Security Lead Engineer

Whop

Not Interested
Bookmark
Report This Job

profile Job Location:

Brooklyn, NY - USA

profile Monthly Salary: Not Disclosed
Posted on: 18 hours ago
Vacancies: 1 Vacancy

Job Summary

About Whop

Whop is the ultimate virtual market that lets people earn money by starting shops and creating content. We deliver $2.5B per year in income to people across the globe and have more than 5M monthly users.

About the role

Whop is hiring our first dedicated security hire. You will work closely with our CTO to uplevel the teams security posture.

This role is responsible for owning all security outcomes: infrastructure compliance external programs and internal security. Youll drive execution and hold an extremely high bar for our security posture. We are looking for someone highly technical an engineer first. The ideal candidate is a backend/infra engineer who evolved into security you owned security at a startup because no one else would.

Were mid-SOC2 with a handful of vendors supporting our IT and Security. Youll inherit these relationships and make them yours and work across every internal team to drive execution. Youll work closely with the CTO head of legal chief of staff and head of ops.

This is a hands-on role. We are looking for a technical individual contributor to independently build these programs from scratch.

Scope:

  • Own SOC2 and data privacy compliance (audits GDPR CCPA)
  • Own infrastructure security (AWS Vercel Cloudflare PlanetScale - secrets access controls monitoring)
  • Own security incident response (detection triage remediation post-mortems)
  • Own external security programs (bug bounty pen tests threat monitoring)
  • Own internal security (IT vendor device security office security training)
  • First line of escalation for all security issues

What were looking for

  • Highly technical understands backend systems infra APIs how things break. Can actually fix issues not just identify them
  • Extremely organized high attention to detail
  • High agency scrappy and urgent
  • Extremely clear communicator - written and verbal
  • Paranoid in the right way - thinks like an attacker to protect us
  • Willing to push back but trusted enough that people listen
  • Highly available and responsive
  • Always learning loves to teach
  • Builds systems that make you redundant over time
  • 5 years in security has owned a program before
  • Low-ego - cares about outcomes not credit
  • Uses modern tools (AI agents) and stays current on threat landscape
  • Constantly monitors and adjusts what you ship
  • Series A/B or high-growth startup experience preferred

Your first 90 days will look like the following:

  • Within 30 days youve mapped how access data money and production systems actually work at Whop. Incident detection is materially improved through stronger logging and monitoring with clear signals for suspicious access and misuse. Youve established clean ownership and escalation for security incidents tightened obvious risk boundaries and taken ownership of all security-relevant systems and vendors without broadcasting internal gaps.

  • Within 60 days security fundamentals are standardized and enforced through engineering systems not policy alone. Identity access secrets devices production access and financial systems operate on least-privilege defaults with strong auditability and fast revocation. Guardrails are embedded into workflows so engineers and operators naturally do the safe thing. SOC 2 is in final stages as a consequence of these systems being in place and actively used.

  • Within 90 days Whops security posture is durable under real-world pressure. External security programs are live incidents are detected early and handled predictably and critical systems are resilient to abuse compromise and traffic spikes. Sensitive data is controlled and minimized by default. Employees can safely use modern tools including AI without creating hidden risk. SOC 2 is complete policies are followed in practice and security runs autonomously day-to-day with minimal CTO involvement.

Benefits Overview

Minimum cash comp of $250000K a competitive equity package

Unlimited PTO with full health vision dental coverage

Lunch & dinner paid for Monday thru Friday

3k ramp card to get you the latest Macbook Pro & tech accessories

This role is a Security Lead Engineer who will report to the CTO.


Required Experience:

IC

About WhopWhop is the ultimate virtual market that lets people earn money by starting shops and creating content. We deliver $2.5B per year in income to people across the globe and have more than 5M monthly users.About the roleWhop is hiring our first dedicated security hire. You will work closely w...
View more view more

Key Skills

  • Splunk
  • IDS
  • Network security
  • Computer Networking
  • Identity & Access Management
  • PKI
  • PCI
  • NIST Standards
  • Security System Experience
  • Information Security
  • Encryption
  • Siem

About Company

Company Logo

Whop is your home on the internet. You can discover interesting communities, meet cool people, and even start a business.

View Profile View Profile