Grc Analyst, Operations & Risk

Whoop Whoop · Consumer · Boston, MA · Information Security

This role supports the Governance, Risk, and Compliance (GRC) program by managing GRC intake, coordinating third-party risk activities, strengthening operational workflows, and improving visibility across risk and compliance work. It involves vendor risk reviews, remediation follow-up, audit readiness, compliance operations, and handling cross-functional GRC requests. The role also focuses on using intake and ticketing data to identify workflow trends and opportunities for improvement in guidance, templates, reporting, and automation. Additionally, it supports broader GRC initiatives like compliance calendar activities, control monitoring, process documentation, and security awareness coordination.

What you'd actually do

  1. support the WHOOP Governance, Risk, and Compliance program by helping manage GRC intake, coordinate third-party risk activities, strengthen operational workflows, and improve visibility across risk and compliance work
  2. support vendor risk reviews, remediation follow-up, audit readiness, compliance operations, and cross-functional GRC requests in a fast-paced environment
  3. help ensure GRC work is reviewed, prioritized, routed, tracked, and completed effectively
  4. use intake and ticketing data to identify workflow trends, recurring questions, handoff gaps, and opportunities to improve guidance, templates, reporting, automation, and stakeholder experience
  5. support broader GRC initiatives, including compliance calendar activities, control monitoring, process documentation, security awareness coordination, and continuous improvement across the GRC program

Skills

Required

  • Governance, Risk, and Compliance (GRC) program management
  • GRC intake management
  • Third-party risk management
  • Operational workflow strengthening
  • Vendor risk reviews
  • Remediation follow-up
  • Audit readiness
  • Compliance operations
  • Cross-functional GRC request handling
  • Intake and ticketing data analysis
  • Workflow trend identification
  • Process improvement
  • Guidance and template development
  • Reporting and automation
  • Stakeholder experience improvement
  • Compliance calendar management
  • Control monitoring
  • Process documentation
  • Security awareness coordination
  • Continuous improvement initiatives