About the job
About Whop
Whop is an innovative financial technology company dedicated to establishing sustainable income opportunities globally. Our vision is to develop the world’s largest online marketplace where individuals can create, connect, and transact seamlessly on a unified platform. With Whop, both individuals and businesses can accept payments, launch new ventures, and engage with a diverse network.
Currently, Whop processes over $3 billion in annual payouts across 144 countries, experiencing remarkable growth with a gross transaction volume increase of approximately 25% month-over-month.
We have successfully attracted significant investment from prestigious institutional investors, including Insight, Bain Capital Ventures, A*, and Peter Thiel, alongside a recent strategic investment from Tether, the world’s leading stablecoin issuer.
Our team consists of passionate young entrepreneurs who have a strong digital background, with over 75% having previously built businesses, including 53 former founders and 30 who have scaled their ventures beyond $1 million in revenue. Our product leadership team includes experts from renowned companies like Meta and Robinhood.
For additional information, please visit whop.com.
About the Role
Whop is on the lookout for our inaugural dedicated Security Lead Engineer. Collaborating closely with our CTO, you will enhance the security posture of our team.
This pivotal role entails taking ownership of all security outcomes, including infrastructure, compliance, external programs, and internal security measures. You will be responsible for executing security initiatives and establishing high standards for our security practices. We seek a candidate with a strong technical background, ideally someone who began their career as a backend/infrastructure engineer and transitioned into a security-focused role, taking charge of security in a startup environment.
As we are mid-way through achieving SOC2 compliance, you will inherit existing vendor relationships and ensure their effectiveness while collaborating with every internal team to drive execution. You will work closely with the CTO, the head of legal, the chief of staff, and the head of operations.
This role is hands-on, and we are looking for a technical individual contributor capable of independently building security programs from the ground up.
Responsibilities Include:
- Leading SOC2 and data privacy compliance efforts (audits, GDPR, CCPA)
- Overseeing infrastructure security (AWS, Vercel, Cloudflare, PlanetScale - managing secrets, access controls, and monitoring)
- Managing security incident response (detection, triage, remediation, and post-mortem analysis)
- Directing external security programs (bug bounties, penetration tests, and threat monitoring)
- Enhancing internal security measures (IT vendor management, device security, office security, and training)

