WHOOP Logo

WHOOP

Director of Governance, Risk, & Compliance

Posted 4 Hours Ago
Be an Early Applicant
Easy Apply
Hybrid
Boston, MA
Senior level
Easy Apply
Hybrid
Boston, MA
Senior level
Lead and advance WHOOP's Governance, Risk & Compliance (GRC) program by defining and executing strategies aligned with business objectives while overseeing compliance and risk management across the organization.
The summary above was generated by AI

At WHOOP, we’re on a mission to unlock human performance and healthspan. Our wearable technology provides personalized insights that help millions of members better understand their bodies and make smarter decisions about training, recovery, and lifestyle.

We are seeking a Director of Governance, Risk & Compliance to lead and advance the WHOOP enterprise GRC program. Reporting to the CISO, you will define and execute the strategy for governance, risk management, and compliance across the organization, translating strategic priorities into scalable programs, controls, and measurable outcomes. 

This is a senior leadership role responsible for strengthening and expanding a world-class GRC function that enables WHOOP to move quickly while maintaining the highest standards of security, privacy, and regulatory compliance.

Responsibilities:

    • Define and execute the enterprise-wide GRC strategy in alignment with WHOOP business objectives, risk appetite, and evolving regulatory landscape, driving implementation across policies, processes, tooling, and metrics
    • Lead, grow, and mentor a high-performing GRC team, establishing clear operating rhythms, ownership models, and performance expectations while fostering a culture of accountability and  continuous improvement
    • Oversee compliance programs across key frameworks including SOC 2, ISO 27001, HIPAA, GDPR, and emerging health data regulations
    • Establish and maintain the enterprise risk management program, including risk identification, quantification, mitigation, and reporting to executive leadership and the board
    •  Own the third-party risk management program, ensuring vendors and partners meet WHOOP’s security and compliance requirements
    • Lead and evolve governance for responsible AI use, including risk assessment, vendor oversight, regulatory alignment, and policy development in coordination with Product, Legal, and Engineering
    • Partner with Legal, Product, Engineering, and Privacy teams to ensure regulatory requirements are embedded into product development and business processes
    •  Lead engagement with external auditors, regulators, and certification bodies
    • Translate strategic objectives into operational controls and program enhancements, personally driving key initiatives as the function continues to scale
    •  Develop and present risk and compliance reporting to the C-suite, delivering clear, business-aligned risk insights
    •  Drive policy governance, ensuring security and compliance policies are current, enforceable, and aligned with industry best practices
    • Champion a culture of security awareness and compliance across the organization

Qualifications:

    • 10+ years of progressive experience in GRC, information security, risk management, or compliance, with at least 5 years in a leadership role

    • Proven track record of scaling and maturing GRC programs in high-growth technology or health-tech companies

    • Deep expertise across multiple compliance frameworks (SOC 2, ISO 27001, HIPAA, GDPR, NIST CSF, PCI-DSS) with familiarity in emerging AI governance and regulatory standards

    • Strong understanding of cloud security architectures (AWS preferred) and their implications for compliance and risk

    • Experience evaluating AI/ML risk, data governance implications, or responsible AI frameworks in regulated environments

    • Experience presenting risk posture and compliance metrics to executive leadership and board-level audiences

    • Exceptional leadership skills with a demonstrated ability to attract, develop, and retain top GRC talent

    • Strong business acumen with the ability to translate technical risk into business terms

    • Relevant certifications preferred (CISSP, CISM, CRISC, CISA, or equivalent)

Top Skills

AWS
Gdpr
Hipaa
Iso 27001
Nist Csf
Pci-Dss
Soc 2
HQ

WHOOP Boston, Massachusetts, USA Office

1 Kenmore Sq, Boston, MA, United States, 02215

Similar Jobs at WHOOP

16 Minutes Ago
Easy Apply
Hybrid
Boston, MA, USA
Easy Apply
Senior level
Senior level
Fitness • Hardware • Healthtech • Sports • Wearables
Lead security incident response efforts, coordinating investigations, containment, and remediation while improving response practices and metrics.
Top Skills: Cloud Security MonitoringEdr ToolsSiem Platforms
4 Hours Ago
Easy Apply
Hybrid
Boston, MA, USA
Easy Apply
150K-180K Annually
Senior level
150K-180K Annually
Senior level
Fitness • Hardware • Healthtech • Sports • Wearables
The Business Analytics Manager will partner with FP&A for financial forecasting and planning, strengthen business model connections to outcomes, and automate data processes for improved accuracy in decision-making.
Top Skills: DbtSnowflakeSQL
6 Hours Ago
Easy Apply
Hybrid
Boston, MA, USA
Easy Apply
120K-160K Annually
Senior level
120K-160K Annually
Senior level
Fitness • Hardware • Healthtech • Sports • Wearables
Lead and scale design research initiatives at WHOOP, ensuring strategic alignment, managing a team, and contributing hands-on to hardware development research.
Top Skills: Ai ToolsQualitative ResearchQuantitative Research

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account