GRC Analyst, Operations & Risk

WHOOP

Boston (MA)

On-site

USD 60,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive base salary
Equity package
Comprehensive benefits

Job summary

Whoop is searching for a GRC Analyst in Boston, MA, to enhance the Governance, Risk, and Compliance program. This role involves managing GRC intake processes, coordinating third-party risk reviews, and ensuring effective compliance operations. The ideal candidate will have 2+ years in a related role, strong operational discipline, and excellent communication skills. Salary ranges from $60,000 to $90,000, with benefits and stock options included.

Qualifications

  • 2+ years of experience in GRC, third-party risk management, or related function.
  • Strong operational discipline for managing competing requests and follow-ups.
  • Experience with security and compliance frameworks such as SOC 2, ISO 27001, etc.

Responsibilities

  • Support day-to-day GRC program operations and workflows.
  • Perform third-party risk management and vendor reviews.
  • Assist risk management activities and compliance monitoring.

Skills

GRC Management
Vendor Management
Risk Assessment
Communication Skills
Process Improvement

Education

Bachelor’s degree in Information Security, Computer Science, or related field

Tools

Jira
GRC platforms
Ticketing Systems

Job description

As a GRC Analyst, Operations & Risk, you will support the WHOOP Governance, Risk, and Compliance program by helping manage GRC intake, coordinate third-party risk activities, strengthen operational workflows, and improve visibility across risk and compliance work. This role will support vendor risk reviews, remediation follow-up, audit readiness, compliance operations, and cross-functional GRC requests in a fast-paced environment.

A key focus of this role will be helping ensure GRC work is reviewed, prioritized, routed, tracked, and completed effectively. You will use intake and ticketing data to identify workflow trends, recurring questions, handoff gaps, and opportunities to improve guidance, templates, reporting, automation, and stakeholder experience. You will also support broader GRC initiatives, including compliance calendar activities, control monitoring, process documentation, security awareness coordination, and continuous improvement across the GRC program.

RESPONSIBILITIES
  • Support day-to-day GRC program operations, including intake management, request prioritization, workflow routing, ticket tracking, escalation management, and completion follow-up
  • Perform and support third-party risk management activities, including vendor reviews, reassessments, partner coordination, remediation tracking, and cross-functional follow-up with Security, Legal, Privacy, Procurement, IT, Finance, and business owners
  • Assist with risk management activities, including risk assessments, risk documentation, mitigation tracking, risk register hygiene, owner follow-up, and treatment plan coordination
  • Support compliance monitoring and audit readiness activities, including evidence collection, preliminary reviews, control-owner coordination, remediation tracking, and compliance calendar activities
  • Analyze intake data, workflow trends, recurring stakeholder questions, and handoff gaps to identify opportunities to improve guidance, templates, reporting, automation, SOPs, and cross-functional ways of working
  • Coordinate security awareness and training activities, including completion tracking, evidence collection, employee follow-up, and support for annual or role-based training initiatives
  • Help maintain visibility into GRC workload, priorities, ownership, service levels, operational metrics, and recurring process improvement opportunities
  • Support continuous improvement across GRC tooling, intake forms, trackers, reporting, control monitoring, workflow design, and responsible automation initiatives
QUALIFICATIONS
  • 2+ years of experience in GRC, third-party risk management, security compliance, IT audit, risk management, vendor management, or a related function
  • Experience supporting third-party risk assessments, vendor security reviews, audit readiness, compliance operations, risk remediation tracking, or similar activities
  • Strong operational discipline, including the ability to manage competing requests, track open items, follow up with stakeholders, and drive work to closure
  • Strong written communication skills, with the ability to document clear status updates, risk summaries, follow-up requests, escalation notes, and process guidance
  • Ability to coordinate effectively across cross-functional stakeholders, including Security, Legal, Privacy, Procurement, Engineering, IT, Finance, and business owners
  • Familiarity with common security and compliance frameworks such as SOC 2, ISO 27001, NIST CSF, GDPR, PCI, or similar frameworks
  • Comfort working in Jira, GRC platforms, ticketing systems, spreadsheets, workflow tools, dashboards, or operational reporting systems
  • Ability to identify process gaps, navigate ambiguity, escape appropriately, and turn unclear requests into actionable next steps
  • Bachelor’s degree in Information Security, Computer Science, Business, Risk Management, or a related field, or equivalent practical experience
  • Relevant certifications such as Security+, CISA, CRISC, CISM, CISSP, ISO 27001, or GRC-related certifications are a plus, but not required
  • Strong commitment to embracing and leveraging AI tools in day-to-day tasks, ensuring AI-assisted work aligns with the same high-quality standards as personal contributions.

This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.

Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.

WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility

The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.

At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long‑term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company’s long‑term growth and success.

The U.S. base salary range for this full‑time position is $60,000 - $90,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job‑related skills, experience, performance, and relevant education or training.

In addition to the base salary, the successful candidate will also receive benefits and a generous equity package.

These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate’s specific qualifications, expertise, and alignment with the role’s requirements.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst - Third Party Risk
GRC Analyst - Third Party Risk

Whoop • Boston (MA)

On-site
USD 70,000 - 110,000
GRC Manager: Strategy, Risk & Compliance Leader
GRC Manager: Strategy, Risk & Compliance Leader

Whoop • Boston (MA)

On-site
Senior GRC Analyst
Senior GRC Analyst

Whoop • Boston (MA)

On-site
USD 130,000 - 170,000
Equity
Manager and Senior Manager: Governance, Risk, & Compliance (GRC)
Manager and Senior Manager: Governance, Risk, & Compliance (GRC)

Whoop • Boston (MA)

On-site
Senior Security Program Management Analyst
Senior Security Program Management Analyst

Whoop • Boston (MA)

On-site
USD 130,000 - 170,000
AI Risk & Compliance Analyst
AI Risk & Compliance Analyst

SupportFinity™ • United States

On-site
USD 85,000 - 135,000
Equity package
Competitive base salary
Benefits package
Security Project Manager
Security Project Manager

Whoop • Boston (MA)

On-site
USD 130,000 - 170,000
AI Risk & Compliance Analyst
AI Risk & Compliance Analyst

Whoop • Boston (MA)

On-site
USD 100,000 - 140,000
Security Analyst
Security Analyst

WHOOP • Boston (MA)

On-site
USD 70,000 - 110,000
Director, Information Security
Director, Information Security

WHOOP • Boston (MA)

On-site
USD 190,000 - 220,000
Competitive base salary
Generous equity package
Comprehensive benefits