GRC Analyst - Third Party Risk

Whoop
Boston
Workplace: OnsiteFull timeUSD 70,000 - 110,000 annuallyFunction: Legal, Risk & ComplianceExperience: 2+ yearsEducation: bachelorsSkills: ["Attention to detail","Responsiveness","Accountability","Organizational skills","Operational discipline","Teamwork"]

Support the Governance, Risk, and Compliance program by managing and completing third-party vendor risk assessment requests. Triage and track GRC intakes, route issues across security, legal, privacy, procurement, IT, finance, and business owners, and ensure vendor reviews and reassessments are completed. Use intake and ticketing data to spot trends and improve guidance, templates, reporting, automation, and stakeholder experience.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Whoop
Whoop
2 weeks ago

GRC Analyst - Third Party Risk

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Support the Governance, Risk, and Compliance program by managing and completing third-party vendor risk assessment requests. Triage and track GRC intakes, route issues across security, legal, privacy, procurement, IT, finance, and business owners, and ensure vendor reviews and reassessments are completed. Use intake and ticketing data to spot trends and improve guidance, templates, reporting, automation, and stakeholder experience.
Location: Boston
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance

Key Responsibilities

  • •Support day-to-day third-party vendor risk assessments by managing, triaging, and accurately tracking GRC third-party vendor assessment intakes through resolution.
  • •Perform vendor risk reviews, reassessments, partner coordination, remediation tracking, and cross-functional follow-up with Security, Legal, Privacy, Procurement, IT, Finance, and business owners.
  • •Assist with third-party risk program management activities.
  • •Help ensure third-party vendor assessment requests are reviewed, prioritized, routed, tracked, and completed effectively.
  • •Use intake and ticketing data to identify workflow trends, recurring questions, handoff gaps, and improvement opportunities for guidance, templates, reporting, automation, and stakeholder experience.

Pay and Benefits

Salary: USD 70,000 - 110,000 annually
Equity and Bonus:Equity
Perks:Equity

Key Requirements

  • •2+ years of experience in GRC, with third-party risk management experience preferred.
  • •Understanding of cybersecurity compliance frameworks and controls including ISO 27001, NIST CSF, COSO, SOC 2, and PDI-DSS.
  • •Highly organized with strong operational discipline to drive clear, fast escalations with informed recommendations to management.
  • •Strong teamwork and ability to work toward common goals in a fast-paced, dynamic environment.
  • •Minimum bachelor’s degree in any discipline; computer science, cyber security and risk, or technology degrees preferred.
Experience:2+ yearsGRCThird-party risk managementCybersecurity compliance
Education:Bachelor's
Skills:Attention to detailResponsivenessAccountabilityOrganizational skillsOperational disciplineTeamwork
Tech Stack:ISO 27001NIST CSFCOSOSOC 2PDI-DSS

Company Brief

Whoop
Whoop designs and sells a subscription-based wearable fitness tracker and analytics platform that monitors recovery, strain, and sleep to optimize athletic performance and daily health for consumers and professional athletes.
Industry: Wearables
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: Boston, United States
Founded: 2012
WebsiteLinkedIn