Governance Risk & Compliance Analyst

Whatnot

$110K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in security governance, risk, and compliance, ideally in a tech startup
  • Bachelor's degree in Computer Science, Information Security, or related field
  • Deep knowledge of security best practices and standards (ISO 27001, SOC2, PCI, GDPR/CCPA)
  • Experience at a Big 4 firm or similar audit firm
  • Proven ability in managing third-party audit projects in cloud environments
  • Excellent written communication skills for documenting and reporting security assessments

Responsibilities

  • Review and implement secure configurations on tools like Okta, Terraform, and AWS
  • Develop security requirements for partner teams and track execution progress
  • Prepare for and conduct external security audits
  • Shape the strategic direction of the Security GRC team
  • Build trust with regulators and stakeholders through commitment to industry standards

Benefits

  • Flexible time off policy and company-wide holidays including dedicated spring and winter breaks
  • Comprehensive health insurance options (medical, dental, vision)
  • Support for work from home with setup allowance and monthly stipends
  • Care benefits including wellness and childcare allowances
  • 401k retirement plan with employer match and global pension plans
  • Monthly allowance for using Whatnot's app as part of employee engagement
  • Generous parental leave policy with paid time off and gradual return to work support
Full Job Description
Role

Whatnot's Security GRC team is dedicated to building trust with regulators, customers, employees, and investors by demonstrating commitment to industry standards and continuous improvement. We defend and protect our users' data and information as if it were our own. As part of the Security GRC team, you can expect to be responsible for:
  • Reviewing and implementing secure configurations across various tools like Okta, Terraform, AWS, Lumos, Cloudflare, and Github.
  • Developing security requirements for partner teams and driving progress towards the execution of those requirements.
  • Preparing for and running our external security audits.
  • Shaping the strategic direction of the Security GRC team.

Team members in this role are required to be within commuting distance of our Los Angeles, CA, San Francisco, CA, Seattle, WA or New York, NY hubs.
You

Curious about who thrives at Whatnot? We've found that low ego, a growth mindset, and leaning into action and high impact goes a long way here.

As our Governance, Risk, & Compliance Analyst you should have a minimum of 8+ years of relevant experience in security governance, risk, and compliance, preferably in a tech startup environment, plus:
  • A Bachelor's degree in Computer Science, Information Security, or a related field.
  • The successful candidate will have a deep knowledge of security best practices and industry standards, such as ISO 27001, SOC2, PCI, and GDPR/ CCPA.
  • Experience at a Big 4 firm or similar reputable audit firm.
  • Experience in supporting complex third party audit projects in a cloud centric environment, with a strong aptitude to understand emerging technologies to ensure regulatory and compliance requirements are met.
  • Excellent written communication skills with the ability to document, communicate, and report security assessments as well as the status of the implementation and effectiveness of cybersecurity controls with product and business leaders.
Benefits
  • Flexible Time off Policy and Company-wide Holidays (including a spring and winter break)
  • Health Insurance options including Medical, Dental, Vision
  • Work From Home Support
    • Home office setup allowance
    • Monthly allowance for cell phone and internet
  • Care benefits
    • Monthly allowance for wellness
    • Annual allowance towards Childcare
    • Lifetime benefit for family planning, such as adoption or fertility expenses
  • Retirement; 401k offering for Traditional and Roth accounts in the US (employer match up to 4% of base salary) and Pension plans internationally
  • Monthly allowance to dogfood the app
    • All Whatnauts are expected to develop a deep understanding of our product. We're passionate about building the best user experience, and all employees are expected to use Whatnot as both a buyer and a seller as part of their job (our dogfooding budget makes this fun and easy!).
  • Parental Leave
    • 16 weeks of paid parental leave + one month gradual return to work *company leave allowances run concurrently with country leave requirements which take precedence.

Similar Jobs

More Jobs at Whatnot

More Information Technology Jobs

Find similar Governance Risk & Compliance Analyst jobs: