# Manager and Senior Manager: Governance, Risk, & Compliance

**Company:** [WHOOP](https://hotfix.jobs/companies/whoop)
**Location:** Boston, MA
**Role:** Other
**Experience:** 8+ years
**Skills:** GRC, ISO 27001, SOC 2, GDPR, HIPAA, nist csf, PCI, Cloud Security, third-party risk management, risk register management, Incident Response, cisa, cissp, crisc
**Posted:** 2026-07-17

> Lead day-to-day execution of WHOOP's GRC program including risk management, third-party assessments, compliance with ISO 27001/SOC 2/GDPR/HIPAA, KPI reporting, and team mentoring in a high-growth health tech environment. Requires 8+ years GRC/infosec experience with 4+ years managing professionals.

## Job Description

## Responsibilities
- Drive the development, implementation, and continuous evolution of the governance program, driving both strategy and hands-on execution to maintain alignment with ISO 27001, SOC 2, GDPR, and other applicable regulatory frameworks.
- Partner in the development, implementation, and ongoing management of scalable security control frameworks, policies, standards, and security awareness programs, third-party risk assessment, SDLC assessment, and risk program management, contributing directly while guiding the team’s work to strengthen organizational compliance.
- Support incident response activities by ensuring regulatory requirements, breach documentation, and post-incident reviews are completed and translated into actionable improvements across the risk and compliance program.
- Actively manage the enterprise risk register, driving risk prioritization, maintaining visibility across key risk domains, and delivering executive-level reporting.
- Spearhead enterprise risk reviews by driving GRC intake and request triage, personally overseeing complex assessments while prioritizing and delegating work across the team.
- Coach, mentor, and develop GRC analysts while balancing hands-on execution with effective delegation and team enablement as the program scales.
- Lead the third-party risk management lifecycle by conducting and overseeing vendor risk assessments and due diligence in partnership with Legal, IT, and Security.
- Own the operational intake and triage process for all GRC requests, including third-party vendor risk assessments, security questionnaires, SDLC risk reviews, and compliance inquiries, ensuring work is prioritized, assigned, and completed within established service levels.
- Develop and report operational metrics and KPIs, providing weekly dashboards and status updates on assessment volumes, turnaround times, backlog, SLA performance, and program health to the leadership.
- Evaluate, implement, and continuously improve GRC tools, processes, and metrics through hands-on execution and operational leadership to support program scale, transparency, and accountability.

## Qualifications
- 8+ years of experience in GRC, or information security preferably in health tech, SaaS, or regulated environments, with ~4+ years managing GRC, compliance, audit or cybersecurity professionals.
- Deep understanding of regulations and standards including, but not limited to ISO 27001, SOC 2, GDPR, PCI, NIST CSF, and privacy/security obligations applicable to regulated or sensitive health data, including HIPAA where relevant.
- Experience managing or mentoring compliance, audit, or GRC professionals.
- Demonstrated experience leading operational GRC programs, including workload prioritization, KPI reporting, and cross-functional coordination.
- Strong understanding of cybersecurity controls, cloud security concepts, third-party risk assurance, and regulatory compliance requirements.
- Proven ability to build scalable, process-driven programs in high-growth or rapidly evolving environments.
- Highly organized and detail-oriented, with strong project execution and prioritization skills across competing deadlines.
- Superior communication and interpersonal skills - written and verbal.
- Relevant certifications (CISA, CISSP, CRISC, CIPP/E, ISO Lead Auditor, HITRUST CCSFP, or similar) are strongly preferred.
- A minimum bachelor’s degree in any discipline. Computer science, cyber security and risk or technology degrees preferred.

## Similar roles

- [Detection and Enforcement Program Manager](https://hotfix.jobs/jobs/471e1e46-0411-48dd-9883-cd500272a2e5) - Discord - San Francisco, CA - $160k – $180k/yr
- [AI & Automation Lead, Customer Operations](https://hotfix.jobs/jobs/0c15619f-ad78-4d5f-aa8c-28b2f4a4c629) - AlertMedia - Austin, TX
- [Compliance Operations Lead](https://hotfix.jobs/jobs/8e5c2d02-1665-4048-9836-26e93ebd2ab3) - Govsignals - New York, NY - $140k – $190k/yr
- [AI Accelerator Lead](https://hotfix.jobs/jobs/d9a2ddc1-a24a-4177-b5d0-133649b62a68) - Vercel - Remote - $114k – $172k/yr
- [Mine Planner](https://hotfix.jobs/jobs/a8664fb7-ff55-41c8-a1e1-4985026efdfb) - Mariana Minerals - San Francisco, CA - $140k – $175k/yr

**Apply:** https://hotfix.jobs/jobs/87d4a336-e609-4cff-94d1-644c41329656
**Canonical:** https://hotfix.jobs/jobs/87d4a336-e609-4cff-94d1-644c41329656