J-1 Visa Risk Compliance Analyst Jobs
Risk Compliance Analyst roles in the U.S. typically qualify for J-1 sponsorship under the Trainee or Intern category, administered by a State Department-designated sponsor organization that issues your DS-2019. Host employers in banking, insurance, and corporate compliance regularly work with these sponsors to bring in internationally trained candidates.
See All Risk Compliance Analyst JobsOverview
Showing 5 of 34+ Risk Compliance Analyst jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 34+ Risk Compliance Analyst jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Risk Compliance Analyst roles.
Get Access To All Jobs
At WHOOP, we’re on a mission to unlock human performance and healthspan. Our wearable technology provides personalized insights that help millions of members better understand their bodies and make smarter decisions about training, recovery, and lifestyle. As AI systems play a growing role across our platform, effective governance, risk management, and compliance for AI and associated technologies are critical for safeguarding member data, ensuring regulatory alignment, and enabling secure innovation. We are seeking an AI Risk & Compliance Analyst to partner with Security, Product, Engineering, Legal, and Privacy teams to govern risk and compliance related to AI systems and machine learning integrations. This role will support AI-related risk evaluation, vendor assessments, policy governance, audit coordination, and compliance with emerging AI regulatory frameworks. This is a senior individual contributor role within GRC with broad influence across risk domains and collaboration with technical and business stakeholders.
Responsibilities
- Lead governance, risk assessment, and compliance activities specific to AI/ML systems, LLM integrations, AI agents, and retrieval-augmented workflows
- Partner with the Senior Security Engineer, AI/ML to integrate risk assessment findings into GRC frameworks and translate technical risk into governance requirements
- Develop, maintain, and refine AI risk and compliance controls aligned with relevant frameworks, including ISO/IEC 27001, NIST Cybersecurity Framework, NIST AI Risk Management Framework, EU AI Act, GDPR, and other applicable standards
- Execute risk assessments for new AI vendors, LLM platforms, AI APIs, and enterprise AI tools, including third-party risk scoring, control mapping, and remediation tracking
- Manage the vendor risk assessment lifecycle for AI/ML related suppliers, ensuring documented controls, evidence collection, and follow-up on remediation items
- Support audit activities, capturing evidence and coordinating cross-functional stakeholders for internal and external compliance reviews involving AI systems
- Develop and maintain AI-specific GRC policies, standards, and procedures that map to AI risk domains, explainability requirements, and compliance obligations
- Facilitate AI risk and compliance reporting to leadership, including risk dashboards, trend analysis, control effectiveness measurements, and key metrics
- Monitor emerging AI governance requirements, guidance, and best practices, translating them into GRC program updates and compliance recommendations
- Support security incident documentation and post-incident analysis for AI system events, coordinating with Legal and Security teams to ensure appropriate governance response
Qualifications
- 6+ years of experience in Governance, Risk & Compliance, including risk assessment, policy development, audit coordination, and third-party risk management
- Demonstrated experience performing governance or risk assessments for AI/ML systems, including LLM integrations, model pipelines, AI agents, or data-driven algorithmic systems
- Experience translating AI-specific risks (i.e., data poisoning, prompt injection, model misuse, data leakage, explainability gaps) into documented control requirements and governance standards
- Hands-on experience conducting third-party risk assessments for AI vendors, LLM platforms, AI APIs, or machine learning service providers
- Experience mapping AI-related risks and controls to frameworks such as ISO/IEC 27001, NIST CSF, NIST AI RMF, ISO/IEC 42001, GDPR, PCI DSS, or similar standards
- Strong understanding of data governance concepts relevant to AI systems, including training data lineage, data retention, model output handling, and human oversight requirements
- Experience supporting regulatory readiness or compliance efforts related to AI systems
- Proven ability to collaborate with engineering and security teams to validate control implementation and remediation
- Experience with GRC tools, risk registers, and evidence-based compliance workflows
- Bachelor’s degree in Information Security, Computer Science, Business Risk, Compliance, or a related field, relevant certifications CISA, CISM, CRISC, CISSP, AIGP, or equivalent practical experience
Location: This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.
Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility.
The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values. At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company’s long-term growth and success.
The U.S. base salary range for this full-time position is $85,000 - $135,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training. In addition to the base salary, the successful candidate will also receive benefits and a generous equity package. These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate’s specific qualifications, expertise, and alignment with the role’s requirements.
See all 34+ Risk Compliance Analyst jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Risk Compliance Analyst roles.
Get Access To All JobsTips for Finding J-1 Visa Sponsorship as a Risk Compliance Analyst
Document your compliance credentials before applying
Gather transcripts, professional certifications (CRCM, CAMS, CIA), and reference letters that demonstrate field-specific training. Designated sponsors assess whether your background justifies a Trainee versus Intern categorization, so credentialing gaps slow approval.
Target host employers with active compliance functions
Financial institutions, fintechs, and insurance carriers with dedicated second-line risk teams are most likely to structure formal training plans. Search for roles that list SOX, BSA, or AML compliance explicitly, which signals an established program rather than a general business hire.
Find J-1 compatible risk roles on Migrate Mate
Use Migrate Mate to filter for Risk Compliance Analyst positions at U.S. employers whose hiring history aligns with exchange visitor programs, so you spend time on realistic targets rather than employers unfamiliar with the DS-2019 process.
Clarify the training plan requirement early in interviews
A J-1 Trainee placement requires a detailed Training Plan (DS-7002) co-signed by you, the host employer, and the designated sponsor. Raise this in a second-round conversation so hiring managers understand the paperwork obligation before extending an offer.
Verify whether your role triggers the home residency requirement
Some J-1 participants funded by their home government or whose skill is on the State Department's Exchange Visitor Skills List must return home for two years after completing the program. Confirm this with your designated sponsor before accepting an offer, as it affects any future H-1B or green card path.
Align your program dates with the employer's fiscal compliance cycle
Risk teams run intensive work around year-end audits and regulatory reporting periods. Proposing a start date that captures one full reporting cycle strengthens your training plan narrative and gives the designated sponsor clearer justification for approving the placement.
Risk Compliance Analyst jobs are hiring across the US. Find yours.
Find Risk Compliance Analyst JobsRisk Compliance Analyst J-1 Visa: Frequently Asked Questions
Which J-1 program category fits a Risk Compliance Analyst role?
Most Risk Compliance Analyst placements fall under the Trainee category if you have a degree plus at least one year of relevant experience, or the Intern category if you are currently enrolled in a degree program. The Trainee category is more common because compliance work typically requires demonstrated professional grounding. A State Department-designated sponsor organization evaluates your background and assigns the appropriate category before issuing your DS-2019.
Who actually sponsors my J-1 visa, the employer or someone else?
The visa sponsor is a U.S. Department of State-designated organization, such as Cultural Vistas, IIE, or AIPT, not your employer. Your employer is the host organization. The designated sponsor issues the DS-2019 form, monitors your program compliance, and co-signs your DS-7002 training plan. The employer provides the placement and the structured training environment but does not hold the sponsorship designation itself.
How do I find U.S. employers open to hosting a J-1 Risk Compliance Analyst?
Use Migrate Mate to search for Risk Compliance Analyst positions at employers whose hiring patterns are compatible with exchange visitor program requirements. Because J-1 hosting involves training plan documentation and sponsor coordination, targeting employers already familiar with the process saves significant time. Regulated industries, including banking, insurance, and asset management, are the most consistent hosts for compliance-focused J-1 placements.
Does a Risk Compliance Analyst placement trigger the two-year home residency requirement?
It depends on two factors: whether your home country government financed your exchange program, and whether your specific skill set appears on the State Department's Exchange Visitor Skills List. Many compliance professionals from countries with high regulatory demand for risk expertise are subject to this requirement. Your designated sponsor reviews your DS-2019 application and will note a Section 212(e) obligation if it applies, before you begin your program.
What does the DS-7002 training plan need to include for a compliance role?
The DS-7002 must outline specific learning objectives tied to compliance functions, such as regulatory reporting, internal audit support, AML transaction monitoring, or risk control testing. It should break the program into phases with measurable goals and list the supervision structure. Vague plans describing general office work are routinely rejected by designated sponsors. Your host employer's compliance or legal department typically drafts this document in coordination with the designated sponsor.
See which Risk Compliance Analyst employers are hiring and sponsoring visas right now.
Search Risk Compliance Analyst Jobs