Turn this role into an interview — a resume and cover letter built around what this employer wants.
WHOOP is seeking a Manager of Governance, Risk, and Compliance to lead the day-to-day GRC program in a fast-paced, high-growth environment. You will collaborate with Legal, Security, Product, and other teams to advance compliance objectives, reduce enterprise risk, and strengthen resilience.
You will oversee governance activities, policy management, and evidence collection, while coordinating third-party risk assessments and SSDLC guardrails.
You are passionate about building scalable GRC programs that have a lasting impact in improving the overall security posture of an organization without slowing the speed of innovationYou have the ability to assess a risk impact in terms of business trade-offsYou are a risk focused GRC leader with ability to assess security risks and translate it into business impactStrong knowledge of SSDLC risk assessments and application security governance processesExcellent written and verbal communication skills, with the ability to communicate effectively with technical teams, business stakeholders, auditors, and executive leadershipThe successful candidate must be prepared to relocate if necessary to work out of the Boston, MA officeA minimum bachelor’s degree in any discipline. Computer science, cybersecurity, and risk or technology degrees preferredDeep knowledge of security and privacy frameworks and regulations, including ISO 27001, SOC 2, NIST CSF, HIPAA, GDPR, PCI DSS, and modern cybersecurity risk management practicesDemonstrated experience leading operational GRC programs, including intake management, workload prioritization, KPI reporting, and cross-functional coordinationExtensive hands-on experience performing third-party/vendor risk assessments, security reviews, due diligence, and risk-based decision support8+ years of experience in GRC, information security, cybersecurity; with 2+ years of experience leading or managing GRC, information security, or audit professionalsProfessional certifications such as CISSP, CRISC, CISA, ISO 27001 Lead Auditor, or HITRUST CCSFPExceptional organizational, analytical, and problem-solving skillsDemonstrated success in program and project management skills with the ability to manage multiple concurrent workstreams in a fast-paced environmentBackground in establishing SSDLC guardrails