WHOOP
Technology
SeniorRisk&ComplianceAnalyst
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior Risk & Compliance Analyst at WHOOP. Skills: Risk management, Compliance, Cybersecurity, AI risk. Lead cyber and technology risk assessments. Evaluate threats, vulnerabilities, control effectiveness”
Industry & Context.
Root cause analysis
What They're Looking For.
Must Have
6+ years cybersecurity risk management, Demonstrated experience conducting risk assessments, Experience maintaining risk registers, Familiarity with regulatory environments, Ability to translate technical findings, Written and verbal communication skills, Experience working with stakeholders, Experience assessing AI risks
Nice to Have
Professional certifications a plus
What You'll Do.
Lead cyber and technology risk assessments
control effectiveness
Maintain enterprise cyber risk register
Draft risk statements
Track mitigation plans
Support governance and reporting
Translate technical findings into business risk
Support quantitative cyber risk analysis
Prepare risk committee materials
Support executive risk reporting
Partner with Security Architecture
Assess risk in system designs
Assess risk in cloud architecture
Assess risk in identity models
Assess risk in data flows
Assess risk in platform changes
Collaborate with Security Engineering
Collaborate with Product Security
Collaborate with Legal
Collaborate with business teams
Evaluate new initiatives
Evaluate technology changes
Evaluate AI use cases
Evaluate third-party integrations
Conduct risk assessments for emerging technologies
Evaluate model behavior
Evaluate external dependencies
Evaluate security implications
Evaluate risks associated with AI
Evaluate risks associated with model behavior
Evaluate risks associated with data exposure
Evaluate risks associated with prompt manipulation
Evaluate risks associated with external model dependencies
Develop dashboards and reporting
Provide leadership visibility
Track mitigation progress
Track risk treatment activities
Ensure accountability
Contribute to cyber risk management processes
Contribute to methodologies
Contribute to governance practices
How You'll Work.
Team & Collaboration
Cross-functional teams; Engineering, architecture, legal, compliance, business stakeholders
Communication Scope
Executive risk reporting; Presenting findings
Full Job Description
RESPONSIBILITIES: - - Lead cyber and technology risk assessments across systems, cloud environments, business processes, and major initiatives, evaluating threats, vulnerabilities, control effectiveness, and residual risk. - Maintain and operate the enterprise cyber risk register, including drafting risk statements, tracking mitigation plans, and supporting governance and reporting processes. - Translate technical findings, architectural concerns, and control gaps into clear business risk scenarios that support prioritization and decision-making. - Support and help mature quantitative cyber risk analysis approaches such as FAIR to improve how risk is measured and communicated. - Prepare materials and analysis to support the Cyber Risk Committee and executive risk reporting. - Partner with Security Architecture to assess risk in system designs, cloud architecture, identity models, data flows, and platform changes. - Collaborate with Security Engineering, Product Security, Legal, IT, and business teams to evaluate new initiatives, technology changes, artificial intelligence use cases, and third-party integrations through a risk lens. - Conduct risk assessments for emerging technologies including artificial intelligence and machine learning systems, evaluating data usage, model behavior, external dependencies, and security implications. - Evaluate risks associated with the use of artificial intelligence technologies, including model behavior, data exposure, prompt or input manipulation, and external model dependencies. - Develop dashboards and reporting that provide leadership with visibility into key cybersecurity risks and trends. - Track mitigation progress and risk treatment activities to ensure accountability and clear documentation of outcomes. - Contribute to the continued development of cyber risk management processes, methodologies, and governance practices across the GRC program. QUALIFICATIONS: - - 6+ years of experience in cybersecurity risk management, inf
Applying for this Senior Risk & Compliance Analyst role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about WHOOP?
Real rants from real employees. Read before you apply.