Whoop
GRC Analyst - Third Party Risk
Boston, MA · Full-time
Sponsorship not specified$70k-$110kDetected 14 days ago
ComplianceProcurementOrganizational Skills
About the role
- Success in this role requires strong attention to detail, responsiveness and accountability through completion in a fast-paced environment.
- The key focus of this role will be helping ensure third-party vendor assessment requests are reviewed, prioritized, routed, tracked, and completed effectively.
- You will use intake and ticketing data to identify workflow trends, recurring questions, handoff gaps, and opportunities to improve guidance, templates, reporting, automation, and stakeholder experience.
Responsibilities
- Support day-to-day third-party vendor risk assessments - manage and triage GRC third-party vendor assessment intakes and accurate tracking through resolution
- Perform vendor risk reviews, reassessments, partner coordination, remediation tracking, and cross-functional follow-up with Security, Legal, Privacy, Procurement, IT, Finance, and business owners
- As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
- As a GRC Analyst, you will support the WHOOP Governance, Risk, and Compliance program.
- You will help manage third-party vendor risk reviews, and operational requests, in cross-functional security compliance workflows.
Requirements
- The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.
- While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate's specific qualifications, expertise, and alignment with the role's requirements.
- Understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls - ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS
- Highly organized and strong operational discipline ensuring clear and expedient escalations with informed recommendations to management
- Being a team player and working to achieve common goal in a dynamic setting
- A minimum bachelor's degree in any discipline. Computer science, cyber security and risk or technology degrees preferred.
Nice to have
- 2+ years of experience in GRC - third-party risk management experience preferred
- A minimum bachelor's degree in any discipline.
- Computer science, cyber security and risk or technology degrees preferred.
Compensation
- At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company's long-term growth and success.
Company info
- At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience.
Equal opportunity
- WHOOP is an Equal Opportunity Employer and participates in E-verify https://www.e-verify.gov/to determine employment eligibility
This listing is sourced directly from Whoop's careers page and normalized into a canonical job model.