HimalayasHimalayas logo
WhopWH

Security Lead

Whop is a leading marketplace that empowers over 1 million entrepreneurs to earn online by enabling them to buy, sell, and discover opportunities in digital communities and products.

Whop

Employee count: 11-50

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

NYC or Palo Alto preferred, open to remote (US, CA). English-first communicator required — your writing goes directly to vendors, auditors, and customers without review.

About Whop

Whop is the ultimate virtual market that lets people earn money by starting shops and creating content. We deliver $2.5B per year in income to people across the globe and have more than 5M monthly users.

About the role

Whop is hiring our first dedicated security hire. You will work closely with our CTO to uplevel the team’s security posture.

This role is responsible for owning all security outcomes: infrastructure, compliance, external programs, and internal security. You'll drive execution and hold an extremely high bar for our security posture. We are looking for someone highly technical – an engineer first. The ideal candidate is a backend/infra engineer who evolved into security — you owned security at a startup because no one else would.

We're mid-SOC2 with a handful of vendors supporting our IT and Security. You'll inherit these relationships and make them yours, and work across every internal team to drive execution. You'll work closely with the CTO, head of legal, chief of staff, and head of ops.

This is a hands-on role. We are looking for a technical individual contributor to independently build these programs from scratch.

Scope:

  • Own SOC2 and data privacy compliance (audits, GDPR, CCPA)
  • Own infrastructure security (AWS, Vercel, Cloudflare, PlanetScale - secrets, access controls, monitoring)
  • Own security incident response (detection, triage, remediation, post-mortems)
  • Own external security programs (bug bounty, pen tests, threat monitoring)
  • Own internal security (IT vendor, device security, office security, training)
  • First line of escalation for all security issues

What we’re looking for

  • Highly technical — understands backend systems, infra, APIs, how things break. Can actually fix issues, not just identify them
  • Extremely organized, high attention to detail
  • High agency, scrappy, and urgent
  • Extremely clear communicator - written and verbal
  • Paranoid in the right way - thinks like an attacker to protect us
  • Willing to push back, but trusted enough that people listen
  • Highly available and responsive
  • Always learning, loves to teach
  • Builds systems that make you redundant over time
  • 5+ years in security, has owned a program before
  • Low-ego - cares about outcomes, not credit
  • Uses modern tools (AI agents), and stays current on threat landscape
  • Constantly monitors and adjusts what you ship
  • Series A/B or high-growth startup experience preferred

Your first 90 days will look like the following:

  • Within 30 days, you’ve audited our current security posture, met all stakeholders, and fully own the SOC 2 process and IT/security vendor relationships
  • Within 60 days, you’ve taken Whop’s existing SOC 2 effort across the finish line (or are in final audit stages). Core infrastructure security is locked down, vendors are executing, and policies, runbooks, and incident response procedures are documented and in use
  • Within 90 days, our external security program is live (bug bounty, pen tests, threat monitoring). You’re running security autonomously day-to-day, with the CTO only involved in major decisions. Teams are operating against clear security standards, and you’ve partnered with IT and Ops to improve physical and workplace security across our NYC and PA offices so Whop feels like a safe place to work for employees and customers

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior
Manager

Location requirements

Hiring timezones

United States +/- 0 hours

About Whop

Learn more about Whop and their company culture.

View company profile

Whop is a marketplace that helps over 1 million entrepreneurs earn online by offering a platform to discover, buy, and sell communities, courses, and software. The company is at the forefront of enhancing the internet economy, enabling individuals to build businesses and generate income efficiently. The platform caters to a diverse range of users, including creators, digital product sellers, and course providers, facilitating seamless transactions and product delivery.

Founded in 2021 and headquartered in Brooklyn, New York, Whop provides the necessary tools for success in the digital marketplace. With a focus on empowerment, the company is dedicated to democratizing entrepreneurship and making it accessible to everyone. By providing educational resources, community support, and a user-friendly interface, Whop encourages its users to innovate and thrive in the digital age. The firm plays a pivotal role in helping users achieve their financial goals and has processed hundreds of millions in transactions, underscoring the trust and reliance the marketplace has garnered.

Claim this profileWhop logoWH

Whop

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

5 remote jobs at Whop

Explore the variety of open remote roles at Whop, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Whop

Remote companies like Whop

Find your next opportunity by exploring profiles of companies that are similar to Whop. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan