Full-Time

GRC Manager

Posted on 8/28/2024

Whoop

Whoop

501-1,000 employees

Wearable fitness tracker with personalized insights

Data & Analytics
Healthcare

Senior

Boston, MA, USA

Position requires onsite presence in Boston, MA.

Category
Risk & Compliance
Legal & Compliance
Requirements
  • Degree in Information Security, Computer Science, or related field; Master's degree preferred or industry-recognized certifications such as CISSP, CISM, CISA CRISC, or equivalent.
  • Minimum of 5 years of experience in information security, risk management, audit, or compliance roles.
  • Strong understanding of relevant regulations, standards, and frameworks (e.g., GDPR, SOC2, ISO 27001, NIST Cybersecurity Framework, etc.).
  • Experience with global regulatory compliance and familiarity with regional data protection laws.
  • Excellent communication skills with the ability to effectively collaborate with cross-functional teams.
  • Proven track record of building and maturing GRC programs in complex, fast paced environments.
  • Strong analytical and problem-solving skills with attention to detail.
  • Detail-oriented with superior organizational and time-management skills - balancing multiple projects, deadlines, and requests.
  • Driven with a can-do attitude and determination to succeed.
Responsibilities
  • Develop and Implement GRC Framework: Design, implement, and maintain an effective GRC framework aligned with industry best practices and regulatory requirements, including ISO 27001 and GDPR. Apply standards-based best practices to ensure the security program meets organizational needs.
  • Policy Development and Management: Develop, review, and update security policies, standards, and procedures in collaboration with relevant stakeholders to ensure global regulatory compliance. Communicate effectively about our policies and practices to internal and external stakeholders.
  • Risk Assessment and Management: Conduct risk assessments, maintain the risk register, and provide appropriate reporting to Executive leadership. Track and keep abreast of emerging risks, threats, legal and regulatory changes, and other developments in the security field.
  • Compliance Monitoring: Monitor and ensure compliance with internal policies, relevant regulations, standards, and contractual obligations (e.g., GDPR, ISO 27001) across global operations.
  • Vendor Risk Management: Assess and manage risks associated with third-party vendors and service providers through effective vendor risk management processes.
  • Incident Response and Investigation: Develop and maintain an incident response plan, coordinate incident response activities, and conduct post-incident investigations as needed.
  • Security Awareness and Training: Develop and deliver security awareness and training programs to educate employees on security policies, procedures, and best practices.
  • Audit Coordination: Serve as the primary point of contact for internal and external audits, coordinate audit activities, and ensure timely remediation of audit findings.
  • Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs): Lead the execution of PIAs and DPIAs to ensure compliance with privacy regulations and organizational policies.
  • GRC Queue Management: Actively participate in the GRC support queue, responding to and resolving inquiries and requests in a timely manner, demonstrating a commitment to providing excellent service.
  • Team Expansion Planning: Develop strategies and plans for expanding the GRC team and tools to support the growth and maturity of the GRC program.
  • Continuous Improvement: Identify process improvements and tools to improve security posture. Identify areas for improvement within the GRC program and partners, implement enhancements, and drive continuous improvement initiatives.

WHOOP offers a fitness membership that focuses on improving personal health and performance through a wearable device called the WHOOP Strap 3.0. This device continuously collects physiological data, including heart rate, sleep patterns, and recovery levels, to provide users with personalized recommendations on their daily activity, sleep needs, and readiness for performance. Unlike many competitors, WHOOP operates on a subscription model, where users pay a fee to access the membership, which includes the device and continuous insights through the WHOOP app. This model not only provides a steady revenue stream but also fosters a strong community among users, encouraging engagement through teams, challenges, and social features. The goal of WHOOP is to help users optimize their health and performance while minimizing injury risk.

Company Stage

Series F

Total Funding

$393.7M

Headquarters

Boston, Massachusetts

Founded

2012

Growth & Insights
Headcount

6 month growth

-2%

1 year growth

-3%

2 year growth

-3%
Simplify Jobs

Simplify's Take

What believers are saying

  • WHOOP's partnership with Cristiano Ronaldo boosts brand visibility and credibility.
  • Expansion into 56 markets enhances WHOOP's global presence and growth potential.
  • Collaborations with brands like Assos strengthen WHOOP's position in sports technology.

What critics are saying

  • Increased competition from brands like Oura and Fitbit threatens market share.
  • Privacy concerns over data collection could lead to regulatory challenges.
  • Economic downturns may affect consumer willingness to pay subscription fees.

What makes Whoop unique

  • WHOOP offers 24/7 physiological data tracking with its WHOOP Strap 3.0.
  • The company provides personalized health insights for athletes and fitness enthusiasts.
  • WHOOP's subscription model includes a community aspect for user engagement.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Take Time Off: Time outside of the office is important for sleep, strain and recovery! Our PTO plan encourages members to take time off in order to come back refreshed.

Live a Healthy Lifestyle: Our competitive benefits package includes premium medical, dental, and vision coverage for employees and their dependents. Life and disability insurance are also available.

Feel Invested: In addition to a competitive base salary and 401k, you're eligible to receive stock options to share in the future of WHOOP. Work means more when you have personal stake. You have ownership in what we are building.

Eat Well: Keep hunger at bay with endless snacks in our fully stocked kitchen. Enjoy catered team lunches on Friday, and even a cold brew keg.

Know The Product: We want you to understand and experience the product firsthand. We offer you a WHOOP strap and membership at no cost.

Be Active: Take advantage of our office gym and on-site showers! WHOOP also offers a $500 yearly wellness perk for fitness classes and memberships.

Be Present: It’s important to be present when bringing home a new family member. Take care of your loved ones with 12 weeks paid parental leave, plus an additional 2 weeks to gradually return to work.

Love Where You Work: Sitting in the heart of Fenway, our beautiful office overlooks Fenway Park. A prime location for great food, not to mention catching a Sox game, too!

Work Hard, Play Harder: If we don't already have a club here that fits your lifestyle and interests, you're encouraged to start one. Share your passions with others at work, or discover new ones!

INACTIVE