Senior GRC Analyst
WHOOP - Boston, MA
Hiring: Senior GRC Analyst Company: WHOOP Location: Boston, MA Job Posted Time: 2026-09-10 11:48:42 Target Skills & Keywords : AI, GDPR, HIPAA, Machine Learning, PCI DSS, Risk Management About the job Experience: •6+ years of experience in cybersecurity or enterprise risk management, information security, or a related field Required Skills: •Lead cyber, AI, and technology risk assessments across systems, cloud environments, business processes, and major initiatives, evaluating threats, vulnerabilities, control effectiveness, and residual risk •Maintain and operate the enterprise cyber risk register, including drafting risk statements, tracking mitigation plans, and supporting governance and reporting processes •Translate technical findings, architectural concerns, and control gaps into clear business risk scenarios that support prioritization and decision-making •Support and help mature quantitative cyber risk analysis approaches such as FAIR to improve how risk is measured and communicated •Prepare materials and analysis to support the Cyber Risk Committee and executive risk reporting •Partner with Security Architecture to assess risk in system designs, cloud architecture, identity models, data flows, and platform changes •Partner cross-functionally with Security Engineering, Product Security, Legal, IT, and business teams to evaluate new initiatives, technology changes, artificial intelligence use cases, and third-party integrations through a risk lens •Conduct risk assessments for emerging technologies including artificial intelligence and machine learning systems, evaluating data usage, model behavior, external dependencies, and security implications Qualifications: •Demonstrated experience conducting structured cybersecurity or IT risk assessment •Comprehensive expertise in security frameworks such as NIST CSF, ISO 27001, or PCI DSS, and familiarity with regulatory environments such as GDPR, HIPAA or other privacy and data protection requirements •Demonstrated capacity to translate technical findings into clear business risk for non-technical stakeholders •Strong written and verbal communication skills with experience presenting findings to cross-functional teams •Professional certifications such as CRISC, CISSP, CISA, or CGRC are a plus •This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office. •Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!