Manager, Governance Risk & Compliance (GRC)
WHOOP - Boston, MA
Hiring: Manager, Governance Risk & Compliance (GRC) Company: WHOOP Location: Boston, MA Job Posted Time: 2026-09-10 11:48:42 Target Skills & Keywords : GDPR, HIPAA, PCI DSS, Project Management, Risk Management, SOC 2 About the job Experience: •8+ years of experience in GRC, information security, cybersecurity; with 2+ years of experience leading or managing GRC, information security, or audit professionals. Required Skills: •Lead the day-to-day operations of the GRC function, ensuring timely execution of governance, risk, compliance, third-party risk, and secure development lifecycle (SSDLC) assessment activities. •Lead enterprise risk reviews by driving GRC intake and request triage, personally overseeing complex assessments while prioritizing and delegating work across the team. •Perform and lead the third-party risk management lifecycle by conducting and overseeing vendor risk assessments and due diligence in partnership with Legal, IT, and Security. •Manage team workload and capacity by assigning, tracking, and escalating requests as needed to ensure consistent delivery, quality, and stakeholder satisfaction. •Develop and report operational metrics and KPIs, providing weekly dashboards and status updates to GRC leadership. •Contribute directly to governance activities, including policy management, control assessments, evidence collection, audit support, and continuous compliance initiatives. •Maintain the enterprise risk register by documenting, tracking, escalating, and reporting technology, cybersecurity, privacy, and third-party risks •Support security incident response activities by coordinating compliance-related obligations, regulatory documentation, and risk remediation tracking. Qualifications: •Demonstrated experience leading operational GRC programs, including intake management, workload prioritization, KPI reporting, and cross-functional coordination. •Extensive hands-on experience performing third-party/vendor risk assessments, security reviews, due diligence, and risk-based decision support. •Strong knowledge of SSDLC risk assessments and application security governance processes. •Deep knowledge of security and privacy frameworks and regulations, including ISO 27001, SOC 2, NIST CSF, HIPAA, GDPR, PCI DSS, and modern cybersecurity risk management practices. •Excellent written and verbal communication skills, with the ability to communicate effectively with technical teams, business stakeholders, auditors, and executive leadership •A minimum bachelor’s degree in any discipline. Computer science, cybersecurity, and risk or technology degrees preferred. •Professional certifications such as CISSP, CRISC, CISA, or ISO 27001 Lead Auditor. •Demonstrated success in program and project management skills with the ability to manage multiple concurrent workstreams in a fast-paced environment. •Exceptional organizational, analytical, and problem-solving skills. •Background in establishing SSDLC guardrails. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!