# Manager, Governance Risk & Compliance (GRC) at Whoop

- Company: Whoop
- What the company does: Backed by SoftBank VF and IVP.
- Company website: https://www.whoop.com/
- Type: Startups
- Level: Senior
- Location: Boston, MA
- Work setup: On-site
- Pay: $155K to $195K base salary per year (USD)
- Posted: 2026-09-08
- Apply by: 2026-10-23
- Apply: https://jobs.ashbyhq.com/whoop/79fdf147-0d79-4ca1-8ce6-374df98179e3
- Page: https://www.1752.vc/careers/jobs/whoop-manager-governance-risk-and-compliance-grc/

## About the role

Lead the day-to-day operations of the GRC function, ensuring timely execution of governance, risk, compliance, third-party risk, and secure development lifecycle (SSDLC) assessment activities. Lead enterprise risk reviews by driving GRC intake and request triage, personally overseeing complex assessments while prioritizing and delegating work across the team.

## What they're looking for

- 8+ years of experience in GRC, information security, cybersecurity, with 2+ years of experience leading or managing GRC, information security, or audit professionals
- Demonstrated experience leading operational GRC programs, including intake management, workload prioritization, KPI reporting, and cross-functional coordination
- Extensive hands-on experience performing third-party/vendor risk assessments, security reviews, due diligence, and risk-based decision support
- Strong knowledge of SSDLC risk assessments and application security governance processes
- Deep knowledge of security and privacy frameworks and regulations, including ISO 27001, SOC 2, NIST CSF, HIPAA, GDPR, PCI DSS, and modern cybersecurity risk management practices
- Excellent written and verbal communication skills, with the ability to communicate effectively with technical teams, business stakeholders, auditors, and executive leadership

Tags: Information Security
