competitive base salary
Annual bonus
Comprehensive medical, dental, and eye
+2
Remote GRC Security Analyst - Risk & Compliance
Remote GRC Security Analyst - Risk & Compliance

LaunchDarkly Group • United States

Remote
USD 116,000 - 188,000
Restricted Stock Units (RSUs)
Health insurance
Dental insurance
+2