Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Manager, Governance, Risk, & Compliance (GRC) image - Rise Careers
Job details

Senior Manager, Governance, Risk, & Compliance (GRC)

At WHOOP, we're on a mission to unlock human performance. WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives. 


WHOOP is seeking a strategic and execution-oriented Senior Manager of Governance, Risk and Compliance to lead the next phase of the GRC program in a fast-paced, high-growth environment. This role will lead both the design and hands-on execution of the GRC function. Initially, this includes building structure, implementing tools, and guiding day-to-day activities while laying the foundation to scale team capabilities and delegate ownership over time. The ideal candidate will partner across Legal, Security, Product, and other teams to ensure alignment with regulatory frameworks, reduce enterprise risk, and strengthen operational resilience.


Responsibilities:
  • Lead the development, implementation, and evolution of a comprehensive governance, risk, and compliance program aligned with standards such as ISO 27001, SOC2, GDPR, and other global regulatory expectations
  • Own the enterprise risk register, delivering ongoing visibility, prioritization, and executive-level reporting across key risk domains
  • Drive the third-party risk management lifecycle, overseeing vendor risk assessments and due diligence in partnership with Legal, IT, and Security
  • Oversee the development and lifecycle of scalable policies, standards, and training programs that promote security awareness and strengthen organizational compliance
  • Serve as the lead point of contact for internal and external audits and assessments, managing evidence workflows and driving remediation to completion
  • Identify, implement, and improve GRC tools, processes, and metrics to support program scale, transparency, and accountability
  • Support incident response processes by ensuring regulatory alignment, breach documentation, and post-incident reviews are conducted and integrated into risk and compliance programs


  • Lead by doing - execute critical GRC workstreams directly while scaling team capabilities, maturing processes, and transitioning ownership to analysts over time
  • Manage and mentor GRC analysts, balancing direct execution with team enablement as the program grows


Qualifications:
  • 6+ years of experience in GRC, information security, audit, or compliance roles, preferably in health tech, SaaS, or regulated environments
  • Deep understanding of regulations and standards including GDPR, ISO 27001, SOC 2, and NIST CSF
  • Experience managing organizational risk registers and applying risk-informed decision-making
  • Proven ability to lead third-party risk management in collaboration with internal stakeholders
  • Familiarity with audit workflows, evidence collection, and control testing in fast-paced or audit-intensive environments
  • Experience managing or mentoring compliance, audit, or GRC professionals
  • Relevant certifications such as CISA, CISSP, CIPP/E, CRISC, ISO Lead Auditor, HITRUST CCSFP, or PMP are a plus
  • Proven ability to build scalable, process-driven programs in high-growth or rapidly evolving environments
  • Highly organized and detail-oriented, with strong project execution and prioritization skills across competing deadlines
  • Demonstrated accountability to metrics, data-driven reporting, and outcome-based program management
  • Strong commitment to embracing and leveraging AI tools in day-to-day tasks, ensuring AI-assisted work aligns with the same high-quality standards as personal contributions, with awareness of emerging governance and ethical considerations such as data privacy and model transparency


Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.


WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility.  It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

WHOOP Glassdoor Company Review
3.4 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
WHOOP DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of WHOOP
WHOOP CEO photo
Will Ahmed
Approve of CEO

Average salary estimate

$120000 / YEARLY (est.)
min
max
$100000K
$140000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Manager, Governance, Risk, & Compliance (GRC), WHOOP

At WHOOP, we're not just about fitness; we're about unlocking human performance to help you excel in every aspect of life. We're looking for a Senior Manager of Governance, Risk, and Compliance (GRC) who is ready to take charge and lead our GRC program as we continue to grow in the exciting health tech field here in Boston, MA. This role is pivotal as it entails both strategic planning and hands-on execution, meaning you'll be the driving force behind building our GRC framework from the ground up. You'll collaborate with a variety of teams, including Legal and Security, to ensure we're not just compliant but also ahead of possible risks. Your responsibilities will include designing robust risk management strategies, steering our third-party vendor assessments, and managing the enterprise risk register, ensuring visibility and executive-level reporting on all key risks. As the Senior Manager, your leadership will guide the development of policies and training programs that promote compliance and security awareness. Plus, by embracing innovative tools to enhance our GRC practices, you'll cultivate an environment of transparency and accountability. If you're passionate about process-driven governance and have the experience to match, then we want you to join our dynamic team, helping to shape the future of WHOOP and contribute to our mission of human performance enhancement. Don't worry if you don't check every box on the qualifications list; we value potential and diverse experiences as much as technical skills!

Frequently Asked Questions (FAQs) for Senior Manager, Governance, Risk, & Compliance (GRC) Role at WHOOP
What are the main responsibilities of a Senior Manager, Governance, Risk, & Compliance at WHOOP?

The Senior Manager of Governance, Risk, and Compliance at WHOOP is responsible for leading the design and execution of the GRC program, including the development of risk management strategies, managing the enterprise risk register, and overseeing vendor risk assessments. This position also requires collaboration with multiple teams to ensure compliance with global regulations such as GDPR and SOC2, as well as developing policies and training programs that build security awareness within the organization.

Join Rise to see the full answer
What qualifications are needed to apply for the Senior Manager GRC position at WHOOP?

Candidates interested in the Senior Manager, Governance, Risk, and Compliance role at WHOOP should have a minimum of 6 years of relevant experience in GRC, information security, or compliance areas, especially in health tech or regulated environments. A strong understanding of standards like ISO 27001 and SOC2 is essential, along with experience managing risk registers and third-party risk management. Relevant certifications such as CISA or CISSP are beneficial but not mandatory.

Join Rise to see the full answer
How does WHOOP support personal growth for the Senior Manager of GRC?

WHOOP is committed to the personal and professional development of its employees, including the Senior Manager of Governance, Risk, and Compliance. This role involves mentoring GRC analysts and offers opportunities to lead critical projects directly. Moreover, WHOOP values diverse experiences and encourages continuous learning, making it a dynamic environment for growth and career advancement.

Join Rise to see the full answer
What skills are essential for success in the Senior Manager GRC role at WHOOP?

Successful candidates for the Senior Manager, Governance, Risk, and Compliance position at WHOOP should possess strong organizational skills, detail orientation, and the ability to juggle priorities in a fast-paced environment. Familiarity with compliance frameworks and experience in leading risk management functions are crucial. Additionally, a commitment to leveraging AI tools for enhancing processes is highly valued.

Join Rise to see the full answer
What tools and processes will the Senior Manager of GRC be expected to implement at WHOOP?

In the Senior Manager, Governance, Risk, and Compliance role at WHOOP, you will need to identify and implement various GRC tools and processes that enhance transparency, accountability, and scalability within the program. This includes developing metrics for performance reporting and supporting incident response processes to ensure that all standards and regulatory requirements are successfully met.

Join Rise to see the full answer
Common Interview Questions for Senior Manager, Governance, Risk, & Compliance (GRC)
Can you explain your experience with regulatory compliance frameworks like GDPR and SOC2?

When discussing your experience with regulatory compliance frameworks like GDPR and SOC2, focus on specific projects you've managed, the challenges faced, and the outcomes achieved. Highlight your understanding of the regulations’ implications on operational practices and how you've implemented changes to ensure compliance. Providing quantifiable results can greatly enhance your response.

Join Rise to see the full answer
How do you prioritize and manage risks in a comprehensive risk register?

In your response, emphasize a structured approach to risk management, such as the strategies you utilize to assess, evaluate, and prioritize risks. Discuss your experience with risk matrix frameworks, and how you communicate these risks to stakeholders. Sharing a specific example where your prioritization led to tangible improvements will strengthen your answer.

Join Rise to see the full answer
Describe a time when you successfully led a vendor risk assessment. What was your approach?

When answering this question, consider providing a real-world example that illustrates your process for conducting a vendor risk assessment. Detail how you interacted with stakeholders, what criteria you evaluated, and the challenges you faced. Emphasize your analytical skills and attention to detail, as well as how you implemented your findings.

Join Rise to see the full answer
What strategies do you use to develop effective compliance training programs?

Discuss your method for creating compliance training programs, emphasizing the importance of aligning content with organizational goals and compliance requirements. Describe how you gather input from various teams to ensure relevance and effectiveness. Sharing successful outcomes, like increased compliance awareness, will enhance your response.

Join Rise to see the full answer
How do you handle internal audits and assessments?

Explain your systematic approach to managing internal audits, including how you prepare for them and how you engage with auditors. Highlight any experience you have with managing evidence workflows and mitigating findings. A specific anecdote demonstrating your successful management of an audit process will showcase your capabilities.

Join Rise to see the full answer
In your view, how does AI impact governance, risk, and compliance processes?

Share your perspective on the role of AI in enhancing GRC processes, such as automating risk assessments or improving incident response efficiency. Discuss any relevant experiences where you’ve used AI tools or data analytics to streamline workflows and improve compliance tracking, showing that you are both forward-thinking and knowledgeable in this area.

Join Rise to see the full answer
What metrics do you believe are crucial for measuring the effectiveness of a GRC program?

When asked about GRC metrics, mention critical indicators such as incident response time, compliance training completion rates, and the frequency of risk assessment updates. Discuss why these metrics matter and how they inform program adjustments. Providing an example of how you successfully tracked and reported on GRC metrics will add weight to your answer.

Join Rise to see the full answer
Can you describe your experience in managing teams and programs in high-growth environments?

In your answer, focus on specific leadership experiences and how you adapted your management style to fit a rapidly evolving landscape. Discuss strategies you’ve implemented to foster team growth and skill development while ensuring program scalability. Highlight the positive impact your leadership had on team dynamics and program success.

Join Rise to see the full answer
What are your strategies for maintaining compliance in a fast-paced technology environment?

Outline your proactive approach to staying compliant in a quickly changing tech environment. Emphasize the importance of continuous learning about regulations and emerging threats, as well as building strong interdepartmental relationships. Specific examples of how you've adjusted compliance practices in light of technology advancements will strengthen your response.

Join Rise to see the full answer
How do you integrate feedback and lessons learned into GRC programs?

Discuss the significance of feedback loops in GRC programs, and outline your approach to gathering and incorporating feedback after incidents, audits, or assessments. Highlight how this practice improves resilience and strengthens compliance efforts. Sharing specific instances of changes made based on lessons learned can effectively illustrate your process.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User

Join WHOOP as a Senior Business Analyst focusing on Quality & Reliability to drive hardware improvements through data analysis.

Photo of the Rise User
Posted 3 days ago

As a Staff Electrical Engineer at WHOOP, you'll drive the architecture and design of innovative products that enhance human performance.

Photo of the Rise User
Posted 9 days ago

Join PwC Gibraltar as a Compliance Senior Associate to enhance KYC processes and ensure regulatory compliance.

Photo of the Rise User

Join Wintermute as a Senior Counsel to advance its regulatory strategies in the dynamic field of digital assets.

Photo of the Rise User
DLA Piper Remote Boston, Massachusetts, United States
Posted 13 days ago
Photo of the Rise User
Posted 10 days ago

Albany Medical Center is looking for a VP Compliance with a strong healthcare regulatory background.

Photo of the Rise User
Posted 11 days ago

Great Minds seeks a Senior Counsel - Employment to provide legal counsel on employment matters and ensure compliance with labor laws.

Photo of the Rise User

Emory Healthcare is looking for a seasoned Compliance & Privacy Partner to lead compliance operations and navigate healthcare regulations effectively.

Join Sul Lee Law Firm as a Bilingual Business Transaction Associate Attorney, where your skills in business law will flourish within a supportive and collaborative environment.

Posted 8 days ago

Join ALSAC as a Summer 2025 Intern in Legal to support their mission of raising funds for St. Jude Children's Research Hospital.

Our mission at WHOOP is to unlock human performance. We believe that every individual has an inner potential that can be enhanced through continuous monitoring. As such we've built a system across hardware, software, and analytics designed to coll...

131 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
April 4, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Dayton just viewed Sr. Logistics Analyst at Innio
Photo of the Rise User
Someone from OH, Cincinnati just viewed Forensic Nurse Examiner-Prn Shift Varies at TriHealth
Photo of the Rise User
Someone from OH, New Albany just viewed Junior Buyer at CSC Generation
Photo of the Rise User
Someone from OH, Columbus just viewed Financial Administrator Intern at Finalsite
F
Someone from OH, Columbus just viewed Part Time Support Lead at Five Below
Photo of the Rise User
Someone from OH, North Olmsted just viewed Art Director - Creative- KY at Photon
Photo of the Rise User
11 people applied to Compliance, Associate at iCapital
Photo of the Rise User
Someone from OH, Cleveland just viewed Account Executive, Army SOF/COCOMs at Pure Storage
Photo of the Rise User
Someone from OH, Kent just viewed IT Compliance Analyst I at Fidelity National Financial
Photo of the Rise User
Someone from OH, Dayton just viewed Music Production / Creative Intern at Landor
Photo of the Rise User
Someone from OH, Cleveland just viewed Double Remote Assistant (Central US) at Zirtual
S
Someone from OH, Cincinnati just viewed Product Manager - Remote at Substance
Photo of the Rise User
26 people applied to Immigration Paralegal | US at Deel
Photo of the Rise User
Someone from OH, Mason just viewed IT General Controls Tester at ING
Photo of the Rise User
Someone from OH, Columbus just viewed Contact Center Representative - 4882 at Advantmed
A
Someone from OH, Columbus just viewed Lead Scientist at ATCC