Governance Risk & Compliance Analyst
$175k - $230kWhatnot
Join the Future of Commerce with Whatnot!
Whatnot is the largest live shopping platform in North America and Europe to buy, sell, and discover the things you love. Whether it's trading cards, fashion, electronics, or live plants, our sellers are building real businesses across hundreds of categories. We're building live commerce at a scale that's never been done in the West, and there's no playbook to copy. The people here are shaping how an entirely new industry develops.
As a remote co-located team, we're inspired by our values and anchored in hubs across the US, UK, Ireland, Poland, Germany, and Australia. We move fast, stay close to our users, and focus on the work that drives the most impact.
We're one of the fastest growing marketplaces and were recently named the #1 Best Startup Employer in America by Forbes. Check out the latest Whatnot updates on our news and engineering blogs and join us as we enable anyone to turn their passion into a business and bring people together through commerce.
Role
Whatnot's Security GRC team is dedicated to building trust with regulators, customers, employees, and investors by demonstrating commitment to industry standards and continuous improvement. We defend and protect our users' data and information as if it were our own. As part of the Security GRC team, you can expect to be responsible for:
Reviewing and implementing secure configurations across various tools like Okta, Terraform, AWS, Lumos, Cloudflare, and Github.
Developing security requirements for partner teams and driving progress towards the execution of those requirements.
Preparing for and running our external security audits.
Shaping the strategic direction of the Security GRC team.
Team members in this role are required to be within commuting distance of our Los Angeles, CA, San Francisco, CA, Seattle, WA or New York, NY hubs.
You
Curious about who thrives at Whatnot? We’ve found that low ego, a growth mindset, and leaning into action and high impact goes a long way here.
As our Governance, Risk, & Compliance Analyst you should have a minimum of 8+ years of relevant experience in security governance, risk, and compliance, preferably in a tech startup environment, plus:
A Bachelor’s degree in Computer Science, Information Security, or a related field.
The successful candidate will have a deep knowledge of security best practices and industry standards, such as ISO 27001, SOC2, PCI, and GDPR/ CCPA.
Experience at a Big 4 firm or similar reputable audit firm.
Experience in supporting complex third party audit projects in a cloud centric environment, with a strong aptitude to understand emerging technologies to ensure regulatory and compliance requirements are met.
Excellent written communication skills with the ability to document, communicate, and report security assessments as well as the status of the implementation and effectiveness of cybersecurity controls with product and business leaders.
Benefits
Flexible Time off Policy and Company-wide Holidays (including a spring and winter break)
Health Insurance options including Medical, Dental, Vision
Work From Home Support
Home office setup allowance
Monthly allowance for cell phone and internet
Care benefits
Monthly allowance for wellness
Annual allowance towards Childcare
Lifetime benefit for family planning, such as adoption or fertility expenses
Retirement; 401k offering for Traditional and Roth accounts in the US (employer match up to 4% of base salary) and Pension plans internationally
Monthly allowance to dogfood the app
All Whatnauts are expected to develop a deep understanding of our product. We're passionate about building the best user experience, and all employees are expected to use Whatnot as both a buyer and a seller as part of their job (our dogfooding budget makes this fun and easy!).
Parental Leave
16 weeks of paid parental leave + one month gradual return to work *company leave allowances run concurrently with country leave requirements which take precedence.
EOE
Whatnot is proud to be an Equal Opportunity Employer. We value diversity, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, parental status, disability status, or any other status protected by local law. We believe that our work is better and our company culture is improved when we encourage, support, and respect the different skills and experiences represented within our workforce.
$100k - $120k
...Governance Risk & Compliance Engineer Polsinelli is hiring a Governance Risk & Compliance Engineer for any of our offices, with the option to work remotely. However, our preference is for this role to be based in Kansas City. CORE RESPONSIBILITIES Participate...SuggestedFull timeTemporary workPart timeWork experience placementRemote workFlexible hoursShift work- ...owned technology and services integrators in the defense and government services industry. We deliver tailored solutions, tested... ...contingent upon award of contract SOSi is seeking a Risk and Compliance Analyst to support mission requirements for a structured approach...SuggestedFull timeContract workFor contractorsRemote workWorldwide
- Technology Risk & Compliance Analyst (Cloud) Location: Seattle, WA. Key Responsibilities Serve as a senior contributor on client engagements... ...practices. Provide insights and recommendations to strengthen governance, controls, and risk management programs. Prepare and...SuggestedTemporary workApprenticeship
$142k - $220.5k
Job DescriptionIf you’re a compliance pro who thrives on building scalable, tech-enabled frameworks and wants... ...of AI-assisted testing and automation. Join the Governance, Risk, and Compliance (GRC) team as a Senior Analyst on the Compliance Assessment team. In this role,...SuggestedFull timeWork experience placement- Google seeks an Associate Principal Analyst for Responsible AI Governance to shape risk frameworks and governance across AI products. You will partner with engineers and product managers to ensure safe, ethical deployment of AI, aligning with company AI Principles and regulatory...Suggested
- Itlearn360 is seeking a Technology Risk & Compliance Analyst in Seattle, WA. This role involves serving as a key contributor on engagements related to IT risk management, audit, and compliance. Candidates should have extensive experience in IT Audit and Compliance, alongside...
$81k - $141.74k
...Internal Audit & Risk Senior Consultant (SOX Focus) Are you interested in joining one of the fastest growing consulting and... ...through deep industry knowledge of risk, internal control, governance, compliance, and internal audit best practices. As one of the fastest...Work experience placement- Seattle City Light is seeking an Energy Risk Governance and Integration Advisor to lead risk governance, risk-informed decision-making, and analytics across wholesale trading activities. The role combines strategic leadership with hands-on data extraction, analysis, and...
- ...to our ongoing growth and success. What We’re Looking For The Risk Advisor is responsible for new insurance account production and... ...a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors...Work at officeLocal area
$102k - $178.4k
...technology company in Seattle is seeking an experienced Scaled Abuse Specialist. The role focuses on managing projects to mitigate risks and prevent fraud across its worldwide platforms. Ideal candidates will have strong skills in data analysis, including SQL and Python...Worldwide$168.32k - $252.48k
...Risk Analyst TerraPower is a nuclear technology company based in Bellevue, Washington. At its core, the company is working to raise living... ...is controlled for export by various agencies of the U.S. Government. TerraPower must evaluate applicants who are foreign nationals...Permanent employmentTemporary workFor subcontractorLocal areaRelocation package- ...Robinhood is seeking a Crypto Risk Senior Specialist to join the risk team and help monitor, assess, and report on risk across crypto products and platforms. The role collaborates with leadership to maintain risk oversight while protecting customers as the business scales...
- ...to our ongoing growth and success. WHAT WE’RE LOOKING FOR The Risk Advisor is responsible for new insurance account production and... ...a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors...Work at officeLocal area
- ...TerraPower is seeking a Risk Analyst to join its Bellevue, WA team. The role reports to the Project Management Office under Enterprise or Project Risk Management and focuses on evaluating, managing, and mitigating risks within TerraPower's Risk Program across project...
- Seattle City Light seeks an Energy Risk Governance and Integration Advisor to lead risk governance for wholesale trading and market participation. You will identify and communicate energy, environmental, and market-structure risks arising from evolving markets, regulatory...
$185k - $237.5k
...Support the day-to-day management and operation of Circle’s Product Risk Management function. The goal of this function is to partner... ...reporting on risks inherent to business activities, including compliance, legal, security, finance and 3rd parties. Self-identify,...Flexible hours- ...Security Risk Management Role We believe that the way people interact with their finances will drastically improve in... ...York, Washington D.C., London and Amsterdam. The Security Governance, Risk, and Compliance (GRC) team is part of Plaid's security organization,...Work experience placementLocal area
$36.15 - $60.25 per hour
...Enterprise Risk Management Analyst Renton Oakesdale Ave SW - Renton, WA 98057 Overview Salary... ...assessments (strategic, operational, compliance, credit, liquidity, and reputational... ...risk reports for management and risk governance committees # Track risk issues,...Hourly payFull timeContract work$70k - $110k
...every team member has a big role to play. Come join our growing team in our brand new Seattle office! The role We’re adding a Risk Analyst to our team to help us build and scale our user-facing products. You'll work closely with product, machine learning, and...Work at office- DLA Piper is seeking a Conflicts Analyst to support risk management by analyzing and resolving conflicts in new client and matter intake, drafting waivers, and implementing information barriers. The role involves collaboration with partners and Professional Responsibility...Work at office
- Fox Rothschild LLP is seeking a Risk Mitigation Analyst to conduct public records and investigative research supporting client engagements and internal risk management. The role emphasizes accuracy, clear documentation, and collaboration with attorneys and staff. The position...
- EY in the United States is seeking a Threat & Risk Analyst to lead strategic and tactical threat intelligence efforts in partnership with Global Security and Regional Security teams, focusing on the Americas. The role collects, assesses and reports intelligence to help...
$76k - $91.75k
As a member of the Knowledge Management Department, the Risk Mitigation Analyst conducts hands‑on, detail‑oriented public records and investigative... ...lateral hires. Maintain and update the firm's trading‑compliance watch‑list database and respond to related watch‑list...Full timeWork experience placementWork at office- EY in the United States is seeking a Risk Management professional within the Independence function. You will support EY engagement... ...EY to collaborate with independence experts globally, advise on compliance, and help protect the firms reputation. This role emphasizes training...
- FiveBy Solutions, a Seattle-headquartered security consultancy with nationwide operations, is seeking an Associate Risk Intelligence Analyst who is fluent in English and Mandarin Chinese to join our team. The role focuses on sanctions research, due diligence, and intelligence...Remote job
- FiveBy Solutions is a Seattle-based security consultancy seeking a Risk Intelligence Analyst to support sanctions research and due diligence for clients. The role emphasizes curiosity, methodological rigor, and cross-functional collaboration, with a strong emphasis on remote...Remote job
- ...Center. Job Title: GRC Analyst II Location: Seattle,... ...Evaluate complex privacy risks and document recommended mitigation... ...to Nordstrom risk and compliance posture Identify opportunities... ...supplement data mapping and governance documentation Support rollout...Temporary work
$62.8k - $65k
...frequency of fraud, piracy, and other commercial risk, there has never been a better time to... ...for an Associate Risk Intelligence Analyst w advanced fluency in both English and Mandarin... ...an integral role in supporting trade compliance for our client through research and...Hourly payFull timeWork at officeLocal areaRemote work$77k - $202k
...Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate The Opportunity As a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate, you will focus on maintaining regulatory compliance and managing risks for clients...$81k - $141.74k
...focused on providing exceptional client service in the areas of risk and advisory?If yes, consider joining Baker Tilly (BT) as an... ...through deep industry knowledge of risk, internal control, governance, compliance, and internal audit best practices. As one of the fastest...Full timeWork experience placementLocal areaWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance Risk & Compliance Analyst. Be the first to apply!
- third party risk analyst Seattle, WA
- senior quantitative risk analyst Seattle, WA
- it risk analyst Seattle, WA
- operational risk consultant Seattle, WA
- risk officer Seattle, WA
- risk analyst Seattle, WA
- operational risk specialist Seattle, WA
- risk consultant Seattle, WA
- research compliance officer Seattle, WA
- privacy compliance analyst Seattle, WA


