Application Security Engineer, Whatnot

$178-235k

+ Stock options

JavaScript
Python
Elixir
Senior level
Denver
Los Angeles
New York
San Francisco Bay Area
Toronto
Whatnot

Live stream platform & marketplace for collectibles

Job no longer available

Whatnot

Live stream platform & marketplace for collectibles

501-1000 employees

B2CMarketplaceToysSocialSocial MediaConsumer Goods

Job no longer available

$178-235k

+ Stock options

JavaScript
Python
Elixir
Senior level
Denver
Los Angeles
New York
San Francisco Bay Area
Toronto

501-1000 employees

B2CMarketplaceToysSocialSocial MediaConsumer Goods

Company mission

Whatnot missions is to enable anyone to turn their passion into a business and bring people together through commerce.

Role

Who you are

  • We’ve found that low ego, a growth mindset, and leaning into action and high impact goes a long way here
  • As our next Application Security Engineer you should have a minimum 5+ years experience in application security, software engineering, or SRE at scale
  • Bachelor’s degree in Computer Science, a related field, or equivalent work experience
  • 5+ years of experience performing security-focused code reviews
  • Development experience required with one or more of the following languages: Python, Elixir, or JavaScript

What the job involves

  • Support and consult with product and development teams in the area of application security, including threat modeling and appsec reviews
  • Assist teams in reproducing, triaging, and addressing web / mobile application security vulnerabilities
  • Support the bug bounty program and the preparation of security releases
  • Assist in development of security patterns, processes and automated tooling that prevent classes of security issues

Share this job

View 53 more jobs at Whatnot

Insights

Top investors

54% employee growth in 12 months

Company

Company benefits

  • Wellness: Health, dental, vision, and life insurance plans. We also cover some of the cost for your dependents as well.
  • Compensation: Full-time Whatnauts receive equity, a WFH stipend to support your remote workspace and a monthly stipend to dogfood the app.
  • Recharge: Flexible Time Off policy, holiday week off at the end of year, and paid parental leave after 1 year with us.
  • Flexibility: Remote-first work culture. We provide a working environment where you're in charge of your time and schedule.

Funding (last 2 of 7 rounds)

Jan 2025

$265m

SERIES E

Jul 2022

$260m

SERIES D

Total funding: $749.2m

Our take

The collectible toy market is large, and Whatnot has built a unique social platform that enables sellers to use livestreams to showcase their products and reach more buyers. The company’s focus is on collectible toys, some of which are rare and can cost thousands of dollars, and has also expanded to sports cards.

The idea of Whatnot was led by buyer trends. Instagram's live feature became a popular place for selling toys and trading cards, but of course was not set up to facilitate bidding or handling payments after a sale occurs. Whatnot combines live showcasing with follow-up sale capabilities, thus serving the community in a more novel way than established collectibles market players such as eBay.

The company has grown fast. It was established in 2019 and has already expanded from its original category - Funko Pop figurines - to Pokemon cards, pins, sports cards, and many more. There is still plenty of scope for expanding into new categories, as the company aims to establish itself as the go-to for this large niche, which will be facilitated by the strong levels of funding that Whatnot has raised.

Steph headshot

Steph

Company Specialist at Welcome to the Jungle