- Where
- Boston, MA
- Posted
- Jul 17
At WHOOP, we're on a mission to unlock and inspire performance for life.
WHOOP is seeking a Governance, Risk, and Compliance Analyst II, to lead the day-to-day operation and support the ongoing risk management program at GRC in a fast-paced, high-growth environment. This role is responsible for operations of GRC initiatives - including but not limited to structured cybersecurity and AI risk assessments, exceptions management,
SDLC reviews and security compliance process ownership. The role will partner closely with Legal, Security, Product, and other teams to advance compliance objectives, reduce enterprise risk, and strengthen operational resilience.
The ideal candidate combines strong analytical thinking, critical risk mind-set, familiarity with AI governance and has the ability to communicate complex risk scenarios clearly to both technical and non-technical stakeholders.
What you'd do
- Lead governance, risk assessment, and compliance activities specific to AI/ML systems
- Partner with the Senior Security Engineer, AI/ML to integrate risk assessment findings into
- Develop, maintain, and refine AI risk and compliance controls aligned with relevant
- Execute risk assessments for new AI vendors, LLM platforms, AI APIs, and enterprise AI
- Manage the vendor risk assessment lifecycle for AI/ML related suppliers, ensuring
- Support audit activities, capturing evidence and coordinating cross-functional
- Develop and maintain AI-specific GRC policies, standards, and procedures that map to AI
- Facilitate AI risk and compliance reporting to leadership, including risk dashboards, trend
- Monitor emerging AI governance requirements, guidance, and best practices, translating
- Support security incident documentation and post-incident analysis for AI system events
What they want
- 6+ years of experience in Governance, Risk & Compliance, including risk assessment
- Demonstrated experience performing governance or risk assessments for AI/ML systems
- Experience translating AI-specific risks (i.e., data poisoning, prompt injection, model
- Experience supporting regulatory readiness or compliance efforts related to AI systems
- Proven ability to collaborate with engineering and security teams to validate control