Backed by SoftBank VF and IVP.
About the role
Lead the day-to-day operations of the GRC function, ensuring timely execution of governance, risk, compliance, third-party risk, and secure development lifecycle (SSDLC) assessment activities. Lead enterprise risk reviews by driving GRC intake and request triage, personally overseeing complex assessments while prioritizing and delegating work across the team.
What they're looking for
- 8+ years of experience in GRC, information security, cybersecurity, with 2+ years of experience leading or managing GRC, information security, or audit professionals
- Demonstrated experience leading operational GRC programs, including intake management, workload prioritization, KPI reporting, and cross-functional coordination
- Extensive hands-on experience performing third-party/vendor risk assessments, security reviews, due diligence, and risk-based decision support
- Strong knowledge of SSDLC risk assessments and application security governance processes
- Deep knowledge of security and privacy frameworks and regulations, including ISO 27001, SOC 2, NIST CSF, HIPAA, GDPR, PCI DSS, and modern cybersecurity risk management practices
- Excellent written and verbal communication skills, with the ability to communicate effectively with technical teams, business stakeholders, auditors, and executive leadership
More about this role
At WHOOP, we're on a mission to unlock human performance. WHOOP empowers
members to perform at a higher level through a deeper understanding of their bodies
and daily lives.
As a Manager of Governance, Risk, and Compliance you will lead the day-to-day
execution and support the ongoing operation of the GRC program in a fast-paced,
high-growth environment. This role is responsible for hands-on execution of GRC
initiatives, collaborating across Legal, Security, Product, and other teams to advance
compliance objectives, reduce enterprise risk exposure, and strengthen operational
resilience.
Lead the day-to-day operations of the GRC function, ensuring timely execution of governance, risk, compliance, third-party risk, and secure development lifecycle (SSDLC) assessment activities.
Lead enterprise risk reviews by driving GRC intake and request triage, personally overseeing complex assessments while prioritizing and delegating work across the team.
Perform and lead the third-party risk management lifecycle by conducting and overseeing vendor risk assessments and due diligence in partnership with Legal, IT, and Security.
Manage team workload and capacity by assigning, tracking, and...
Browse similar: Startup jobs · Boston