Whoop

Whoop

GRC Analyst - Third Party Risk

Boston, MA · Full-time

Sponsorship not specified$70k-$110kDetected 14 days ago
ComplianceProcurementOrganizational Skills

About the role

  • Success in this role requires strong attention to detail, responsiveness and accountability through completion in a fast-paced environment.
  • The key focus of this role will be helping ensure third-party vendor assessment requests are reviewed, prioritized, routed, tracked, and completed effectively.
  • You will use intake and ticketing data to identify workflow trends, recurring questions, handoff gaps, and opportunities to improve guidance, templates, reporting, automation, and stakeholder experience.

Responsibilities

  • Support day-to-day third-party vendor risk assessments - manage and triage GRC third-party vendor assessment intakes and accurate tracking through resolution
  • Perform vendor risk reviews, reassessments, partner coordination, remediation tracking, and cross-functional follow-up with Security, Legal, Privacy, Procurement, IT, Finance, and business owners
  • As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
  • As a GRC Analyst, you will support the WHOOP Governance, Risk, and Compliance program.
  • You will help manage third-party vendor risk reviews, and operational requests, in cross-functional security compliance workflows.

Requirements

  • The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.
  • While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate's specific qualifications, expertise, and alignment with the role's requirements.
  • Understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls - ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS
  • Highly organized and strong operational discipline ensuring clear and expedient escalations with informed recommendations to management
  • Being a team player and working to achieve common goal in a dynamic setting
  • A minimum bachelor's degree in any discipline. Computer science, cyber security and risk or technology degrees preferred.

Nice to have

  • 2+ years of experience in GRC - third-party risk management experience preferred
  • A minimum bachelor's degree in any discipline.
  • Computer science, cyber security and risk or technology degrees preferred.

Compensation

  • At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company's long-term growth and success.

Company info

  • At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience.

Equal opportunity

  • WHOOP is an Equal Opportunity Employer and participates in E-verify https://www.e-verify.gov/to determine employment eligibility

This listing is sourced directly from Whoop's careers page and normalized into a canonical job model.