Senior Manager, Governance, Risk, & Compliance (GRC)
Boston, MA
WHOOP
Monitor your sleep, strain, recovery, and health with the most advanced fitness and health wearable available today. WHOOP helps you discover data-driven insights for a healthier, more empowered life.
At WHOOP, we're on a mission to unlock human performance. WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives.
WHOOP is seeking a strategic and execution-oriented Senior Manager of Governance, Risk and Compliance to lead the next phase of the GRC program in a fast-paced, high-growth environment. This role will lead both the design and hands-on execution of the GRC function. Initially, this includes building structure, implementing tools, and guiding day-to-day activities while laying the foundation to scale team capabilities and delegate ownership over time. The ideal candidate will partner across Legal, Security, Product, and other teams to ensure alignment with regulatory frameworks, reduce enterprise risk, and strengthen operational resilience.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
WHOOP is seeking a strategic and execution-oriented Senior Manager of Governance, Risk and Compliance to lead the next phase of the GRC program in a fast-paced, high-growth environment. This role will lead both the design and hands-on execution of the GRC function. Initially, this includes building structure, implementing tools, and guiding day-to-day activities while laying the foundation to scale team capabilities and delegate ownership over time. The ideal candidate will partner across Legal, Security, Product, and other teams to ensure alignment with regulatory frameworks, reduce enterprise risk, and strengthen operational resilience.
Responsibilities:
- Lead the development, implementation, and evolution of a comprehensive governance, risk, and compliance program aligned with standards such as ISO 27001, SOC2, GDPR, and other global regulatory expectations
- Own the enterprise risk register, delivering ongoing visibility, prioritization, and executive-level reporting across key risk domains
- Drive the third-party risk management lifecycle, overseeing vendor risk assessments and due diligence in partnership with Legal, IT, and Security
- Oversee the development and lifecycle of scalable policies, standards, and training programs that promote security awareness and strengthen organizational compliance
- Serve as the lead point of contact for internal and external audits and assessments, managing evidence workflows and driving remediation to completion
- Identify, implement, and improve GRC tools, processes, and metrics to support program scale, transparency, and accountability
- Support incident response processes by ensuring regulatory alignment, breach documentation, and post-incident reviews are conducted and integrated into risk and compliance programs
- Lead by doing - execute critical GRC workstreams directly while scaling team capabilities, maturing processes, and transitioning ownership to analysts over time
- Manage and mentor GRC analysts, balancing direct execution with team enablement as the program grows
Qualifications:
- 6+ years of experience in GRC, information security, audit, or compliance roles, preferably in health tech, SaaS, or regulated environments
- Deep understanding of regulations and standards including GDPR, ISO 27001, SOC 2, and NIST CSF
- Experience managing organizational risk registers and applying risk-informed decision-making
- Proven ability to lead third-party risk management in collaboration with internal stakeholders
- Familiarity with audit workflows, evidence collection, and control testing in fast-paced or audit-intensive environments
- Experience managing or mentoring compliance, audit, or GRC professionals
- Relevant certifications such as CISA, CISSP, CIPP/E, CRISC, ISO Lead Auditor, HITRUST CCSFP, or PMP are a plus
- Proven ability to build scalable, process-driven programs in high-growth or rapidly evolving environments
- Highly organized and detail-oriented, with strong project execution and prioritization skills across competing deadlines
- Demonstrated accountability to metrics, data-driven reporting, and outcome-based program management
- Strong commitment to embracing and leveraging AI tools in day-to-day tasks, ensuring AI-assisted work aligns with the same high-quality standards as personal contributions, with awareness of emerging governance and ethical considerations such as data privacy and model transparency
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
1
1
0
Categories:
Compliance Jobs
Leadership Jobs
Tags: Audits CIPP CISA CISSP Compliance CRISC GDPR Governance HITRUST Incident response ISO 27001 NIST Privacy Risk assessment Risk management SaaS SOC SOC 2
Perks/benefits: Career development Team events Transparency
Region:
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Product Security Engineer jobsInformation System Security Officer jobsSenior Security Analyst jobsSenior Cloud Security Engineer jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsSystems Engineer jobsSenior Information Security Analyst jobsInformation Security Manager jobsSenior Network Security Engineer jobsIT Security Engineer jobsCyber Security Specialist jobsIT Security Analyst jobsChief Information Security Officer jobsSecurity Consultant jobsSecurity Specialist jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsSenior Product Security Engineer jobsSenior Cyber Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Information Security Engineer jobsThreat Intelligence Analyst jobsCyber Security Architect jobsSecurity Operations Analyst jobs
SaaS jobsTS/SCI jobsBash jobsEDR jobsEncryption jobsIDS jobsThreat detection jobsIPS jobsSplunk jobsMalware jobsSDLC jobsTerraform jobsTop Secret jobsFinance jobsSQL jobsForensics jobsDocker jobsRMF jobsIntrusion detection jobsCompTIA jobsSOC 2 jobsITIL jobsOWASP jobsGIAC jobsActive Directory jobs
DoDD 8570 jobsAnsible jobsHIPAA jobsVPN jobsTCP/IP jobsOSCP jobsData Analytics jobsSOAR jobsIT infrastructure jobsUNIX jobsSANS jobsMITRE ATT&CK jobsClearance Required jobsCCSP jobsSAP jobsCRISC jobsJira jobsBanking jobsSOX jobsJavaScript jobsPolygraph jobsNIST 800-53 jobsSecurity strategy jobsMachine Learning jobsIndustrial jobs