Manager, Governance Risk & Compliance (GRC)

Whoop
Boston
Workplace: OnsiteFull timeUSD 155,000 - 195,000 annuallyFunction: Legal, Risk & ComplianceExperience: 8+ yearsEducation: bachelorsSkills: ["Written communication","Verbal communication","Cross-functional coordination","Organizational skills","Analytical skills"]

Lead the day-to-day operation of the GRC program, driving governance, risk, compliance, third-party risk, and secure development lifecycle (SSDLC) assessment activities. Oversee complex enterprise risk reviews, manage intake and triage, and lead vendor due diligence in partnership with Legal, IT, and Security. Build and report operational KPIs, maintain the risk register, and support compliance obligations tied to security incident response and audit readiness.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Whoop
Whoop
1 day ago

Manager, Governance Risk & Compliance (GRC)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Lead the day-to-day operation of the GRC program, driving governance, risk, compliance, third-party risk, and secure development lifecycle (SSDLC) assessment activities. Oversee complex enterprise risk reviews, manage intake and triage, and lead vendor due diligence in partnership with Legal, IT, and Security. Build and report operational KPIs, maintain the risk register, and support compliance obligations tied to security incident response and audit readiness.
Location: Boston
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Manager level

Key Responsibilities

  • •Lead the day-to-day operations of the GRC function, ensuring timely execution of governance, risk, compliance, third-party risk, and SSDLC assessment activities.
  • •Drive enterprise risk reviews by managing GRC intake, triaging requests, and overseeing complex assessments while prioritizing and delegating work.
  • •Lead third-party risk management by conducting and overseeing vendor risk assessments and due diligence in partnership with Legal, IT, and Security.
  • •Manage team workload and capacity by assigning, tracking, and escalating requests to ensure consistent delivery, quality, and stakeholder satisfaction.
  • •Develop and report operational metrics and maintain the enterprise risk register, supporting governance evidence collection, audit support, and compliance-related incident response obligations.

Pay and Benefits

Salary: USD 155,000 - 195,000 annually
Equity and Bonus:Equity

Key Requirements

  • •8+ years of experience in GRC, information security, or cybersecurity, including 2+ years leading or managing GRC, information security, or audit professionals.
  • •Proven experience running operational GRC programs with intake management, workload prioritization, KPI reporting, and cross-functional coordination.
  • •Hands-on experience conducting third-party/vendor risk assessments, security reviews, and due diligence.
  • •Strong knowledge of SSDLC risk assessments and application security governance processes.
  • •Deep knowledge of security and privacy frameworks and regulations including ISO 27001, SOC 2, NIST CSF, HIPAA, GDPR, and PCI DSS.
Experience:8+ yearsGRCInformation securityCybersecurityThird-party riskSecurity governance
Education:Bachelor's
Skills:Written communicationVerbal communicationCross-functional coordinationOrganizational skillsAnalytical skills
Certifications:CISSPCRISCCISAISO 27001 Lead AuditorHITRUST CCSFP
Tech Stack:ISO 27001SOC 2NIST CSFHIPAAGDPRPCI DSSSSDLC

Company Brief

Whoop
Whoop designs and sells a subscription-based wearable fitness tracker and analytics platform that monitors recovery, strain, and sleep to optimize athletic performance and daily health for consumers and professional athletes.
Industry: Wearables
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: Boston, United States
Founded: 2012
WebsiteLinkedIn