bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesWhoopGRC Analyst, Operations & Risk

GRC Analyst, Operations & Risk

Whoop · Boston, MA · On Site · Active · $70,000–$110,000 / year · Lever

Job facts

FieldValue
CompanyWhoop
TitleGRC Analyst, Operations & Risk
Normalized title-
Department / teamInformation Security
LocationBoston, MA, United States
Work modelOn Site
Employment type-
Salary$70,000–$110,000 / year
Statusactive
ATS providerLever
Posted / first seen2026-05-11 / 2026-05-29
Changed / last seen2026-06-03 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Whoop.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Lever.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in Boston.Open
Work model jobsActive On Site postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyWhoop
Sourceecc909db-1586-4810-ade6-cdf769612277
ATS providerLever

Description

As a GRC Analyst, you will support the WHOOP Governance, Risk, and Compliance program. You will help manage risk reviews, operational requests, and cross-functional security compliance workflows. Success in this role requires strong attention to detail, responsiveness and accountability through completion in a fast-paced environment. A key focus of this role will be helping ensure GRC work is reviewed, prioritized, routed, tracked, and completed effectively. You will use intake and ticketing data to identify workflow trends, recurring questions, handoff gaps, and opportunities to improve guidance, templates, reporting, automation, and stakeholder experience. You will also support broader GRC initiatives, including compliance calendar activities, control monitoring, process documentation, security awareness coordination, and continuous improvement across the GRC program. This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office. Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply. WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values. At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company’s long-term growth and success. The U.S. base salary range for this full-time position is $70,000 - $110,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training. In addition to the base salary, the successful candidate will also receive benefits and a generous equity package. These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate’s specific qualifications, expertise, and alignment with the role’s requirements. RESPONSIBILITIES: Support day-to-day GRC program operations – manage and triage GRC intakes and accurate tracking through resolution Perform and support third-party risk management activities, including vendor reviews, reassessments, partner coordination, remediation tracking, and cross-functional follow-up with Security, Legal, Privacy, Procurement, IT, Finance, and business owners Assist with risk program management activities Support security compliance monitoring and audit readiness activities, managing audit request lists and taking ownership of gathering security audit evidence to verify compliance with internal policies / regulations and industry best practices Coordinate security awareness and training program management activities QUALIFICATIONS: 2+ years of experience in GRC, third-party risk management, security compliance, internal audit, risk management, or a related function Deep understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls – ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS Possess a strong risk mindset, exceptional attention to detail, and the ability to apply critical thinking when assessing complex issues and control gaps Highly organized and strong operational discipline ensuring clear and expedient escalations with informed recommendations to management Superior interpersonal and communication skills – verbal and written Being a team player and working to achieve common goal in a dynamic setting Strong commitment to embracing and leveraging AI tools in day-to-day tasks, ensuring AI-assisted work aligns with the same high-quality standards as personal contributions. A minimum bachelor’s degree in any discipline. Computer science, cyber security and risk or technology degrees preferred. CISA or CRISC certification preferred

Full job record

Job IDe04c128872888334cd1a5a744f14580ff433bed0
Org ID81b7662b-beb5-42b7-a56b-1a3be62744eb
Source IDecc909db-1586-4810-ade6-cdf769612277
Board IDecc909db-1586-4810-ade6-cdf769612277
Providerlever
Provider Job Key3c091499-3208-4bf7-8ed7-44c463cc05ce
TitleGRC Analyst, Operations & Risk
Normalized Title
Statusactive
Activeyes
Location TextBoston, MA
Department
TeamInformation Security
Employment Type
Workplace Typeon_site
Remote Policy
CountryUnited States
RegionMA
CityBoston
Salary Rawsalary range for this full-time position is $70,000 - $110,000. Salary ranges are determined by role, level, and location
Salary Min70,000
Salary Max110,000
Salary CurrencyUSD
Salary Periodyear
Source URLhttps://jobs.lever.co/whoop/3c091499-3208-4bf7-8ed7-44c463cc05ce
Apply URLhttps://jobs.lever.co/whoop/3c091499-3208-4bf7-8ed7-44c463cc05ce/apply
First Seen At2026-05-29 07:01:38Z
Last Seen At2026-06-06 07:57:37Z
Last Checked At2026-06-06 07:57:37Z
Last Changed At2026-06-03 12:34:19Z
Inactive At
Source Posted At2026-05-11 13:55:26Z
Source Updated At
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=lever/board=whoop/date=2026-06-06/2026-06-06T07-57-37-112Z-3a62ae598fc582af875adf7026536e582b340245001f88e50ac54fd067359829.json
Event Fields
{
  "content_hash": "7c2e2d92a245c5503c4d0f592a7e7232d2c81fa7785fde933a0dfaf469e0c481",
  "source_hash": "c9ef89fb95073c9ef3af77d583974abd5ed2e4f8a0e63aec811c145f6d8fb48e",
  "last_changed_at": "2026-06-03T12:34:19.380Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Boston, MA",
    "city": "Boston",
    "region": "MA",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.9
  },
  "salary_max": 110000,
  "salary_min": 70000,
  "inferred_at": "2026-06-06T07:57:37.686Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "Boston, MA",
      "city": "Boston",
      "region": "MA",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.9
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": null,
  "salary_period": "year",
  "workplace_type": "on_site",
  "salary_currency": "USD"
}
Extensions
{}
Native Structured
{
  "lists": [
    {
      "text": "RESPONSIBILITIES:",
      "content": "<div>\n\n<li>\n<p>Support day-to-day GRC program operations – manage and triage GRC intakes and accurate tracking through resolution</p>\n</li>\n<li>\n<p>Perform and support third-party risk management activities, including vendor reviews, reassessments, partner coordination, remediation tracking, and cross-functional follow-up with Security, Legal, Privacy, Procurement, IT, Finance, and business owners</p>\n</li>\n<li>\n<p>Assist with risk program management activities</p>\n</li>\n<li>\n<p>Support security compliance monitoring and audit readiness activities, managing audit request lists and taking ownership of gathering security audit evidence to verify compliance with internal policies / regulations and industry best practices</p>\n</li>\n<li>\n<p>Coordinate security awareness and training program management activities</p>\n</li>\n\n</div>"
    },
    {
      "text": "QUALIFICATIONS:",
      "content": "<div>\n\n<li>\n<p>2+ years of experience in GRC, third-party risk management, security compliance, internal audit, risk management, or a related function</p>\n</li>\n<li>\n<p>Deep understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls – ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS</p>\n</li>\n<li>\n<p>Possess a strong risk mindset, exceptional attention to detail, and the ability to apply critical thinking when assessing complex issues and control gaps</p>\n</li>\n<li>\n<p>Highly organized and strong operational discipline ensuring clear and expedient escalations with informed recommendations to management</p>\n</li>\n<li>\n<p>Superior interpersonal and communication skills – verbal and written</p>\n</li>\n<li>\n<p>Being a team player and working to achieve common goal in a dynamic setting</p>\n</li>\n<li>\n<p>Strong commitment to embracing and leveraging AI tools in day-to-day tasks, ensuring AI-assisted work aligns with the same high-quality standards as personal contributions.</p>\n</li>\n<li>\n<p>A minimum bachelor’s degree in any discipline. Computer science, cyber security and risk or technology degrees preferred. CISA or CRISC certification preferred</p>\n</li>\n\n</div>"
    }
  ],
  "country": "US",
  "createdAt": 1778507726517,
  "updatedAt": null,
  "categories": {
    "team": "Information Security",
    "location": "Boston, MA",
    "allLocations": [
      "Boston, MA"
    ]
  },
  "salaryRange": null,
  "workplaceType": "onsite"
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/e04c128872888334cd1a5a744f14580ff433bed0?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/81b7662b-beb5-42b7-a56b-1a3be62744ebJSON
GET https://api.bluedoor.sh/job-postings/v1/sources/ecc909db-1586-4810-ade6-cdf769612277JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/e04c128872888334cd1a5a744f14580ff433bed0/eventsJSON