Manager and Senior Manager: Governance, Risk, & Compliance (GRC)

Whoop
Boston
Workplace: OnsiteFull timeUSD 155,000 - 205,000 annuallyFunction: Legal, Risk & ComplianceExperience: 8+ yearsEducation: bachelorsSkills: ["Leadership","Communication","Interpersonal skills","Organizational skills","Detail orientation"]

Lead the governance, risk, and compliance (GRC) program end to end—combining strategy with hands-on execution to align with ISO 27001, SOC 2, GDPR, and other applicable frameworks. Own control and policy development, incident-response compliance support, third-party risk management, risk register oversight, and GRC request intake/triage. Deliver executive reporting through KPIs, and continuously improve GRC tools, processes, and operational metrics while coaching GRC analysts.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Whoop
Whoop
3 weeks ago

Manager and Senior Manager: Governance, Risk, & Compliance (GRC)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Lead the governance, risk, and compliance (GRC) program end to end—combining strategy with hands-on execution to align with ISO 27001, SOC 2, GDPR, and other applicable frameworks. Own control and policy development, incident-response compliance support, third-party risk management, risk register oversight, and GRC request intake/triage. Deliver executive reporting through KPIs, and continuously improve GRC tools, processes, and operational metrics while coaching GRC analysts.
Location: Boston
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance

Key Responsibilities

  • •Drive the development, implementation, and continuous evolution of the governance program to maintain alignment with ISO 27001, SOC 2, GDPR, and other applicable frameworks.
  • •Develop and manage scalable security control frameworks, policies, standards, and security awareness programs, including third-party risk assessment and SDLC assessment, guiding the team’s work to strengthen compliance.
  • •Support incident response by ensuring regulatory requirements, breach documentation, and post-incident reviews are completed and translated into actionable improvements.
  • •Manage the enterprise risk register and run enterprise risk reviews by triaging GRC intake requests, personally overseeing complex assessments, and prioritizing/delegating work.
  • •Lead third-party risk management and improve GRC operations by owning request intake/triage for GRC inquiries, building KPI dashboards, and continuously enhancing GRC tools and processes.

Pay and Benefits

Salary: USD 155,000 - 205,000 annually
Equity and Bonus:Equity
Perks:Equity

Key Requirements

  • •8+ years of experience in GRC or information security, preferably in health tech, SaaS, or regulated environments, with ~4+ years managing GRC, compliance, audit, or cybersecurity professionals.
  • •Deep understanding of regulations and standards including ISO 27001, SOC 2, GDPR, PCI, NIST CSF, and privacy/security obligations (including HIPAA where relevant).
  • •Experience managing or mentoring compliance, audit, or GRC professionals.
  • •Demonstrated experience leading operational GRC programs, including workload prioritization, KPI reporting, and cross-functional coordination.
  • •Relevant certifications (CISA, CISSP, CRISC, CIPP/E, ISO Lead Auditor, HITRUST CCSFP, or similar) are strongly preferred.
Experience:8+ yearsHealth techSaaSRegulated environments
Education:Bachelor's
Skills:LeadershipCommunicationInterpersonal skillsOrganizational skillsDetail orientation
Certifications:CISACISSPCRISCCIPP/EISO Lead AuditorHITRUST CCSFP
Tech Stack:ISO 27001SOC 2GDPRPCINIST CSFSDLCThird-party riskHIPAA

Company Brief

Whoop
Whoop designs and sells a subscription-based wearable fitness tracker and analytics platform that monitors recovery, strain, and sleep to optimize athletic performance and daily health for consumers and professional athletes.
Industry: Wearables
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: Boston, United States
Founded: 2012
WebsiteLinkedIn