Governance Risk & Compliance Manager

WHOOP

Boston (MA)

On-site

USD 140,000 - 190,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Flexible vacation
Parental leave (18 weeks)
Stock options
WHOOP membership
Medical, dental, vision
Wellness stipend
Sleep bonus $100
Office in Boston (One Kenmore Square)

Job summary

WHOOP is seeking a Manager of Governance, Risk, and Compliance to lead the day-to-day GRC program in a fast-paced, high-growth environment. You will collaborate with Legal, Security, Product, and other teams to advance compliance objectives, reduce enterprise risk, and strengthen resilience.

You will oversee governance activities, policy management, and evidence collection, while coordinating third-party risk assessments and SSDLC guardrails.

Qualifications

  • Leads the GRC program and operationalizes governance, risk, and compliance initiatives.
  • Manages third-party risk, SSDLC, and regulatory alignment across teams.
  • Drives KPI reporting, policy management, evidence collection, and audit support.

Responsibilities

  • Lead day-to-day GRC operations across governance, risk, compliance.
  • Coordinate with Legal, Security, Product and others to advance compliance objectives.
  • Oversee third-party risk lifecycle and vendor due diligence.
  • Manage workload, track requests, and ensure timely delivery with quality.
  • Develop and report operational metrics and KPIs to GRC leadership.
  • Support security incident response with compliance obligations and risk remediation.

Skills

GRC leadership
SSDLC risk assessments
Policy management
Vendor risk assessments
Audit support
KPI reporting
Cross-functional coordination
Information security
Privacy frameworks
Communication skills

Education

Bachelor's degree

Job description

  • As a Manager of Governance, Risk, and Compliance you will lead the day-to-day execution and support the ongoing operation of the GRC program in a fast-paced, high-growth environment
  • This role is responsible for hands-on execution of GRC initiatives, collaborating across Legal, Security, Product, and other teams to advance compliance objectives, reduce enterprise risk exposure, and strengthen operational resilience
  • Lead the day-to-day operations of the GRC function, ensuring timely execution of governance, risk, compliance, third-party risk, and secure development lifecycle (SSDLC) assessment activities
  • Lead enterprise risk reviews by driving GRC intake and request triage, personally overseeing complex assessments while prioritizing and delegating work across the team
  • Perform and lead the third-party risk management lifecycle by conducting and overseeing vendor risk assessments and due diligence in partnership with Legal, IT, and Security
  • Manage team workload and capacity by assigning, tracking, and escalating requests as needed to ensure consistent delivery, quality, and stakeholder satisfaction
  • Develop and report operational metrics and KPIs, providing weekly dashboards and status updates to GRC leadership
  • Contribute directly to governance activities, including policy management, control assessments, evidence collection, audit support, and continuous compliance initiatives
  • Maintain the enterprise risk register by documenting, tracking, escalating, and reporting technology, cybersecurity, privacy, and third-party risks
  • Support security incident response activities by coordinating compliance-related obligations, regulatory documentation, and risk remediation tracking
Benefits
  • Flexible Vacation: WHOOP has a flexible vacation policy that allows you to unwind, laptop-free, when you need it most.
  • Focus on Family: We offer 18 weeks paid parental leave, plus an additional 2 weeks to gradually return to work.
  • Get Invested: In addition to a competitive base salary and 401k, you’re eligible to receive stock options to share in the future of WHOOP.
  • WHOOP +1: Everyone on the team gets a complimentary WHOOP membership—plus another membership to share with a loved one.
  • Health Matters: Our competitive benefits package covers medical, dental, and vision, in addition to mental health services, life and disability insurance, and more.
  • Find Your Fit: Full-time employees get $500 a year to spend on wellness in whatever way they see fit, from fitness classes and memberships, to recovery services.
  • It Pays to Sleep: Our Sleep Performance Program incentivizes employees to get more sleep. Log an average sleep performance of 85% or higher for the month and get a $100 bonus.
  • Location, Location, Location: You can’t beat the views from the rooftop of One Kenmore Square. Feel inspired daily as you work, enjoy free snacks and coffee, and collaborate in the heart of Boston.

You are passionate about building scalable GRC programs that have a lasting impact in improving the overall security posture of an organization without slowing the speed of innovationYou have the ability to assess a risk impact in terms of business trade-offsYou are a risk focused GRC leader with ability to assess security risks and translate it into business impactStrong knowledge of SSDLC risk assessments and application security governance processesExcellent written and verbal communication skills, with the ability to communicate effectively with technical teams, business stakeholders, auditors, and executive leadershipThe successful candidate must be prepared to relocate if necessary to work out of the Boston, MA officeA minimum bachelor’s degree in any discipline. Computer science, cybersecurity, and risk or technology degrees preferredDeep knowledge of security and privacy frameworks and regulations, including ISO 27001, SOC 2, NIST CSF, HIPAA, GDPR, PCI DSS, and modern cybersecurity risk management practicesDemonstrated experience leading operational GRC programs, including intake management, workload prioritization, KPI reporting, and cross-functional coordinationExtensive hands-on experience performing third-party/vendor risk assessments, security reviews, due diligence, and risk-based decision support8+ years of experience in GRC, information security, cybersecurity; with 2+ years of experience leading or managing GRC, information security, or audit professionalsProfessional certifications such as CISSP, CRISC, CISA, ISO 27001 Lead Auditor, or HITRUST CCSFPExceptional organizational, analytical, and problem-solving skillsDemonstrated success in program and project management skills with the ability to manage multiple concurrent workstreams in a fast-paced environmentBackground in establishing SSDLC guardrails

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Governance Risk & Compliance (GRC)
Manager, Governance Risk & Compliance (GRC)

WHOOP • Boston (MA)

On-site
USD 155,000 - 195,000
GRC Risk & Compliance Manager | Equity & Impact
GRC Risk & Compliance Manager | Equity & Impact

WHOOP • Boston (MA)

On-site
USD 155,000 - 195,000
Senior Security Program Management Analyst
Senior Security Program Management Analyst

Whoop • Boston (MA)

On-site
USD 130,000 - 170,000
Director of Security Engineering & Operations
Director of Security Engineering & Operations

WHOOP • Boston (MA)

On-site
USD 230,000 - 290,000
Flexible Vacation
Parental leave 18 weeks
Stock options
+4
Security Project Manager
Security Project Manager

WHOOP • Boston (MA)

On-site
USD 130,000 - 170,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

Hybrid
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Director, Security Engineering & Operations
Director, Security Engineering & Operations

Whoop • Boston (MA)

On-site
USD 220,000 - 245,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
GRC Leader: Enterprise Risk & Compliance Ops
GRC Leader: Enterprise Risk & Compliance Ops

WHOOP • Boston (MA)

On-site
USD 140,000 - 190,000
Flexible vacation
Parental leave (18 weeks)
Stock options
+5
AI Risk & Compliance Analyst
AI Risk & Compliance Analyst

SupportFinity™ • United States

On-site
USD 85,000 - 135,000
Equity package
Competitive base salary
Benefits package