Governance Risk & Compliance Analyst
Whatnot is the largest live shopping platform in North America and Europe to buy, sell, and discover collectibles, fashion, electronics, live plants, and more. Our sellers build real businesses across hundreds of categories. We're pioneering live commerce at an unprecedented scale, shaping an entirely new industry without a playbook. As a remote co-located team, we operate in hubs across the US, UK, Ireland, Poland, Germany, and Australia, moving fast, staying close to users, and focusing on high-impact work. We're one of the fastest-growing marketplaces and were named the #1 Best Startup Employer in America by Forbes.
About the role
The Security GRC team builds trust with regulators, customers, employees, and investors by demonstrating commitment to industry standards and continuous improvement. We defend and protect user data as if it were our own. Team members must be within commuting distance of our Los Angeles, CA; San Francisco, CA; Seattle, WA; or New York, NY hubs.
Responsibilities
- Review and implement secure configurations across tools like Okta, Terraform, AWS, Lumos, Cloudflare, and GitHub.
- Develop security requirements for partner teams and drive execution of those requirements.
- Prepare for and run external security audits.
- Shape the strategic direction of the Security GRC team.
Requirements
- Minimum of 8+ years of relevant experience in security governance, risk, and compliance, preferably in a tech startup environment.
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- Deep knowledge of security best practices and industry standards, such as ISO 27001, SOC2, PCI, GDPR, and CCPA.
- Experience at a Big 4 firm or similar reputable audit firm.
- Experience supporting complex third-party audit projects in a cloud-centric environment, with a strong aptitude for understanding emerging technologies to meet regulatory and compliance requirements.
- Excellent written communication skills to document, communicate, and report security assessments, as well as the status of cybersecurity controls to product and business leaders.
Benefits
- Flexible time-off policy and company-wide holidays (including spring and winter breaks).
- Health insurance options including medical, dental, and vision.
- Work-from-home support, including home office setup allowance.
- Monthly allowance for cell phone, internet, wellness, and dogfooding the app.
- Annual allowance for childcare and lifetime benefit for family planning (e.g., adoption or fertility expenses).
- Retirement plans: 401k (with 4% employer match) in the US; pension plans internationally.
- Parental leave: 16 weeks paid + one month gradual return (company leave runs concurrently with country requirements).
Pay
Compensation range: $175,000 – $230,000.