WHOOP

Technology

SeniorRisk&ComplianceAnalyst

$130–170k Boston, Massachusetts, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Senior Risk & Compliance Analyst at WHOOP. Skills: Risk management, Compliance, Cybersecurity, AI risk. Lead cyber and technology risk assessments. Evaluate threats, vulnerabilities, control effectiveness”

Industry & Context.

Technology
Problems you'll solve

Root cause analysis

What They're Looking For.

Must Have

6+ years cybersecurity risk management, Demonstrated experience conducting risk assessments, Experience maintaining risk registers, Familiarity with regulatory environments, Ability to translate technical findings, Written and verbal communication skills, Experience working with stakeholders, Experience assessing AI risks

Nice to Have

Professional certifications a plus

What You'll Do.

Lead cyber and technology risk assessments

control effectiveness

Maintain enterprise cyber risk register

Draft risk statements

Track mitigation plans

Support governance and reporting

Translate technical findings into business risk

Support quantitative cyber risk analysis

Prepare risk committee materials

Support executive risk reporting

Partner with Security Architecture

Assess risk in system designs

Assess risk in cloud architecture

Assess risk in identity models

Assess risk in data flows

Assess risk in platform changes

Collaborate with Security Engineering

Collaborate with Product Security

Collaborate with Legal

Collaborate with business teams

Evaluate new initiatives

Evaluate technology changes

Evaluate AI use cases

Evaluate third-party integrations

Conduct risk assessments for emerging technologies

Evaluate model behavior

Evaluate external dependencies

Evaluate security implications

Evaluate risks associated with AI

Evaluate risks associated with model behavior

Evaluate risks associated with data exposure

Evaluate risks associated with prompt manipulation

Evaluate risks associated with external model dependencies

Develop dashboards and reporting

Provide leadership visibility

Track mitigation progress

Track risk treatment activities

Ensure accountability

Contribute to cyber risk management processes

Contribute to methodologies

Contribute to governance practices

How You'll Work.

Team & Collaboration

Cross-functional teams; Engineering, architecture, legal, compliance, business stakeholders

Communication Scope

Executive risk reporting; Presenting findings

Full Job Description

RESPONSIBILITIES: - - Lead cyber and technology risk assessments across systems, cloud environments, business processes, and major initiatives, evaluating threats, vulnerabilities, control effectiveness, and residual risk. - Maintain and operate the enterprise cyber risk register, including drafting risk statements, tracking mitigation plans, and supporting governance and reporting processes. - Translate technical findings, architectural concerns, and control gaps into clear business risk scenarios that support prioritization and decision-making. - Support and help mature quantitative cyber risk analysis approaches such as FAIR to improve how risk is measured and communicated. - Prepare materials and analysis to support the Cyber Risk Committee and executive risk reporting. - Partner with Security Architecture to assess risk in system designs, cloud architecture, identity models, data flows, and platform changes. - Collaborate with Security Engineering, Product Security, Legal, IT, and business teams to evaluate new initiatives, technology changes, artificial intelligence use cases, and third-party integrations through a risk lens. - Conduct risk assessments for emerging technologies including artificial intelligence and machine learning systems, evaluating data usage, model behavior, external dependencies, and security implications. - Evaluate risks associated with the use of artificial intelligence technologies, including model behavior, data exposure, prompt or input manipulation, and external model dependencies. - Develop dashboards and reporting that provide leadership with visibility into key cybersecurity risks and trends. - Track mitigation progress and risk treatment activities to ensure accountability and clear documentation of outcomes. - Contribute to the continued development of cyber risk management processes, methodologies, and governance practices across the GRC program. QUALIFICATIONS: - - 6+ years of experience in cybersecurity risk management, inf

Free ATS check

Applying for this Senior Risk & Compliance Analyst role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about WHOOP?

Real rants from real employees. Read before you apply.

Read Company Rants →