GRC Analyst - Third Party Risk
Job description
About the role
This position operates within the WHOOP Governance, Risk, and Compliance program to manage third-party vendor risk. The role focuses on intake and ticket data analysis, process tracking, and coordination across security and business functions. Success depends on meticulous attention to detail and consistent follow-through in a fast-paced environment. The hire will own the daily execution of third-party risk workflows and act as a central point of contact for cross-functional stakeholders. They will translate complex risk findings into clear, actionable insights for non-technical audiences. This role requires a proactive mindset to identify gaps and drive remediation without direct oversight. The candidate will serve as a critical connector between Security, Legal, Privacy, and business teams to ensure risk management remains integrated and efficient.
Key facts
What you'll do
- Review, prioritize, route, track, and complete third-party vendor assessment requests using established criteria.
- Analyze intake and ticketing data to identify workflow trends, recurring questions, and handoff gaps between teams.
- Guide improvements to guidance, templates, reporting, and automation to enhance the stakeholder experience and reduce manual effort.
- Support day-to-day management of vendor risk assessments, ensuring accurate tracking from initial intake through final resolution.
- Perform vendor risk reviews, conduct reassessments, coordinate with partners, and track remediation progress against timelines.
- Follow up across cross-functional teams including Security, Legal, Privacy, Procurement, IT, Finance, and business owners to close open items.
- Assist with broader third-party risk program management activities as required, including documentation and process updates.
- Maintain accurate records and ensure alignment with established processes, policies, and regulatory expectations.
- Confirm that vendors understand and adhere to required standards, controls, and contractual obligations.
- Escalate high-risk scenarios and emerging issues to leadership with recommended courses of action and impact analysis.
- Contribute to the continuous monitoring of the vendor ecosystem to detect potential compliance or control weaknesses.
- Support special projects related to third-party risk initiatives, assessments, and audits on an as-needed basis.
- Synthesize data from multiple sources to produce summaries that inform decision-making and process optimization.
- Promote a culture of risk awareness by collaborating with stakeholders to improve controls and vendor due diligence.
Requirements
You bring two or more years of GRC experience, with preference for third-party risk management background. You understand Cybersecurity compliance frameworks such as ISO 27001, NIST CSF, COSO, SOC 2, and PDI-DSS. You stay organized and manage clear, expedient escalations with informed recommendations for leadership. You work effectively as a team member in a dynamic setting. A minimum bachelor's degree in any discipline is required. Degrees in computer science, cyber security, risk, or technology are preferred. You are comfortable working in a fast-paced environment where priorities can shift quickly and demands are high. Strong written and verbal communication skills are essential for interacting with internal stakeholders and vendors. You demonstrate ownership of tasks and follow-through to ensure that deadlines are met and expectations are exceeded. Attention to detail is critical, as the role involves managing sensitive risk data and vendor information. You must be legally authorized to work in the United States and not require work authorization sponsorship from Whoop for this position at this time.
Practical notes
This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of Boston, MA.
Interested in the role, but do not meet every qualification? WHOOP encourages applications from all candidates. The organization values character alongside experience and is committed to building a diverse and inclusive environment.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility.
Compensation and benefits
The U.S. base salary range for this full-time position is $70,000 - $110,000. Salary ranges are determined by role, level, and location. Individual pay is based on job-related skills, experience, performance, and relevant education or training.
In addition to the base salary, the successful candidate will receive benefits and a generous equity package. Equity aligns employees with the Whoop long-term success of the company and allows corporate team members to share in growth and success.
These ranges may be updated in the future to reflect evolving market conditions and organizational needs. While most offers will fall toward the start of the range, total compensation depends on the candidate's specific qualifications and role alignment.