GRC & Third-Party Risk Analyst - Vendor Compliance

Whoop

Boston (MA)

On-site

USD 70,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

WHOOP is seeking a GRC Analyst in Boston to support the Governance, Risk, and Compliance program and manage third-party vendor risk reviews within cross-functional security workflows.

You will review, prioritize, route, track, and complete vendor assessments, using intake data to improve guidance, templates, reporting, and stakeholder experience. A bachelor’s degree and 2+ years in GRC are expected; relocation to Boston may be required.

Qualifications

  • 2+ years of experience in GRC - third-party risk management experience preferred.
  • Understanding of ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS.
  • Highly organized with clear escalations and informed recommendations to management.
  • A minimum bachelor’s degree in any discipline. Computer science, cyber security and risk or technology degrees preferred.

Responsibilities

  • Support day-to-day third-party vendor risk assessments – manage and triage GRC third-party vendor assessment intakes and accurate tracking through resolution
  • Perform vendor risk reviews, reassessments, partner coordination, remediation tracking, and cross-functional follow-up with Security, Legal, Privacy, Procurement, IT, Finance, and business owners
  • Assist with third-party risk program management activities

Skills

GRC experience
Vendor risk
Cybersecurity frameworks
Team collaboration

Education

Bachelor's degree
CS/Cyber security/tech degree preferred

Job description

WHOOP is seeking a GRC Analyst in Boston to support the Governance, Risk, and Compliance program and manage third-party vendor risk reviews within cross-functional security workflows.

You will review, prioritize, route, track, and complete vendor assessments, using intake data to improve guidance, templates, reporting, and stakeholder experience. A bachelor’s degree and 2+ years in GRC are expected; relocation to Boston may be required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst - Third Party Risk
GRC Analyst - Third Party Risk

United States Digital Space LLC • Boston (MA)

On-site
USD 70,000 - 110,000
GRC Analyst - Third Party Risk
GRC Analyst - Third Party Risk

Whoop • Boston (MA)

On-site
USD 70,000 - 110,000
GRC Analyst: Third-Party Risk & Vendor Oversight
GRC Analyst: Third-Party Risk & Vendor Oversight

United States Digital Space LLC • Boston (MA)

On-site
USD 70,000 - 110,000
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)

recruit22 • Chicago (IL)

On-site
USD 65,000 - 90,000
Senior GRC Analyst: TPRM & Human Risk
Senior GRC Analyst: TPRM & Human Risk

Gilder Search Group • Phoenix (AZ)

On-site
USD 80,000 - 120,000
Comprehensive Benefits Package
Discretionary Annual Bonus
Flexible Spending Accounts
GRC Operations & Risk Analyst — Equity & Growth
GRC Operations & Risk Analyst — Equity & Growth

Whoop • Boston (MA)

On-site
USD 60,000 - 90,000
Competitive base salary
Equity package
Comprehensive benefits
Senior GRC Analyst — Third-Party & Human Risk
Senior GRC Analyst — Third-Party & Human Risk

Gilder Search Group • Atlanta (GA)

On-site
USD 90,000 - 120,000
Discretionary Annual Bonus
Comprehensive Benefits Package
401k and PTO
GRC Analyst, Operations & Risk
GRC Analyst, Operations & Risk

WHOOP • Boston (MA)

On-site
USD 60,000 - 90,000
Competitive base salary
Equity package
Comprehensive benefits
GRC Analyst: Risk & Compliance Lead (Remote)
GRC Analyst: Risk & Compliance Lead (Remote)

Remote Jobs • United States

Remote
USD 103,000 - 125,000
Flexible work hours
401K match
Parental leave
+3
Global GRC Analyst - Third-Party Risk & Compliance
Global GRC Analyst - Third-Party Risk & Compliance

091 CROWN Holdings, Inc. • Yardley (WA)

On-site
USD 110,000 - 135,000
Strong commitment to employee safety
Career development through training
Exposure to global cybersecurity and R
+1