GRC Analyst II
WHOOP
Job Overview
Who's the hiring manager?
Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Job Description
About WHOOP
At WHOOP, we're on a mission to unlock human performance and healthspan. WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives.
As a GRC Analyst II, you will play a crucial role in supporting the development, implementation, and maintenance of our Governance, Risk, and Compliance (GRC) program. Working under the guidance of the GRC Senior Manager, you will assist in various activities, including policy development, risk assessments, compliance framework implementation and monitoring, and audit coordination. Step into a role that empowers you to build a well-rounded foundation in GRC, explore multiple facets of the field, and sharpen your skills in specialized areas such as risk management or standards program management. Your sharp eye for detail and strong analytical mindset will play a pivotal role in strengthening our security and compliance initiatives.
Responsibilities for GRC Analyst II
- Assist in the development and implementation of GRC standards, frameworks and regulations (SOC2, ISO 27001, NIST Cybersecurity Framework, HIPAA, PCI DSS, etc.) to support business objectives, aligned with industry best practices and regulatory requirements.
- Assist in conducting risk assessments, supporting the development and adherence of risk mitigation strategies, and maintaining the risk register.
- Support ongoing compliance monitoring activities to ensure adherence to internal policies, relevant regulations, standards, and contractual obligations.
- Assist in evaluating and managing risks associated with third-party vendors and service providers through vendor risk assessment processes.
- Provide support in incident response activities, including documentation, coordination, and post-incident analysis as directed.
- Assist in the development and delivery of security awareness and training programs to educate employees on security policies, procedures, and best practices.
- Support audit activities by gathering evidence, conducting preliminary assessments, and assisting in the remediation of audit findings.
- Manage and resolve GRC support tickets promptly and efficiently.
- Participate in the review, development, and maintenance of security policies, standards, and procedures to ensure compliance with regulatory mandates and industry standards.
- Maintain and update GRC standard operating procedures to ensure consistency and efficiency.
- Identify areas for process improvement within the GRC program and assist in implementing enhancements to improve effectiveness and efficiency.
- Work cross-functionally with IT, Engineering, Legal, HR, and other stakeholders to document and validate compliance controls and support their implementation within the GRC platform.
- Leverage AI and automation tools to enhance compliance monitoring, reporting, evidence collection, and risk analysis.
Qualifications
- Bachelor's degree in Information Security, Computer Science, or related field.
- Compliance and security certifications (e.g., CompTIA Security+, CISSP, CISA, CISM, CRISC, other GRC certifications) a plus.
- Minimum of 3 years demonstrated experience in GRC is mandatory.
- Strong understanding of GRC concepts, principles, and practices.
- Familiarity with using and or administrating GRC tools is a plus.
- Demonstrated familiarity with relevant regulations, standards, and frameworks is required (e.g., GDPR, SOC2, ISO 27001, NIST Cybersecurity Framework, PCI DSS, HIPAA).
- Prior healthcare compliance experience and knowledge of HIPAA and or HITRUST is a plus.
- Excellent analytical and problem-solving skills with attention to detail.
- Effective communication and interpersonal skills, with the ability to establish relationships and collaborate with cross-functional teams.
- Detail-oriented with superior organizational and time-management skills - balancing multiple projects, deadlines, and requests.
- Proven ability to navigate ambiguity and complexity, turning uncertainty into clarity and actionable insights.
- Driven with a pro-active and results-oriented approach, demonstrating a can-do attitude and determination to succeed.
- Familiarity with Jira or other project management tools for organizing and managing daily work and projects is preferred.
Key skills/competency
- GRC program management
- Risk assessment
- Compliance monitoring
- Policy development
- Security awareness training
- Audit coordination
- Incident response support
- Vendor risk management
- NIST Cybersecurity Framework
- HIPAA
How to Get Hired at WHOOP
- Research WHOOP's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor to understand their health and performance focus.
- Customize your GRC Analyst II resume: Highlight 3+ years of GRC experience, strong analytical skills, and familiarity with frameworks like SOC2, ISO 27001, and HIPAA.
- Prepare for technical GRC questions: Be ready to discuss risk assessment methodologies, compliance frameworks, and incident response procedures specific to WHOOP's domain.
- Showcase problem-solving skills: During interviews, provide concrete examples of how you've navigated ambiguity, improved processes, or resolved compliance challenges.
- Demonstrate cross-functional collaboration: Emphasize your ability to work effectively with IT, Engineering, Legal, and HR on GRC initiatives at WHOOP.
Frequently Asked Questions
Find answers to common questions about this job opportunity
Explore similar opportunities that match your background