Security Lead

WhopBrooklyn, NY
19dRemote

About The Position

Whop is hiring our first dedicated security hire. You will work closely with our CTO to uplevel the team’s security posture. This role is responsible for owning all security outcomes: infrastructure, compliance, external programs, and internal security. You'll drive execution and hold an extremely high bar for our security posture. We are looking for someone highly technical – an engineer first. The ideal candidate is a backend/infra engineer who evolved into security — you owned security at a startup because no one else would. We're mid-SOC2 with a handful of vendors supporting our IT and Security. You'll inherit these relationships and make them yours, and work across every internal team to drive execution. You'll work closely with the CTO, head of legal, chief of staff, and head of ops. This is a hands-on role. We are looking for a technical individual contributor to independently build these programs from scratch.

Requirements

  • Highly technical — understands backend systems, infra, APIs, how things break. Can actually fix issues, not just identify them
  • Extremely organized, high attention to detail
  • High agency, scrappy, and urgent
  • Extremely clear communicator - written and verbal
  • Paranoid in the right way - thinks like an attacker to protect us
  • Willing to push back, but trusted enough that people listen
  • Highly available and responsive
  • Always learning, loves to teach
  • Builds systems that make you redundant over time
  • 5+ years in security, has owned a program before
  • Low-ego - cares about outcomes, not credit
  • Uses modern tools (AI agents), and stays current on threat landscape
  • Constantly monitors and adjusts what you ship
  • Series A/B or high-growth startup experience preferred

Responsibilities

  • Own SOC2 and data privacy compliance (audits, GDPR, CCPA)
  • Own infrastructure security (AWS, Vercel, Cloudflare, PlanetScale - secrets, access controls, monitoring)
  • Own security incident response (detection, triage, remediation, post-mortems)
  • Own external security programs (bug bounty, pen tests, threat monitoring)
  • Own internal security (IT vendor, device security, office security, training)
  • First line of escalation for all security issues

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Education Level

No Education Listed

Number of Employees

101-250 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service