Whatnot logo

Security Engineer

Whatnot

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

Who you are

  • Curious about who thrives at Whatnot? We’ve found that low ego, a growth mindset, and leaning into action and high impact goes a long way here.
  • As our Governance, Risk, & Compliance Analyst you should have a minimum of 5+ years of relevant experience in security governance, risk, and compliance, preferably in a tech startup environment, plus:
    • A Bachelor’s degree in Computer Science, Information Security, or a related field.
    • The successful candidate will have a deep knowledge of security best practices and industry standards, such as ISO 27001, SOC2, PCI, and GDPR/CCPA.
    • Experience at a Big 4 firm or similar reputable audit firm.
    • Experience in supporting complex third party audit projects in a cloud centric environment, with a strong aptitude to understand emerging technologies to ensure regulatory and compliance requirements are met.
    • Excellent written communication skills with the ability to document, communicate, and report security assessments as well as the status of the implementation and effectiveness of cybersecurity controls with product and business leaders.
    • Experience creating and running a security risk management program that adeptly balances security risks with business priorities.

What the job involves

  • Whatnot's Security GRC team is dedicated to building trust with regulators, customers, employees, and investors by demonstrating commitment to industry standards and continuous improvement. We defend and protect our users' data and information as if it were our own. As part of the Security GRC team, you can expect to be responsible for:
    • Reviewing and implementing secure configurations across various tools like Okta, Terraform, AWS, Lumos, Cloudflare, and Github.
    • Developing security requirements for partner teams and driving progress towards the execution of those requirements.
    • Preparing for and running our external security audits.
    • Shaping the strategic direction of the Security GRC team.
    • Leading our security risk management program to prioritize security risks and ensure proper mitigations are implemented.

Benefits

  • Wellness: Health, dental, vision, and life insurance plans. We also cover some of the cost for your dependents as well.
  • Compensation: Generous compensation, including a competitive base salary and equity. Whatnot offers monthly reimbursement for internet and phone costs, along with a one-time home office set-up allowance. Whatnot offers a pension plan and matches employee contributions of up to 4% of the employee’s base salary.
  • Recharge: Whatnot gives you the freedom to take time off as you see fit. And, we take company-wide Winter and Summer breaks so we can recharge. Whatnot provides a monthly allowance for wellness expenses. We know that to take care of our customers, we have to take care of ourselves. Supplemental health and life insurance coverage comes standard at Whatnot. 16 weeks of paid parental leave, and an additional one-month gradual return-to-work period. Plus an additional childcare allowance, and a lifetime allowance for family planning, including adoption and fertility expenses. The leave allowances provided by Whatnot may be dictated/informed by your country’s legal requirements.
  • Flexibility: As a remote co-located team, we’re inspired by innovation and anchored in our values. With hubs in the US, UK, Germany, Ireland, and Poland, we’re building the future of online marketplaces – together.

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at Whatnot was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.