--- title: 'Manager, Governance Risk & Compliance (GRC) at Whoop' canonical: 'https://feeny.ai/job/manager-governance-risk-compliance-grc-whoop-boston-dd393qqsb2jy' type: 'job' last_seen: '2026-09-09' --- # Manager, Governance Risk & Compliance (GRC) at Whoop - **Company:** [Whoop](https://feeny.ai/companies/whoop) - **Location:** Boston, MA - **Employment:** full-time - **Work type:** onsite - **Posted:** 2026-09-08 - **Last confirmed live:** 2026-09-09 - **Apply:** https://jobs.ashbyhq.com/whoop/79fdf147-0d79-4ca1-8ce6-374df98179e3 ## Job description At WHOOP, we're on a mission to unlock human performance. WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives. As a Manager of Governance, Risk, and Compliance you will lead the day-to-day execution and support the ongoing operation of the GRC program in a fast-paced, high-growth environment. This role is responsible for hands-on execution of GRC initiatives, collaborating across Legal, Security, Product, and other teams to advance compliance objectives, reduce enterprise risk exposure, and strengthen operational resilience. ## RESPONSIBILITIES - Lead the day-to-day operations of the GRC function, ensuring timely execution of governance, risk, compliance, third-party risk, and secure development lifecycle (SSDLC) assessment activities. - Lead enterprise risk reviews by driving GRC intake and request triage, personally overseeing complex assessments while prioritizing and delegating work across the team. - Perform and lead the third-party risk management lifecycle by conducting and overseeing vendor risk assessments and due diligence in partnership with Legal, IT, and Security. - Manage team workload and capacity by assigning, tracking, and escalating requests as needed to ensure consistent delivery, quality, and stakeholder satisfaction. - Develop and report operational metrics and KPIs, providing weekly dashboards and status updates to GRC leadership. - Contribute directly to governance activities, including policy management, control assessments, evidence collection, audit support, and continuous compliance initiatives. - Maintain the enterprise risk register by documenting, tracking, escalating, and reporting technology, cybersecurity, privacy, and third-party risks - Support security incident response activities by coordinating compliance-related obligations, regulatory documentation, and risk remediation tracking. ## QUALIFICATIONS - 8+ years of experience in GRC, information security, cybersecurity; with 2+ years of experience leading or managing GRC, information security, or audit professionals. - Demonstrated experience leading operational GRC programs, including intake management, workload prioritization, KPI reporting, and cross-functional coordination. - Extensive hands-on experience performing third-party/vendor risk assessments, security reviews, due diligence, and risk-based decision support. - Strong knowledge of SSDLC risk assessments and application security governance processes. - Deep knowledge of security and privacy frameworks and regulations, including ISO 27001, SOC 2, NIST CSF, HIPAA, GDPR, PCI DSS, and modern cybersecurity risk management practices. - Excellent written and verbal communication skills, with the ability to communicate effectively with technical teams, business stakeholders, auditors, and executive leadership - A minimum bachelor’s degree in any discipline. Computer science, cybersecurity, and risk or technology degrees preferred. ## BONUS QUALIFICATIONS - Professional certifications such as CISSP, CRISC, CISA, ISO 27001 Lead Auditor, or HITRUST CCSFP. - Demonstrated success in program and project management skills with the ability to manage multiple concurrent workstreams in a fast-paced environment. - Exceptional organizational, analytical, and problem-solving skills. - Background in establishing SSDLC guardrails. ## ABOUT YOU - You are a risk focused GRC leader with ability to assess security risks and translate it into business impact. - You have the ability to assess a risk impact in terms of business trade-offs. - You are passionate about building scalable GRC programs that have a lasting impact in improving the overall security posture of an organization without slowing the speed of innovation. This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office. Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply. WHOOP is an Equal Opportunity Employer and participates in E-verify https://www.e-verify.gov/to determine employment eligibility. The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values. At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company’s long-term growth and success. The U.S. base salary range for this full-time position is $155,000-$195,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training. In addition to the base salary, the successful candidate will also receive benefits and a generous equity package. These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate’s specific qualifications, expertise, and alignment with the role’s requirements. ## About Whoop ## Company Overview - **One-liner**: WHOOP is a human performance optimization platform that uses a wearable device and 24/7 monitoring to help members improve sleep, strain, recovery, and overall health. - **Entity Type**: Private (funding stage not publicly available in provided sources) - **Headquarters**: Boston, Massachusetts, USA - **Founded**: 2012 - **Founders**: Will Ahmed ## Core Business - **Primary industry**: Wearable health technology, human performance optimization - **Target customers**: B2C (consumers, athletes) and B2B (professional sports teams, organizations) - **Mission**: “To unlock human performance and Healthspan.” [whoop.com - About](https://www.whoop.com/us/en/about/) ## Products & Services - **WHOOP 5.0 + Subscription**: A non-screen wrist-worn wearable with 14+ day battery life that continuously monitors sleep, strain, recovery, heart rate, heart rate variability, and 65+ biomarkers. The platform provides personalized coaching, blood pressure insights, women’s hormonal insights, VO₂ max, heart rate zones, and mental health tracking. Type: Hardware + SaaS subscription. [whoop.com - Homepage](https://www.whoop.com/us/en/) ## Market Standing - **Valuation/Market Cap**: Not publicly available from provided sources - **Key Metric**: Not publicly available (annual revenue not disclosed); estimated headcount of 500 employees [Built In Boston](https://www.builtinboston.com/company/whoop) - **Notable Investors/Partners**: Not disclosed in provided sources - **Growth Signals**: 500 total employees; hybrid workspace (4 days on-site per week); actively hiring across Engineering, AI/ML, Data & Analytics, Product, and Design; only 0.13% of applicants are hired, indicating high selectivity and strong talent demand. [whoop.com - Careers](https://www.whoop.com/us/en/careers/) | [Built In Boston](https://www.builtinboston.com/company/whoop) ## Competitive Advantages - Proprietary 24/7 physiological monitoring with advanced sensor technology and an ultra-long battery life (14+ days) - Deep scientific foundation – founded after reviewing over 500 medical papers - Personalized coaching and insight delivery based on individual biometric data - Strong brand recognition among elite athletes and mainstream consumers - Privacy-first design with encrypted data storage [whoop.com - Homepage](https://www.whoop.com/us/en/) ## Strategic Focus - Expanding health insights: introducing blood pressure monitoring, women’s hormonal health features, and heart health tracking - Enhancing AI/ML capabilities (evident from many open AI/ML roles) [jobs.lever.co](https://jobs.lever.co/whoop) - Deepening enterprise/B2B partnerships with sports organizations and research institutions - Continuing to build out Healthspan and longevity features ## Why Work Here - **Hybrid workspace** – employees are on-site 4 days a week in Boston’s “best office” [whoop.com - Careers](https://www.whoop.com/us/en/careers/) - **Benefits** – flexible time off, above-market compensation, paid parental leave, health support [whoop.com - Careers](https://www.whoop.com/us/en/careers/) - **Employee Resource Groups** – ADAPT (disability inclusion), BLACK@WHOOP, LGBTQ+ (WHOOP GOOP), Veterans and Military Personnel, Women of WHOOP, Women in Science and Engineering, WHOOP Parents [whoop.com - Careers](https://www.whoop.com/us/en/careers/) - **High selectivity** – only 0.13% of applicants are hired, reflecting a rigorous, standards-driven culture [whoop.com - Careers](https://www.whoop.com/us/en/careers/) - **Equal Opportunity Employer** – committed to diversity and inclusion in all employment decisions [whoop.com - Careers](https://www.whoop.com/us/en/careers/) ## Sources 1. [whoop.com - Careers](https://www.whoop.com/us/en/careers/) 2. [whoop.com - About](https://www.whoop.com/us/en/about/) 3. [whoop.com - Homepage](https://www.whoop.com/us/en/) 4. [Built In Boston - WHOOP Office Profile](https://www.builtinboston.com/company/whoop) 5. [jobs.lever.co - WHOOP Job Listings](https://jobs.lever.co/whoop) ## Other roles at Whoop - [Senior Manager: Governance, Risk, & Compliance (GRC)](https://feeny.ai/job/senior-manager-governance-risk-compliance-grc-whoop-boston-9s2qk0pm8c6r) — Boston, MA - [Manager, Immigration & Global Mobility](https://feeny.ai/job/manager-immigration-global-mobility-whoop-boston-cs3md62x0hqe) — Boston, MA - [Director, Data Governance](https://feeny.ai/job/director-data-governance-whoop-boston-e4dt7r9pnbrq) — Boston, MA - [Director, Enablement- Membership Services](https://feeny.ai/job/director-enablement-membership-services-whoop-boston-7tjnj7311jfc) — Boston, MA - [Senior Product Manager, Sensing](https://feeny.ai/job/senior-product-manager-sensing-whoop-boston-74033x64kasj) — Boston, MA - [Lead, Lifecycle Marketing Automation](https://feeny.ai/job/lead-lifecycle-marketing-automation-whoop-boston-ddez605e4h54) — Boston, MA - [Staff Android Engineer, Connectivity](https://feeny.ai/job/staff-android-engineer-connectivity-whoop-boston-ay35t4j5nmfm) — Boston, MA - [Vice President, Hardware Quality](https://feeny.ai/job/vice-president-hardware-quality-whoop-boston-qn8ptdmh7m06) — Boston, MA - [Systems Engineer, Endpoint](https://feeny.ai/job/systems-engineer-endpoint-whoop-boston-6qjr7t75xvz8) — Boston, MA - [Director, Security Engineering & Operations](https://feeny.ai/job/director-security-engineering-operations-whoop-boston-ds145x8s86db) — Boston, MA