Information Security
At WHOOP, we're on a mission to unlock human performance. WHOOP empowers
members to perform at a higher level through a deeper understanding of their bodies
and daily lives.
As a Manager of Governance, Risk, and Compliance you will lead the day-to-day
execution and support the ongoing operation of the GRC program in a fast-paced,
high-growth environment. This role is responsible for hands-on execution of GRC
initiatives, collaborating across Legal, Security, Product, and other teams to advance
compliance objectives, reduce enterprise risk exposure, and strengthen operational
resilience.
RESPONSIBILITIES
- Lead the day-to-day operations of the GRC function, ensuring timely execution of governance, risk, compliance, third-party risk, and secure development lifecycle (SSDLC) assessment activities.
- Lead enterprise risk reviews by driving GRC intake and request triage, personally overseeing complex assessments while prioritizing and delegating work across the team.
- Perform and lead the third-party risk management lifecycle by conducting and overseeing vendor risk assessments and due diligence in partnership with Legal, IT, and Security.
- Manage team workload and capacity by assigning, tracking, and escalating requests as needed to ensure consistent delivery, quality, and stakeholder satisfaction.
- Develop and report operational metrics and KPIs, providing weekly dashboards and status updates to GRC leadership.
- Contribute directly to governance activities, including policy management, control assessments, evidence collection, audit support, and cont