Manager, Governance Risk & Compliance (GRC)

WhoopBoston, MA
$155,000 - $195,000Onsite

About The Position

At WHOOP, we're on a mission to unlock human performance. WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives. As a Manager of Governance, Risk, and Compliance you will lead the day-to-day execution and support the ongoing operation of the GRC program in a fast-paced, high-growth environment. This role is responsible for hands-on execution of GRC initiatives, collaborating across Legal, Security, Product, and other teams to advance compliance objectives, reduce enterprise risk exposure, and strengthen operational resilience.

Requirements

  • 8+ years of experience in GRC, information security, cybersecurity; with 2+ years of experience leading or managing GRC, information security, or audit professionals.
  • Demonstrated experience leading operational GRC programs, including intake management, workload prioritization, KPI reporting, and cross-functional coordination.
  • Extensive hands-on experience performing third-party/vendor risk assessments, security reviews, due diligence, and risk-based decision support.
  • Strong knowledge of SSDLC risk assessments and application security governance processes.
  • Deep knowledge of security and privacy frameworks and regulations, including ISO 27001, SOC 2, NIST CSF, HIPAA, GDPR, PCI DSS, and modern cybersecurity risk management practices.
  • Excellent written and verbal communication skills, with the ability to communicate effectively with technical teams, business stakeholders, auditors, and executive leadership.
  • A minimum bachelor’s degree in any discipline. Computer science, cybersecurity, and risk or technology degrees preferred.

Nice To Haves

  • Professional certifications such as CISSP, CRISC, CISA, ISO 27001 Lead Auditor, or HITRUST CCSFP.
  • Demonstrated success in program and project management skills with the ability to manage multiple concurrent workstreams in a fast-paced environment.
  • Exceptional organizational, analytical, and problem-solving skills.
  • Background in establishing SSDLC guardrails.

Responsibilities

  • Lead the day-to-day operations of the GRC function, ensuring timely execution of governance, risk, compliance, third-party risk, and secure development lifecycle (SSDLC) assessment activities.
  • Lead enterprise risk reviews by driving GRC intake and request triage, personally overseeing complex assessments while prioritizing and delegating work across the team.
  • Perform and lead the third-party risk management lifecycle by conducting and overseeing vendor risk assessments and due diligence in partnership with Legal, IT, and Security.
  • Manage team workload and capacity by assigning, tracking, and escalating requests as needed to ensure consistent delivery, quality, and stakeholder satisfaction.
  • Develop and report operational metrics and KPIs, providing weekly dashboards and status updates to GRC leadership.
  • Contribute directly to governance activities, including policy management, control assessments, evidence collection, audit support, and continuous compliance initiatives.
  • Maintain the enterprise risk register by documenting, tracking, escalating, and reporting technology, cybersecurity, privacy, and third-party risks.
  • Support security incident response activities by coordinating compliance-related obligations, regulatory documentation, and risk remediation tracking.

Benefits

  • meaningful equity
  • generous equity package
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service