Jobs · Business Development · Massachusetts

Senior GRC Analyst

WHOOP · Boston, MA · 1 mo ago
On-siteBusiness Development$130k–$170k/yrFull-time

Responsibilities

  • Lead cyber, AI, and technology risk assessments across systems, cloud environments, business processes, and major initiatives, evaluating threats, vulnerabilities, control effectiveness, and residual risk
  • Maintain and operate the enterprise cyber risk register, including drafting risk statements, tracking mitigation plans, and supporting governance and reporting processes
  • Translate technical findings, architectural concerns, and control gaps into clear business risk scenarios that support prioritization and decision-making
  • Support and help mature quantitative cyber risk analysis approaches such as FAIR to improve how risk is measured and communicated
  • Prepare materials and analysis to support the Cyber Risk Committee and executive risk reporting
  • Partner with Security Architecture to assess risk in system designs, cloud architecture, identity models, data flows, and platform changes
  • Collaborate with Security Engineering, Product Security, Legal, IT, and business teams to evaluate new initiatives, technology changes, artificial intelligence use cases, and third-party integrations through a risk lens
  • Develop dashboards and reporting that provide leadership with visibility into key cybersecurity risks and trends
  • Contribute to the continued development of cyber risk management processes

Qualifications

  • 6+ years of experience in cybersecurity or enterprise risk management, information security, or a related field
  • Demonstrated experience conducting structured cybersecurity or IT risk assessments
  • Experience maintaining risk registers and tracking risk mitigation or treatment activities
  • Deep understanding of security frameworks such as NIST CSF, ISO 27001, or PCI DSS, and familiarity with regulatory environments such as GDPR, HIPAA or other privacy and data protection requirements
  • Ability to translate technical findings into clear business risk for non-technical stakeholders
  • Strong written and verbal communication skills with experience presenting findings to cross-functional teams
  • Experience assessing risks related to artificial intelligence, machine learning systems, or emerging technologies, including familiarity with emerging AI governance frameworks such as NIST AI RMF, ISO/IEC 42001, or similar standards
  • Professional certifications such as CRISC, CISSP, CISA, or CGRC are a plus

Similar jobs

Senior GRC Analyst

ClaycoPhoenix, AZ· 2 mo ago
Information Technology$8.1/hrapply on jobs.crelate.com

Senior GRC Analyst

ClaycoSt Louis, MO· 2 mo ago
Information Technology$8.1/hrapply on jobs.crelate.com

Senior GRC Analyst

Wolfe, LLCPittsburgh, PA· 2 wk ago
Business Development$114k–$163k/yrapply on wolfe.pinpointhq.com

Senior GRC Analyst

LaddersUnited States· 1 mo ago
RemoteBusiness Development$100k–$130k/yrapply on theladders.com