Director of Product Security
Job description
About the role
You will architect and own the end-to-end product security strategy for member authentication and identity systems at scale. You will build and lead multiple engineering teams that execute on secure software development lifecycle practices across the entire product portfolio. This role demands a strategic partner who translates business risk into technical roadmaps for product teams. You will strengthen our posture by driving threat modeling, privacy by design, and secure-by-default engineering patterns. Ultimately, you will ensure that security becomes a core accelerator of innovation rather than a bottleneck. Your work will directly protect member data and reinforce trust in the WHOOP platform.
Key facts
What you'll do
Define and communicate a long-term product security strategy, product architecture standards, and design principles for all product-facing systems.
Build, lead, and grow multiple engineering teams focused on member authentication, code security, cloud security across AWS accounts, privacy by design, and threat modeling.
Establish and enforce best practices, standards, and processes for secure software development, testing, and deployment across the organization.
Lead application vulnerability management programs spanning bug bounties, code vulnerabilities, container vulnerabilities, and infrastructure vulnerabilities.
Build, integrate, and mature DevSecOps tooling and developer security controls, including SAST, SCA, container scanning, secrets detection, and CI/CD security checks.
Partner with engineering, product, legal, compliance, and enterprise security to embed privacy and security by design across the software development lifecycle.
Provide mentorship, guidance, and career development for engineering managers and individual contributors, fostering growth at the staff level and beyond.
Foster a culture of innovation, teamwork, psychological safety, and continuous learning within the Product Security organization.
Leverage data-driven decision-making to prioritize security initiatives and measure the effectiveness of security controls.
Act as the technical authority on product security, balancing hands-on technical oversight with long-term organizational scaling.
Serve as the primary liaison with office of the CISO and enterprise security to align on risk posture and regulatory requirements.
Champion secure coding practices and ensure security is integrated early in the design phase of new products and features.
Drive adoption of secure-by-default engineering patterns to reduce friction while increasing protection for members.
Continuously evaluate emerging threats and adapt security tooling and processes to maintain resilience.
Requirements
Demonstrated success scaling a security team whilst crafting clear and efficient team domains.
Proven experience as a technical leader managing multiple teams or a growing security engineering organization.
Experience growing high level individual contributor career growth at the staff level or higher.
Deep understanding of product security principles, including vulnerability management, data privacy, threat modeling, secure SDLC practices, and secure-by-default engineering patterns.
Experience building or integrating developer security tooling to improve secure-by-default practices.
Strong technical background in software development, testing, and deployment processes.
Excellent communication, interpersonal, and leadership skills with the ability to influence across teams and levels.
Must be legally authorized to work in the United States without sponsorship for this position.
Nice to have
Experience with AWS cloud environments and data-driven decision-making.
Hands-on experience with containerized microservice environments.
Background in incident response and post-mortem analysis for security events.
Familiarity with automation frameworks for vulnerability scanning, compliance checks, or infrastructure security.
Practical notes
This role is based in the WHOOP office located in Boston, MA.
The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.
Learn more about our Software Org and how to be successful in your engineering career at WHOOP via our Career Framework https://engineering.prod.whoop.com/careerframework.
Interested in the role, but don't meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
WHOOP is an Equal Opportunity Employer and participates in EEO compliance.