Security Architect
Job description
About the role
This position is responsible for shaping how security architecture is practiced and standardized across the entire WHOOP organization. The hire will define foundational security design patterns and governance models that scale with rapid business growth. They will act as a hands-on technical leader, translating complex security topics into clear guidance for cross-functional teams. This role requires balancing strong technical depth with the ability to build trusted relationships with product and engineering stakeholders. The Security Architect will influence long-term technical strategy while enabling teams to move quickly without compromising security or compliance. They will mentor engineers and elevate the overall security maturity of the company through collaboration and education. Success in this role will be measured by the adoption of security best practices and the reduction of architectural risk across the technology stack.
Key facts
What you'll do
Partner with Engineering, Product, Infrastructure, IT, and Security teams to provide architectural guidance throughout the software development lifecycle, ensuring security is incorporated early into design decisions.
Help establish and mature WHOOP's Security Architecture practice by defining architecture governance, review methodologies, security standards, and engagement models that scale with the organization.
Develop and maintain security architecture principles, standards, reference architectures, and reusable design patterns that enable engineering teams to build secure systems consistently.
Review application, cloud, infrastructure, AI, and enterprise technology initiatives to identify architectural risks, validate security controls, and recommend practical mitigation strategies.
Lead architecture reviews and collaborate with engineering teams on threat models, trust boundaries, data flows, identity patterns, secure service-to-service communications, and security design decisions.
Provide technical leadership across application security, cloud security, infrastructure security, API security, identity and access management, secrets management, network security, and data protection.
Work closely with Product Security, Infrastructure Security, and Engineering teams to establish consistent security expectations across new products, internal platforms, and third-party integrations.
Evaluate the security architecture of strategic vendors and technology solutions as part of WHOOP's Third-Party Risk Assessment process.
Translate regulatory and compliance requirements - including HIPAA, PCI DSS, ISO 27001, SOC 2, and NIST frameworks - into practical engineering guidance and architectural controls.
Mentor engineers and security team members on secure design principles, helping raise the organization's overall security maturity through collaboration, education, and trusted technical leadership.
Produce clear architectural documentation, technical standards, design reviews, and implementation guidance that can be consistently applied across engineering teams.
Partner with Security leadership to define the long-term vision, operating model, roadmap, and success metrics for Security Architecture as a strategic capability within the Information Security organization.
Serve as a trusted advisor to engineering and business leaders, balancing security, operational efficiency, and business objectives while promoting a secure-by-design culture across WHOOP.
Requirements
8-12+ years of experience in security architecture, application security, cloud security, infrastructure security, or senior security engineering roles supporting modern distributed systems.
Demonstrated experience designing and securing cloud-native applications and infrastructure, with deep knowledge of AWS security services and modern cloud architecture.
Strong understanding of application security, secure software development, infrastructure security, cloud security, API security, identity and access management, enterprise networking, and modern security architecture principles.
Previous software engineering or application development experience with the ability to understand application design, architecture, implementation tradeoffs, and engineering workflows.
Experience performing architecture reviews, security design assessments, and threat modeling for complex distributed systems.
Familiarity with healthcare, regulated environments, or security programs supporting HIPAA, PCI DSS, ISO 27001, SOC 2, NIST, and similar frameworks is required.
Strong written and verbal communication skills to articulate security guidance to both technical and non-technical audiences across the organization.
Ability to work independently and collaboratively in a fast-paced environment while managing multiple priorities and evolving requirements.