- Company Name
- WHOOP
- Job Title
- GRC Analyst
- Job Description
-
**Job Title**
GRC Analyst
**Role Summary**
Support the development, implementation, and maintenance of the Governance, Risk, and Compliance (GRC) program. Work under a senior manager to develop policies, conduct risk assessments, monitor compliance, coordinate audits, manage vendor risk, assist incident response, deliver training, and improve GRC processes.
**Expactations**
- Minimum 2 years experience in information security, risk management, audit, or compliance.
- Bachelor’s degree in Information Security, Computer Science, or related field.
- Strong grasp of GRC concepts, standards, and regulatory frameworks (GDPR, SOC 2, ISO 27001, NIST CSF).
- Excellent analytical, problem‑solving, communication, and organizational skills.
- Proactive, results‑oriented attitude with ability to navigate ambiguity.
**Key Responsibilities**
- Assist in building and implementing the GRC framework aligned with business goals and industry best practices.
- Conduct risk assessments and help develop mitigation strategies; maintain the risk register.
- Support ongoing compliance monitoring against internal policies, regulations, standards, and contracts.
- Evaluate and manage third‑party vendor risks through assessment processes.
- Provide incident‑response support: documentation, coordination, and post‑incident analysis.
- Develop and deliver security awareness and training programs for employees.
- Support audit activities: gather evidence, perform preliminary assessments, aid remediation of findings.
- Respond to and resolve GRC support tickets efficiently.
- Review, draft, and update security policies, standards, and procedures to meet regulatory mandates.
- Maintain and refine GRC SOPs; identify improvement opportunities and assist implementation.
**Required Skills**
- Risk assessment and mitigation planning.
- Knowledge of GRC tools and platforms.
- Familiarity with regulatory requirements (GDPR, SOC 2, ISO 27001, NIST CSF).
- Incident response documentation and coordination.
- Audit evidence collection and preliminary evaluation.
- Policy, standards, and SOP development.
- Strong written and verbal communication.
- Organizational and time‑management capabilities.
- Ability to work cross‑functionally and manage multiple projects.
**Required Education & Certifications**
- Bachelor’s degree in Information Security, Computer Science, or related discipline.
- Valid certifications (CompTIA Security+, CISSP, CISA, CISM, or GRC‑specific certificates) are a plus.
---