- As Senior Manager, GRC you will play a critical role in shaping, driving, and leading our GRC team towards supporting ongoing operation and enhancement of the overall information security governance program, assessing the risk landscape in a fast-paced, high-growth environment
- This role will strategically craft the roadmap in collaboration with stakeholders across the business and fulfil growing security needs assessing risk landscape across WHOOP
- In addition to core GRC responsibilities, you will partner closely with functions across Product, Engineering, Data Analytics, and Legal to meaningfully move the security posture of the company. We are seeking a leader and strategic partner with prior experience driving GRC programs for technology teams
- Lead the development, implementation, and continuous evolution of the GRC
- Program, driving both strategy and hands‑on execution
- Lead the development, implementation, and ongoing management of scalable
- Security control frameworks, policies, standards, and security awareness
- Programs, contributing directly while guiding the team’s work to strengthen
- Organizational compliance
- Support incident response activities and translated into actionable improvements
- Across the risk and compliance program
- Actively manage the enterprise risk register, driving risk prioritization, and
- Delivering executive‑level reporting
- Manage, mentor, and develop GRC analysts while balancing hands‑on execution
- With effective delegation and team enablement as the program scales
- Evaluate, implement, and continuously improve GRC program, tools, processes,
- And metrics
Benefits
- Flexible Vacation: WHOOP has a flexible vacation policy that allows you to unwind, laptop‑free, when you need it most.
- Focus on Family: We offer 18 weeks paid parental leave, plus an additional 2 weeks to gradually return to work.
- Get Invested: In addition to a competitive base salary and 401k, you’re eligible to receive stock options to share in the future of WHOOP.
- WHOOP +1: Everyone on the team gets a complimentary WHOOP membership—plus another membership to share with a loved one.
- Health Matters: Our competitive benefits package covers medical, dental, and vision, in addition to mental health services, life and disability insurance, and more.
- Find Your Fit: Full‑time employees get $500 a year to spend on wellness in whatever way they see fit, from fitness classes and memberships, to recovery services.
- It Pays to Sleep: Our Sleep Performance Program incentivizes employees to get more sleep. Log an average sleep performance of 85% or higher for the month and get a $100 bonus.
- Location, Location, Location: You can’t beat the views from the rooftop of One Kenmore Square. Feel inspired daily as you work, enjoy free snacks and coffee, and collaborate in the heart of Boston.
Experience building or integrating GRC programs in enterprise security to improve overall security posture of the organizationExcellent communication, interpersonal, and leadership skills with the ability to influence across teams and levelsDeep understanding of regulations and standards including, but not limited to ISO 27001, SOC 2, GDPR, PCI, NIST CSF, and privacy/security obligations10+ years of experience in GRC, or information security / cybersecurity, with 5+ years in managing GRC, information security, or cybersecurity professionalsDemonstrated success scaling GRC programs whilst crafting clear and efficient team objectives and programsA minimum bachelor’s degree in any discipline. Computer science, cyber security and risk or technology degrees preferredYou are a risk aware leader with ability to translate security risks in business terms to influence both technical and non‑technical teamsYou are a strategic and people‑focused leader who thrives on balancing hands‑on oversight with long‑term organizational growthYou are passionate about building bridges across different departments and can operate confidently in both strategic and security control tactical domainsYou believe that security enables innovation, and you lead with integrity fostering a culture that embodies risk mind‑setBackground in establishing DevSecOps, AI Governance, and SSDLC guardrailsBackground in leading Enterprise Risk, Cybersecurity Risk, Information Security programsCertifications such as CISA, CISSP, CIPP/E, CRISC, ISO Lead Auditor, or HITRUST CCSFP