Governance Risk & Compliance Analyst
Whatnot
Join the Future of Commerce with Whatnot! Whatnot is the largest live shopping platform in North America and Europe to buy, sell, and discover the things you love. Whether it's trading cards, fashion, electronics, or live plants, our sellers are building real businesses across hundreds of categories. We're building live commerce at a scale that's never been done in the West, and there's no playbook to copy. The people here are shaping how an entirely new industry develops. As a remote co-located team, we're inspired by our values and anchored in hubs across the US, UK, Ireland, Poland, Germany, and Australia. We move fast, stay close to our users, and focus on the work that drives the most impact. We're one of the fastest growing marketplaces and were recently named the #1 Best Startup Employer in America by Forbes. Check out the latest Whatnot updates on our news and engineering blogs and join us as we enable anyone to turn their passion into a business and bring people together through commerce.
Role Whatnot's Security GRC team is dedicated to building trust with regulators, customers, employees, and investors by demonstrating commitment to industry standards and continuous improvement. We defend and protect our users' data and information as if it were our own. As part of the Security GRC team, you can expect to be responsible for:
You Curious about who thrives at Whatnot? We've found that low ego, a growth mindset, and leaning into action and high impact goes a long way here. As our Governance, Risk, & Compliance Analyst you should have a minimum of 8+ years of relevant experience in security governance, risk, and compliance, preferably in a tech startup environment, plus:
Role Whatnot's Security GRC team is dedicated to building trust with regulators, customers, employees, and investors by demonstrating commitment to industry standards and continuous improvement. We defend and protect our users' data and information as if it were our own. As part of the Security GRC team, you can expect to be responsible for:
- Reviewing and implementing secure configurations across various tools like Okta, Terraform, AWS, Lumos, Cloudflare, and Github.
- Developing security requirements for partner teams and driving progress towards the execution of those requirements.
- Preparing for and running our external security audits.
- Shaping the strategic direction of the Security GRC team.
You Curious about who thrives at Whatnot? We've found that low ego, a growth mindset, and leaning into action and high impact goes a long way here. As our Governance, Risk, & Compliance Analyst you should have a minimum of 8+ years of relevant experience in security governance, risk, and compliance, preferably in a tech startup environment, plus:
- A Bachelor's degree in Computer Science, Information Security, or a related field.
- The successful candidate will have a deep knowledge of security best practices and industry standards, such as ISO 27001, SOC2, PCI, and GDPR/ CCPA.
- Experience at a Big 4 firm or similar reputable audit firm.
- Experience in supporting complex third party audit projects in a cloud centric environment, with a strong aptitude to understand emerging technologies to ensure regulatory and compliance requirements are met.
- Excellent written communication skills with the ability to document, communicate, and report security assessments as well as the status of the implementation and effectiveness of cybersecurity controls with product and business leaders.
- Flexible Time off Policy and Company-wide Holidays (including a spring and winter break)
- Health Insurance options including Medical, Dental, Vision
- Work From Home Support
- Home office setup allowance
- Monthly allowance for cell phone and internet
- Care benefits
- Monthly allowance for wellness
- Annual allowance towards Childcare
- Lifetime benefit for family planning, such as adoption or fertility expenses
- Retirement; 401k offering for Traditional and Roth accounts in the US (employer match up to 4% of base salary) and Pension plans internationally
- Monthly allowance to dogfood the app
- All Whatnauts are expected to develop a deep understanding of our product. We're passionate about building the best user experience, and all employees are expected to use Whatnot as both a buyer and a seller as part of their job (our dogfooding budget makes this fun and easy!).
- Parental Leave
- 16 weeks of paid parental leave + one month gradual return to work *company leave allowances run concurrently with country leave requirements which take precedence.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Governance Risk & Compliance Analyst in San Francisco, CA vacancy
- ...Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This... ...policies, standards, and procedures. Support AI governance and responsible AI compliance initiatives. What...SuggestedContract workWork at officeRemote workVisa sponsorshipRelocation packageFlexible hours
$150k - $200k
...global economy. Join us! Overview We're hiring a GRC Senior Analyst to help build the compliance foundation powering the future of global crypto payments.... ..., and recovery runbooks. Conduct vendor and third‑party risk assessments as we expand our global network of partners....SuggestedWork at officeRemote work2 days per week$135k - $165k
...foundational to our platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Why Ivo Every civilization runs on...SuggestedContract workFlexible hours$150k - $180k
...knowledge. The Role We're looking for a GRC Analyst to join our growing Security, IT, and... ...function. You'll be the backbone of all the compliance work at the intersection of Engineering,... ...The right person translates security and risk into terms that the business and product...SuggestedFull timeImmediate startRemote workWork from homeFlexible hours$140k - $178k
...achieve their truth-finding goals. As a GRCT Analyst, you will independently drive moderately complex trust, compliance, and risk workstreams that help Everlaw scale... ...external audiences. Support internal risk and governance processes such as security impact analyses...SuggestedLocal areaFlexible hoursShift work- Perplexity is seeking a highly experienced Governance, Risk & Compliance Analyst to join our world-class team. Responsibilities You will help shape our compliance and risk management program. Implement and lead frameworks such as SOC2, ISO 27001, and HIPAA, ensuring...
$153.4k - $191.8k
...technical mistake. More often, they stem from gaps in governance, risk management, operational discipline, and... ...We are looking for an Information Security GRC Analyst to help mature Mercury’s security, risk, and compliance programs. This is not a traditional compliance...- You.com is looking for a GRC Analyst to join our Security, IT, and Privacy function in San... ...will be crucial in building and maintaining compliance programs and ensuring trust with our... ...various frameworks and conducting vendor risk assessments. The ideal candidate has 3-5...
- Early Warning is seeking a Sr. Risk Analyst to support the Enterprise Risk Management program. You... ...senior management in Product Development, Legal/Compliance, IT, and Finance. A strong background in risk, analytics, and governance is essential. You will contribute to risk...
$132.6k - $195k
...marketplace of consumers, merchants, and drivers.About the RoleThe Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security-focused Third-Party Risk Management (TPRM) Sr. Analyst. If you are comfortable and have experience working in a fast-paced...Hourly payContract workWork at officeLocal areaRemote workFlexible hours- Perplexity is seeking a Governance, Risk & Compliance Analyst to shape and run our compliance and risk management program. You will lead the implementation of frameworks, oversee data privacy regulations, and build scalable audit systems in a fast‑growing startup environment...
- SmithRx is seeking a Compliance Analyst to help implement a robust compliance program in a dynamic PBM regulatory landscape. You will remediate non-compliance and support policy and procedure adherence across the organization. You will work with the Corporate Compliance...Remote jobFull timeHome office
- Baker Tilly Public Sector Internal Audit & Risk Senior Consultant in the San Francisco region offers a dynamic, client‑facing role... ...advisory firm. You will assess risks, strengthen controls and support governance improvements for government and public sector clients. The role...Remote job
$92.82k - $109.2k
...Job Title Business Risk Professional Job Description The organization's risk... ...structure is designed to promote effective governance and risk management that is systematic,... ...projects and/or activities that ensure compliance with applicable federal, state and local...Temporary workWork experience placementWork at officeLocal areaRemote workFlexible hours3 days per week- Mercury is seeking an Information Security GRC Analyst to mature security, risk, and compliance programs and build guardrails for business continuity and... ...NIST, CIS, and ISO 27001. The role emphasizes scalable governance and practical controls to enable fast, secure...
$118.68k - $175.8k
...company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.Team:The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing...Work experience placementWork at officeLocal area- Anthropic is seeking a Senior Third Party Risk Manager to lead the top tier of vendor risk, including mission-critical compute, data center, and data-pipeline partners. You will shape risk assessments, escalation, and remediation across security, privacy, and operations...Work at officeVisa sponsorship
- Baker Tilly is seeking an IT Audit, Cybersecurity & Risk Senior Consultant with a SOC focus to join its Risk Advisory practice in a... ...environment in San Francisco. You will assess technology risks, support governance and internal controls, and help clients improve risk management...
$132k - $178k
...Enterprise Risk Analyst Denver, CO or Long Beach, CA or Washington, DC or SF Bay Area... ...closely with engineering, security, legal, compliance, and operations teams to help identify,... ..., external assessor interactions, and government partner reviews. Qualifications...Permanent employmentContract workWork at office- ...Senior Vendor Risk Analyst Financial Services - Commercial Banking Job Description Senior Vendor Risk Analyst San Francisco... ...information to identify information security weaknesses or non-compliance with industry standards Produce detailed documentation of...Remote workFlexible hours
- The Goldman Sachs Group is seeking an Associate for their Global Compliance team in San Francisco. This role involves monitoring compliance, assessing financial products for suitability, and advising on regulations. Ideal candidates will possess a Bachelor's degree and...
- ...Reflection is seeking a senior leader to design, operate, and mature enterprise risk governance across the organization. The role sits at the intersection of risk, compliance, technology, and AI safety to shape how the company understands and responds to regulatory and...
$185k - $237.5k
...Support the day-to-day management and operation of Circle’s Product Risk Management function. The goal of this function is to partner... ...reporting on risks inherent to business activities, including compliance, legal, security, finance and 3rd parties. Self-identify,...Flexible hours$75k - $110k
...Risk Management Analyst At Prologis, we don't just lead the industry—we define it with a 1.3 billion square foot portfolio and an annual throughput of approximately $3.2 trillion. We create the intelligent infrastructure that powers global commerce, seamlessly connecting...Full time$57.45k - $120.27k
...The Risk Management Analyst plays a pivotal role in identifying, assessing, monitoring, and reporting enterprise-wide risks to strengthen and... ...in internal audits, regulatory examinations, and compliance reviews as needed. Oversee second line of defense activities...Work at office- ...Risk Management Analyst Integrated Resources, Inc is a premier staffing firm recognized as one of the tri-states most well-respected professional specialty firms. IRI has built its reputation on excellent service and integrity since its inception in 1996. Our mission...
- OpenAI is seeking a Senior Operations Analyst to tackle complex safety and risk challenges and turn them into scalable, practical solutions. This senior IC role requires movement across queues, investigations, and workflow design, with leadership across product, engineering...Work at office
- ...and an FDIC-insured bank in Kansas City. Risk Team at Lead The Risk team helps Lead... ...our strategic third-party partners, risk governance across the enterprise, and engagement with... ...with Product, Program Management, Compliance, Financial Crimes, Legal, and Information...Flexible hours
- ...experience, offering remote-first roles across the U.S. We seek an Analyst I to learn consumer lending while delivering scoped analytics... ...scalable reports, and collaborate with Product, Legal, and Compliance to translate evolving regulations into data models and...Remote work
- Plaid in San Francisco seeks a Security Risk Assessor to run vendor risk assessments end-to-end—from intake and questionnaire to risk rating and tracked findings. You will vet customer and partner security postures onboarding to the platform, maintain a current risk register...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance Risk & Compliance Analyst. Be the first to apply!
Related searches
- third party risk analyst San Francisco, CA
- senior quantitative risk analyst San Francisco, CA
- risk compliance officer San Francisco, CA
- it risk analyst San Francisco, CA
- operational risk consultant San Francisco, CA
- governance risk & compliance analyst San Francisco, CA
- risk officer San Francisco, CA
- risk analyst San Francisco, CA
- operational risk specialist San Francisco, CA
- transaction risk analyst San Francisco, CA

