Senior GRC Analyst

Whoop
Boston
Workplace: OnsiteFull timeUSD 130,000 - 170,000 annuallyFunction: Solutions Engineering & Sales EngineeringSkills: ["Analytical thinking","Critical risk mindset","Communication","Stakeholder management","Presenting findings"]

Lead day-to-day operations of the Governance, Risk, and Compliance (GRC) program by executing structured cyber and AI risk assessments, managing exceptions, and performing SDLC/security compliance reviews. Maintain and operate the enterprise cyber risk register, translate technical control findings into business risk scenarios, support FAIR-based quantitative risk approaches, and prepare materials for executive risk reporting and the Cyber Risk Committee.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Whoop
Whoop
3 weeks ago

Senior GRC Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Lead day-to-day operations of the Governance, Risk, and Compliance (GRC) program by executing structured cyber and AI risk assessments, managing exceptions, and performing SDLC/security compliance reviews. Maintain and operate the enterprise cyber risk register, translate technical control findings into business risk scenarios, support FAIR-based quantitative risk approaches, and prepare materials for executive risk reporting and the Cyber Risk Committee.
Location: Boston
Workplace: Onsite
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Lead cyber, AI, and technology risk assessments across systems, cloud environments, business processes, and major initiatives, evaluating threats, vulnerabilities, control effectiveness, and residual risk.
  • •Maintain and operate the enterprise cyber risk register, including drafting risk statements, tracking mitigation plans, and supporting governance and reporting processes.
  • •Translate technical findings, architectural concerns, and control gaps into clear business risk scenarios to support prioritization and decision-making.
  • •Support and mature quantitative cyber risk analysis approaches such as FAIR to improve how risk is measured and communicated.
  • •Prepare materials for the Cyber Risk Committee and executive risk reporting, and partner with Legal, Security Architecture, Product Security, IT, and other teams to assess risks in system designs, architecture, identity models, data flows, platform changes, AI use cases, and third-party integrations.

Pay and Benefits

Salary: USD 130,000 - 170,000 annually
Equity and Bonus:Equity

Key Requirements

  • •6+ years of experience in cybersecurity, enterprise risk management, information security, or a related field.
  • •Experience conducting structured cybersecurity or IT risk assessments and translating findings into business risk for non-technical stakeholders.
  • •Experience maintaining risk registers and tracking risk mitigation/treatment activities.
  • •Deep understanding of security frameworks such as NIST CSF, ISO 27001, or PCI DSS, and familiarity with GDPR, HIPAA, or other privacy/data protection requirements.
  • •Experience assessing risks related to AI/ML and emerging technologies, including familiarity with NIST AI RMF or ISO/IEC 42001; certifications like CRISC, CISSP, CISA, or CGRC are a plus.
Experience:CybersecurityEnterprise risk managementInformation securityAI/ML
Skills:Analytical thinkingCritical risk mindsetCommunicationStakeholder managementPresenting findings
Certifications:CRISCCISSPCISACGRC
Tech Stack:NIST CSFISO 27001PCI DSSGDPRHIPAANIST AI RMFISO/IEC 42001FAIRSDLC

Company Brief

Whoop
Whoop designs and sells a subscription-based wearable fitness tracker and analytics platform that monitors recovery, strain, and sleep to optimize athletic performance and daily health for consumers and professional athletes.
Industry: Wearables
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series E+
Headquarters: Boston, United States
Founded: 2012
WebsiteLinkedIn