Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Governance Risk & Compliance Analyst

Whatnot

Join the Future of Commerce with Whatnot!Whatnot is the largest live shopping platform in North America and Europe to buy, sell, and discover the things you love. Whether it's trading cards, fashion, electronics, or live plants, our sellers are building real businesses across hundreds of categories. We're building live commerce at a scale that's never been done in the West, and there's no playbook to copy. The people here are shaping how an entirely new industry develops.As a remote co-located team, we're inspired by our values and anchored in hubs across the US, UK, Ireland, Poland, Germany, and Australia. We move fast, stay close to our users, and focus on the work that drives the most impact.We're one of the fastest growing marketplaces and were recently named the #1 Best Startup Employer in America by Forbes. Check out the latest Whatnot updates on our news and engineering blogs and join us as we enable anyone to turn their passion into a business and bring people together through commerce.RoleWhatnot's Security GRC team is dedicated to building trust with regulators, customers, employees, and investors by demonstrating commitment to industry standards and continuous improvement. We defend and protect our users' data and information as if it were our own. As part of the Security GRC team, you can expect to be responsible for:Reviewing and implementing secure configurations across various tools like Okta, Terraform, AWS, Lumos, Cloudflare, and Github.Developing security requirements for partner teams and driving progress towards the execution of those requirements.Preparing for and running our external security audits.Shaping the strategic direction of the Security GRC team.Team members in this role are required to be within commuting distance of our Los Angeles, CA, San Francisco, CA, Seattle, WA or New York, NY hubs.YouCurious about who thrives at Whatnot? We've found that low ego, a growth mindset, and leaning into action and high impact goes a long way here.As our Governance, Risk, & Compliance Analyst you should have a minimum of 8+ years of relevant experience in security governance, risk, and compliance, preferably in a tech startup environment, plus:A Bachelor's degree in Computer Science, Information Security, or a related field.The successful candidate will have a deep knowledge of security best practices and industry standards, such as ISO 27001, SOC2, PCI, and GDPR/ CCPA.Experience at a Big 4 firm or similar reputable audit firm.Experience in supporting complex third party audit projects in a cloud centric environment, with a strong aptitude to understand emerging technologies to ensure regulatory and compliance requirements are met.Excellent written communication skills with the ability to document, communicate, and report security assessments as well as the status of the implementation and effectiveness of cybersecurity controls with product and business leaders.BenefitsFlexible Time off Policy and Company-wide Holidays (including a spring and winter break)Health Insurance options including Medical, Dental, VisionWork From Home Support Home office setup allowanceMonthly allowance for cell phone and internetCare benefits Monthly allowance for wellnessAnnual allowance towards ChildcareLifetime benefit for family planning, such as adoption or fertility expensesRetirement; 401k offering for Traditional and Roth accounts in the US (employer match up to 4% of base salary) and Pension plans internationallyMonthly allowance to dogfood the app All Whatnauts are expected to develop a deep understanding of our product. We're passionate about building the best user experience, and all employees are expected to use Whatnot as both a buyer and a seller as part of their job (our dogfooding budget makes this fun and easy!).Parental Leave 16 weeks of paid parental leave + one month gradual return to work *company leave allowances run concurrently with country leave requirements which take precedence.EOEWhatnot is proud to be an Equal Opportunity Employer. We value diversity, and we do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, parental status, disability status, or any other status protected by local law. We believe that our work is better and our company culture is improved when we encourage, support, and respect the different skills and experiences represented within our workforce.

Vacancy posted 11 hours ago
Similar jobs that could be interesting for youBased on the Governance Risk & Compliance Analyst in San Francisco, CA vacancy
  • $150k - $200k

     ...economy. Join us! Overview We're hiring a GRC Senior Analyst to help build the compliance foundation powering the future of global crypto payments....  ...recovery runbooks. Conduct vendor and third-party risk assessments as we expand our global network of partners.... 
    Suggested
    Full time
    Work at office
    Remote work
    2 days per week

    Mesh

    San Francisco, CA
    7 days ago
  • $135k - $165k

     ...foundational to our platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Role Overview Ivo is seeking a... 
    Suggested
    Contract work
    Flexible hours

    Icehouseventures

    San Francisco, CA
    4 days ago
  • Perplexity is seeking a highly experienced Governance, Risk & Compliance Analyst to join our world‑class team. You will help shape our compliance and risk management program. If you are a self‑motivated, organized professional with a passion for driving compliance and building... 
    Suggested

    B Capital

    San Francisco, CA
    4 days ago
  • $150k - $180k

     ...knowledge. The Role We're looking for a GRC Analyst to join our growing Security, IT, and...  ...function. You'll be the backbone of all the compliance work at the intersection of Engineering,...  ...The right person translates security and risk into terms that the business and product... 
    Suggested
    Full time
    Immediate start
    Remote work
    Work from home
    Flexible hours

    You.com

    San Francisco, CA
    2 days ago
  • $140k - $178k

     ...achieve their truth-finding goals. As a GRCT Analyst, you will independently drive moderately complex trust, compliance, and risk workstreams that help Everlaw scale...  ...external audiences. Support internal risk and governance processes such as security impact analyses... 
    Suggested
    Local area
    Flexible hours
    Shift work

    Everlaw

    San Francisco, CA
    2 days ago
  • $153.4k - $191.8k

     ...technical mistake. More often, they stem from gaps in governance, risk management, operational discipline, and...  ...We are looking for an Information Security GRC Analyst to help mature Mercury’s security, risk, and compliance programs. This is not a traditional compliance... 

    Embedded Shishya

    San Francisco, CA
    6 days ago
  • You.com is looking for a GRC Analyst to join our Security, IT, and Privacy function in San...  ...will be crucial in building and maintaining compliance programs and ensuring trust with our...  ...various frameworks and conducting vendor risk assessments. The ideal candidate has 3-5... 

    You.com

    San Francisco, CA
    2 days ago
  • Early Warning is seeking a Sr. Risk Analyst to support the Enterprise Risk Management program. You...  ...senior management in Product Development, Legal/Compliance, IT, and Finance. A strong background in risk, analytics, and governance is essential. You will contribute to risk... 

    Early Warning

    San Francisco, CA
    5 days ago
  • $132.6k - $195k

     ...marketplace of consumers, merchants, and drivers.About the RoleThe Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security-focused Third-Party Risk Management (TPRM) Sr. Analyst. If you are comfortable and have experience working in a fast-paced... 
    Hourly pay
    Contract work
    Work at office
    Local area
    Remote work
    Flexible hours

    Doordash

    San Francisco, CA
    3 days ago
  • Perplexity is seeking a Governance, Risk & Compliance Analyst to shape and run our compliance and risk management program. You will lead the implementation of frameworks, oversee data privacy regulations, and build scalable audit systems in a fast‑growing startup environment... 

    Apply

    San Francisco, CA
    4 days ago
  • $105k

     ...Requisition ID # 174003  Job Category: Compliance / Risk / Quality Assurance  Job Level: Individual Contributor Business Unit: Gen...  ...Location: Oakland    Department Overview The Enterprise Governance and Shared Compliance (EG&SC) group within General Counsel,... 
    Remote work
    Flexible hours

    Pacific Gas And Electric Company

    Oakland, CA
    9 days ago
  • Baker Tilly Public Sector Internal Audit & Risk Senior Consultant in the San Francisco region offers a dynamic, client‑facing role...  ...advisory firm. You will assess risks, strengthen controls and support governance improvements for government and public sector clients. The role... 
    Remote job

    Baker Tilly International

    San Francisco, CA
    3 days ago
  • Mercury is seeking an Information Security GRC Analyst to mature security, risk, and compliance programs and build guardrails for business continuity and...  ...NIST, CIS, and ISO 27001. The role emphasizes scalable governance and practical controls to enable fast, secure... 

    Embedded Shishya

    San Francisco, CA
    6 days ago
  • $118.68k - $175.8k

     ...company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.Team:The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing... 
    Work experience placement
    Work at office
    Local area

    Plaid Financial

    San Francisco, CA
    2 days ago
  • Anthropic is seeking a Senior Third Party Risk Manager to lead the top tier of vendor risk, including mission-critical compute, data center, and data-pipeline partners. You will shape risk assessments, escalation, and remediation across security, privacy, and operations... 
    Work at office
    Visa sponsorship

    Anthropic

    San Francisco, CA
    5 days ago
  • $90k - $125k

     ...Adyen is looking for a CDD Risk Analyst in San Francisco to manage Know-Your-Customer (KYC) and Customer Due Diligence (CDD) processes...  ...collecting customer information, and collaborating with teams for compliance. The base compensation is $90,000-$125,000 plus equity. #J-18... 

    Jobr

    San Francisco, CA
    4 days ago
  •  ...and an FDIC-insured bank in Kansas City. Risk Team at Lead The Risk team helps Lead...  ...our strategic third-party partners, risk governance across the enterprise, and engagement with...  ...with Product, Program Management, Compliance, Financial Crimes, Legal, and Information... 
    Flexible hours

    LEAD

    San Francisco, CA
    2 days ago
  •  ...Public Advocates Office in California seeks an analytical professional to join the team as an Analyst focusing on utility safety and risk management. You will analyze risk mitigation performance, costs, and effectiveness, and work with stakeholders to promote safe and... 
    Work at office

    ISACA

    San Francisco, CA
    2 days ago
  • The Goldman Sachs Group is seeking an Associate for their Global Compliance team in San Francisco. This role involves monitoring compliance, assessing financial products for suitability, and advising on regulations. Ideal candidates will possess a Bachelor's degree and... 

    The Goldman Sachs Group

    San Francisco, CA
    2 days ago
  • $185k - $237.5k

     ...Support the day-to-day management and operation of Circle’s Product Risk Management function. The goal of this function is to partner...  ...reporting on risks inherent to business activities, including compliance, legal, security, finance and 3rd parties. Self-identify,... 
    Flexible hours

    Circle

    San Francisco, CA
    2 days ago
  •  ...Delta Dental of California is seeking a Risk Management Analyst to identify, assess, monitor, and report enterprise risks. You will partner with internal stakeholders, apply COSO/ISO 31000 frameworks, and provide clear insights to strengthen our risk posture in a healthcare... 

    Delta Dental of California

    San Francisco, CA
    2 days ago
  • $75k - $110k

     ...Risk Management Analyst At Prologis, we don't just lead the industry—we define it with a 1.3 billion square foot portfolio and an annual throughput of approximately $3.2 trillion. We create the intelligent infrastructure that powers global commerce, seamlessly connecting... 
    Full time

    Prologis

    San Francisco, CA
    3 days ago
  • $57.45k - $120.27k

     ...The Risk Management Analyst plays a pivotal role in identifying, assessing, monitoring, and reporting enterprise-wide risks to strengthen and...  ...in internal audits, regulatory examinations, and compliance reviews as needed. Oversee second line of defense activities... 
    Work at office

    Delta Dental of California

    San Francisco, CA
    5 hours ago
  •  ...experience, offering remote-first roles across the U.S. We seek an Analyst I to learn consumer lending while delivering scoped analytics...  ...scalable reports, and collaborate with Product, Legal, and Compliance to translate evolving regulations into data models and... 
    Remote work

    Affirm

    San Francisco, CA
    3 days ago
  • $90k - $125k

     ...their ambitions faster. Adyen is looking for a hands‑on CDD Risk Analyst to join our Direct Customer Onboarding team and contribute to...  ...with a wide range of teams within Adyen, including commercial, compliance, and product, to ensure that our customers and our... 
    Full time
    Work at office
    Local area

    Adyen

    San Francisco, CA
    3 days ago
  •  ...infrastructure platform trusted by fintechs to power compliant, programmable services like payments and lending. The Risk Team partners across Product, Compliance, Legal, and Information Security to build safe, scalable risk management for fintech integrations. The team... 
    Full time

    Lead

    San Francisco, CA
    2 days ago
  •  ...identify and mitigate abuse and strategic risks to ensure a safe online ecosystem in...  ...We are looking for an AI emerging risks analyst to help us understand potential harms and...  ...provided to inquiries unrelated to job posting compliance. We are committed to providing... 

    Neura Market

    San Francisco, CA
    2 days ago
  •  ...information security weaknesses or non-compliance with industry standards. Produce detailed...  ...ensuring their understanding of associated risks and actions needed to remediate those...  ...a job alert for this search Senior Risk Analyst • San Francisco, CA, US #J-18808-Ljbffr... 
    Remote work
    Flexible hours

    Direct Staffing Inc

    San Francisco, CA
    2 days ago
  • $90k - $125k

    Adyen is seeking a hands-on CDD Risk Analyst in San Francisco, responsible for executing KYC and CDD procedures, while ensuring compliance with regulations. Ideal candidates have over 4 years of relevant experience, a strong analytical mindset, and a great sense of responsibility... 
    Work at office

    Adyen

    San Francisco, CA
    6 days ago
  •  ...mitigate abuse and strategic risks to ensure a safe online ecosystem...  ...the Role As an Agentic Risk Analyst, you will shape OpenAI’s...  ...safety, security, policy, and governance teams. You will work closely...  ...inquiries unrelated to job posting compliance. We are committed to... 
    Shift work

    Neura Market

    San Francisco, CA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Governance Risk & Compliance Analyst. Be the first to apply!