Whoop · Boston, MA

Salary
$100,000–$140,000from the description
Posted
Jul 16, 2026
Location
Boston, MA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A GRC analyst role focused heavily on AI and machine learning governance, sitting within a cybersecurity risk team. Day-to-day work centers on conducting risk assessments for AI/ML systems and vendors, mapping controls to frameworks such as NIST AI RMF and ISO/IEC 42001, managing the vendor risk lifecycle, and producing compliance reporting for leadership. Suits someone with a solid GRC background who has hands-on experience assessing AI-specific risks and translating them into documented governance requirements.

Senior level · 6+ years · Boston-Cambridge-Newton, MA-NH · Bachelor's required · Full-time

Advertised as Mid, but the requirements read as Senior.

Must have (7)
risk assessmentNIST CSFNIST AI RMFISO/IEC 42001GDPRLLMsEU AI Act
Nice to have (1)
PCI DSS

Posted 3 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
GDPR12%

Rare in this occupation — lead with these, and say what you built with them.

What the occupation pays Median $139,553 (middle half $110,917–$180,330). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

The title 'Analyst II' conventionally signals a mid-level role, but the requirements — 6+ years of GRC experience, demonstrated AI/ML governance work, and end-to-end program ownership — support a Senior classification.

ISO/IEC 42001 is listed twice in the qualifications section; treated as a single requirement.

PCI DSS appears in the qualifications as part of an 'or similar standards' list alongside the primary required frameworks; listed as preferred since it is presented as one option among several alternatives rather than a standalone gate.

The role is explicitly office-based in Boston, MA with a relocation requirement; remote=false.

Several items in the qualifications (e.g., 'audit coordination', 'policy development') are operational GRC competencies rather than named tools or technologies; they are included here because the JD explicitly gates on them as distinct demonstrated experience areas within the GRC domain.

Ignored 4 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): AI/ML governance, third-party risk management, audit coordination, policy development.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗