GRC Risk & Compliance Manager | Equity & Impact

WHOOP

Boston (MA)

On-site

USD 155,000 - 195,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

WHOOP in Boston seeks a Manager of Governance, Risk, and Compliance to lead the day-to-day GRC operations in a fast-growing environment. You will collaborate with Legal, Security, Product, and other teams to advance compliance, reduce enterprise risk, and strengthen resilience.

You will own risk assessments, third‑party due diligence, policy management, and KPI reporting, while guiding a team and ensuring SSDLC controls align with frameworks such as ISO 27001, SOC 2, NIST CSF, and HIPAA.

Qualifications

  • 8+ years of experience in GRC, information security, cybersecurity; with 2+ years of experience leading or managing GRC, information security, or audit professionals.
  • Demonstrated experience leading operational GRC programs, including intake management, workload prioritization, KPI reporting, and cross-functional coordination.
  • Extensive hands‑on experience performing third‑party/vendor risk assessments, security reviews, due diligence, and risk‑based decision support.
  • Strong knowledge of SSDLC risk assessments and application security governance processes.
  • Deep knowledge of security and privacy frameworks and regulations, including ISO 27001, SOC 2, NIST CSF, HIPAA, GDPR, PCI DSS, and modern cybersecurity risk management practices.
  • Excellent written and verbal communication skills, with the ability to communicate effectively with technical teams, business stakeholders, auditors, and executive leadership
  • A minimum bachelor’s degree in any discipline. Computer science, cybersecurity, and risk or technology degrees preferred.

Responsibilities

  • Lead the day-to-day operations of the GRC function, ensuring timely execution of governance, risk, compliance, third‑party risk, and secure development lifecycle (SSDLC) assessment activities.
  • Lead enterprise risk reviews by driving GRC intake and request triage, personally overseeing complex assessments while prioritizing and delegating work across the team.
  • Perform and lead the third‑party risk management lifecycle by conducting and overseeing vendor risk assessments and due diligence in partnership with Legal, IT, and Security.
  • Manage team workload and capacity by assigning, tracking, and escalating requests as needed to ensure consistent delivery, quality, and stakeholder satisfaction.
  • Develop and report operational metrics and KPIs, providing weekly dashboards and status updates to GRC leadership.
  • Contribute directly to governance activities, including policy management, control assessments, evidence collection, audit support, and continuous compliance initiatives.
  • Maintain the enterprise risk register by documenting, tracking, escalating, and reporting technology, cybersecurity, privacy, and third‑party risks
  • Support security incident response activities by coordinating compliance‑related obligations, regulatory documentation, and risk remediation tracking.

Skills

GRC Leadership
Risk Assessment
Regulatory Knowledge
Vendor Risk
SSDLC

Education

Bachelor's degree

Job description

WHOOP in Boston seeks a Manager of Governance, Risk, and Compliance to lead the day-to-day GRC operations in a fast-growing environment. You will collaborate with Legal, Security, Product, and other teams to advance compliance, reduce enterprise risk, and strengthen resilience.

You will own risk assessments, third‑party due diligence, policy management, and KPI reporting, while guiding a team and ensuring SSDLC controls align with frameworks such as ISO 27001, SOC 2, NIST CSF, and HIPAA.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC & Third-Party Risk Analyst - Vendor Compliance
GRC & Third-Party Risk Analyst - Vendor Compliance

Whoop • Boston (MA)

On-site
USD 70,000 - 110,000
GRC Operations & Risk Analyst — Equity & Growth
GRC Operations & Risk Analyst — Equity & Growth

Whoop • Boston (MA)

On-site
USD 60,000 - 90,000
Competitive base salary
Equity package
Comprehensive benefits
GRC & Security Compliance Lead
GRC & Security Compliance Lead

Neura Market • San Francisco (CA)

On-site
USD 140,000 - 190,000
Equity
Medical, dental, and vision coverage
Flexible PTO
+4
Senior GRC Manager — Remote, Risk & Compliance Strategy
Senior GRC Manager — Remote, Risk & Compliance Strategy

Sound Physicians • United States

On-site
USD 130,000 - 160,000
GRC Manager: Build Enterprise-Grade Security & Compliance
GRC Manager: Build Enterprise-Grade Security & Compliance

Doist • Las Vegas (NV)

On-site
USD 140,000 - 190,000
Stock Options
Medical Insurance
Dental Insurance
+7
Security GRC Engineer — Lead Compliance & Risk
Security GRC Engineer — Lead Compliance & Risk

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Health Insurance options
Work From Home Support
Home office setup allowance
+3
Senior GRC Specialist
Senior GRC Specialist

Franklin Fitch • United States

Remote
USD 100,000 - 130,000
Security GRC Engineer: Risk, Audits and Compliance
Security GRC Engineer: Risk, Audits and Compliance

Whatnot • San Francisco (CA)

On-site
USD 175,000 - 230,000
Health Insurance
Home office setup allowance
Cell phone and internet allowance
+6
Remote GRC Leader: Governance, Risk & Compliance
Remote GRC Leader: Governance, Risk & Compliance

Sound Physicians • Northern (KY)

Hybrid
USD 130,000 - 160,000
Medical, dental & vision insurance
FSA (healthcare & dependent care)
401(k) with company match
+2
GRC Manager: Strategy, Risk & Compliance Leader
GRC Manager: Strategy, Risk & Compliance Leader

Whoop • Boston (MA)

On-site