Security GRC Engineer: Risk, Audits and Compliance

Whatnot

San Francisco (CA)

On-site

USD 175,000 - 230,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health Insurance
Home office setup allowance
Cell phone and internet allowance
Wellness stipend
Childcare allowance
Family planning allowance
401k with company match
Pension plans internationally
Parental leave (16 weeks)

Job summary

Whatnot is seeking a Governance, Risk, & Compliance Analyst to strengthen security governance, risk management, and regulatory compliance across the organization. You will help shape security controls, partner with teams, and support external audits to protect user data and trust.

As part of a remote co-located team with hubs in Los Angeles, San Francisco, Seattle, and New York, you will drive security requirements, manage third-party audits, and guide the strategic direction of the GRC

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • Deep knowledge of security best practices and industry standards such as ISO 27001, SOC2, PCI, and GDPR/ CCPA.
  • Experience at a Big 4 firm or similar reputable audit firm.
  • Experience in supporting complex third party audit projects in a cloud centric environment, with a strong aptitude to understand emerging technologies to ensure regulatory and compliance requirements are met.
  • Excellent written communication skills with the ability to document, communicate, and report security assessments as well as the status of the implementation and effectiveness of cybersecurity controls with product and business leaders.
  • Experience creating and running a security risk management program that adeptly balances security risks with business priorities.

Responsibilities

  • Reviewing and implementing secure configurations across tools like Okta, Terraform, AWS, Lumos, Cloudflare, and Github.
  • Developing security requirements for partner teams and driving progress towards the execution of those requirements.
  • Preparing for and running our external security audits.
  • Shaping the strategic direction of the Security GRC team.
  • Leading our security risk management program to prioritize security risks and ensure proper mitigations are implemented.

Skills

Security governance
Risk management
Compliance
ISO 27001
SOC 2
PCI DSS
Data privacy
Audit support
Technical writing
Cloud security

Education

Bachelor’s degree in CS/InfoSec

Job description

Whatnot is seeking a Governance, Risk, & Compliance Analyst to strengthen security governance, risk management, and regulatory compliance across the organization. You will help shape security controls, partner with teams, and support external audits to protect user data and trust.

As part of a remote co-located team with hubs in Los Angeles, San Francisco, Seattle, and New York, you will drive security requirements, manage third-party audits, and guide the strategic direction of the GRC

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security GRC Engineer — Lead Compliance & Risk
Security GRC Engineer — Lead Compliance & Risk

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Health Insurance options
Work From Home Support
Home office setup allowance
+3
Security GRC Engineer: Risk, Audit & Compliance
Security GRC Engineer: Risk, Audit & Compliance

Whatnot • Seattle (WA)

On-site
USD 175,000 - 230,000
Health Insurance options including US
Work From Home support
Home office setup allowance
+5
Senior GRC & Security Compliance Lead (Remote)
Senior GRC & Security Compliance Lead (Remote)

Shift Technology • Boston (MA)

Hybrid
USD 120,000 - 150,000
Flexible remote and hybrid options
Generous PTO and paid holidays
Mental health benefits
+2
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

On-site
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Senior GRC & InfoSec Risk Analyst (Remote)
Senior GRC & InfoSec Risk Analyst (Remote)

Golden Technology • North Carolina

Hybrid
USD 120,000 - 160,000
Remote GRC Analyst — Security & Compliance
Remote GRC Analyst — Security & Compliance

Webhosting • San Francisco (CA), New York (NY)

Hybrid
USD 134,000 - 202,000
GRC Analyst: Cyber Risk, Compliance & Reporting
GRC Analyst: Cyber Risk, Compliance & Reporting

Insight Global • Carol Stream (IL)

On-site
USD 95,000 - 135,000
Remote GRC Analyst: Build Practical Compliance Programs
Remote GRC Analyst: Build Practical Compliance Programs

Insight Security • Northern (KY)

Hybrid
USD 68,000 - 95,000
Health, dental, and vision insurance
Fully remote work
Unlimited PTO
+2
Remote IT Risk & Compliance Analyst: Shape the GRC Program
Remote IT Risk & Compliance Analyst: Shape the GRC Program

Not Specified • United States

Remote
USD 60,000 - 90,000
Hybrid GRC Analyst I: Risk, Audit & Compliance
Hybrid GRC Analyst I: Risk, Audit & Compliance

Geographic Solutions, Inc. • Palm Harbor (FL)

Hybrid
USD 65,000 - 85,000