Governance Risk & Compliance Analyst

Whatnot
San Francisco, New York, Los Angeles, Seattle
Workplace: HybridFull timeUSD 175,000 - 230,000 annuallyFunction: Legal, Risk & ComplianceExperience: 8+ yearsEducation: bachelorsSkills: ["Written communication","Documentation","Reporting","Cross-functional communication"]

Own governance, risk, and compliance work for Whatnot’s Security GRC team. Review and implement secure configurations across tools such as Okta, Terraform, AWS, Lumos, Cloudflare, and GitHub, define security requirements for partner teams, and prepare for external security audits. Help shape the team’s strategic direction while documenting and reporting security control effectiveness to product and business leaders.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Whatnot
Whatnot
2 days ago

Governance Risk & Compliance Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Own governance, risk, and compliance work for Whatnot’s Security GRC team. Review and implement secure configurations across tools such as Okta, Terraform, AWS, Lumos, Cloudflare, and GitHub, define security requirements for partner teams, and prepare for external security audits. Help shape the team’s strategic direction while documenting and reporting security control effectiveness to product and business leaders.
Location: San Francisco, New York, Los Angeles, Seattle
Workplace: Hybrid
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Review and implement secure configurations across tools including Okta, Terraform, AWS, Lumos, Cloudflare, and GitHub.
  • •Develop security requirements for partner teams and drive progress toward execution.
  • •Prepare for and run external security audits.
  • •Shape the strategic direction of the Security GRC team.
  • •Document, communicate, and report security assessment status and the effectiveness of cybersecurity controls.

Pay and Benefits

Salary: USD 175,000 - 230,000 annually
Perks:Health InsuranceDentalVisionRemote WorkHome OfficePaid LeaveParental Leave401kPensionChildcareWellness Stipend

Key Requirements

  • •Minimum 8+ years of relevant experience in security governance, risk, and compliance, preferably in a tech startup environment.
  • •Bachelor’s degree in Computer Science, Information Security, or a related field.
  • •Deep knowledge of security best practices and standards including ISO 27001, SOC2, PCI, and GDPR/CCPA.
  • •Experience at a Big 4 firm or similar reputable audit firm.
  • •Experience supporting complex third-party audit projects in a cloud-centric environment and communicating findings to technical and business leaders.
Experience:8+ yearsSecurity governanceRisk & complianceCloud centricAudit
Education:Bachelor's in Computer Science, Information Security, or a related field
Skills:Written communicationDocumentationReportingCross-functional communication
Certifications:ISO 27001SOC2PCIGDPRCCPA
Tech Stack:OktaTerraformAWSLumosCloudflareGitHub

Company Brief

Whatnot
Whatnot is a live-stream shopping marketplace connecting sellers and collectors for trading cards, toys, and collectibles. The platform hosts live auctions and interactive streams, enabling creators and small businesses to sell directly to engaged communities.
Industry: Online Marketplaces
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series D
Headquarters: United States
Founded: 2019
WebsiteLinkedIn