Manager and Senior Manager: Governance, Risk, & Compliance
Lead day-to-day execution of WHOOP's GRC program including risk management, third-party assessments, compliance with ISO 27001/SOC 2/GDPR/HIPAA, KPI reporting, and team mentoring in a high-growth health tech environment. Requires 8+ years GRC/infosec experience with 4+ years managing professionals.
Salary not listed
On-site8+ YOEOther
About the role
Responsibilities
Drive the development, implementation, and continuous evolution of the governance program, driving both strategy and hands-on execution to maintain alignment with ISO 27001, SOC 2, GDPR, and other applicable regulatory frameworks.
Partner in the development, implementation, and ongoing management of scalable security control frameworks, policies, standards, and security awareness programs, third-party risk assessment, SDLC assessment, and risk program management, contributing directly while guiding the team’s work to strengthen organizational compliance.
Support incident response activities by ensuring regulatory requirements, breach documentation, and post-incident reviews are completed and translated into actionable improvements across the risk and compliance program.
Actively manage the enterprise risk register, driving risk prioritization, maintaining visibility across key risk domains, and delivering executive-level reporting.
Spearhead enterprise risk reviews by driving GRC intake and request triage, personally overseeing complex assessments while prioritizing and delegating work across the team.
Coach, mentor, and develop GRC analysts while balancing hands-on execution with effective delegation and team enablement as the program scales.
Lead the third-party risk management lifecycle by conducting and overseeing vendor risk assessments and due diligence in partnership with Legal, IT, and Security.
Own the operational intake and triage process for all GRC requests, including third-party vendor risk assessments, security questionnaires, SDLC risk reviews, and compliance inquiries, ensuring work is prioritized, assigned, and completed within established service levels.
Develop and report operational metrics and KPIs, providing weekly dashboards and status updates on assessment volumes, turnaround times, backlog, SLA performance, and program health to the leadership.
Evaluate, implement, and continuously improve GRC tools, processes, and metrics through hands-on execution and operational leadership to support program scale, transparency, and accountability.
Qualifications
8+ years of experience in GRC, or information security preferably in health tech, SaaS, or regulated environments, with ~4+ years managing GRC, compliance, audit or cybersecurity professionals.
Deep understanding of regulations and standards including, but not limited to ISO 27001, SOC 2, GDPR, PCI, NIST CSF, and privacy/security obligations applicable to regulated or sensitive health data, including HIPAA where relevant.
Experience managing or mentoring compliance, audit, or GRC professionals.
Demonstrated experience leading operational GRC programs, including workload prioritization, KPI reporting, and cross-functional coordination.
Strong understanding of cybersecurity controls, cloud security concepts, third-party risk assurance, and regulatory compliance requirements.
Proven ability to build scalable, process-driven programs in high-growth or rapidly evolving environments.
Highly organized and detail-oriented, with strong project execution and prioritization skills across competing deadlines.
Superior communication and interpersonal skills - written and verbal.
Relevant certifications (CISA, CISSP, CRISC, CIPP/E, ISO Lead Auditor, HITRUST CCSFP, or similar) are strongly preferred.
A minimum bachelor’s degree in any discipline. Computer science, cyber security and risk or technology degrees preferred.
Program manage product, process, and detection initiatives on Discord's Youth Safety team to improve mitigations against child sexual exploitation and other harms. Requires 6-10 years program management experience in safety/threat detection, intermediate SQL, and a bachelor's degree.
160k – 180k/yr
On-site6+ YOEOther
AI & Automation Lead, Customer Operations
AlertMediaAustin, TX
Lead the identification, implementation, and scaling of AI and automation solutions to improve efficiency and customer outcomes in Customer Operations. Requires 2+ years experience, technical fluency, and the ability to drive initiatives from concept to execution with minimal oversight.
Salary not listed
Hybrid2+ YOEOther
Compliance Operations Lead
GovsignalsNew York, NY
Build and own the end-to-end security and compliance program for a government contracting AI platform, driving FedRAMP High ATO, automating evidence collection in CI/CD, and serving as the customer-facing trust lead. Requires 3+ years leading compliance programs with proven FedRAMP success and fluency in public-sector frameworks.
140k – 190k/yr
Hybrid3+ YOEOther
AI Accelerator Lead
VercelSan Francisco, CA
Own and execute the full lifecycle of Vercel's AI Accelerator program for pre-seed and idea-stage AI founders. Design cohorts, manage applications through Demo Day, build founder relationships and community, and partner cross-functionally to deliver exceptional programming and content while feeding insights back into Vercel.
114k – 172k/yr
Remote5+ YOEOther
Mine Planner
Mariana MineralsSan Francisco, CA
Senior Mine Planner leading strategic long-range mine planning, multi-pit optimization, and portfolio evaluation to maximize NPV and guide capital allocation decisions for mining projects. Requires 5+ years experience with tools like Deswik/Whittle and expertise connecting technical plans to corporate strategy.