Security Engineer, IAM
Job description
About the role
You will architect and operationalize identity and access management controls that serve as the central nervous system for securing our cloud-native platforms and SaaS ecosystems. This role owns the design, implementation, and continuous optimization of authentication, authorization, and federation mechanisms across our global workforce and production environments. You will act as the technical guardian of identity, ensuring that access policies remain aligned with business objectives without compromising security rigor. You will translate complex security requirements into practical implementation patterns that scale reliably for millions of members. Collaboration with Security, IT, and Engineering stakeholders will drive the delivery of zero trust principles and modern identity frameworks. You will lead initiatives to evolve legacy workflows into future-state access models that are both resilient and user-friendly. Your work will directly influence the integrity of critical systems and the trust of our membership base.
Key facts
What you'll do
Implement authentication and authorization controls across SaaS platforms, cloud infrastructure, and internal applications to establish a unified security perimeter.
Configure and maintain SSO, MFA, conditional access policies, and federation integrations to enforce consistent identity verification and risk-based access.
Assist with the evolution of single sign-on (SSO), multi-factor authentication (MFA), conditional access, and zero trust access models to reduce attack surfaces and improve verification rigor.
Assist in design and enforce role-based and attribute-based access control models (RBAC/ABAC) across cloud and SaaS systems to ensure least privilege and precise permissioning.
Validate identity provider integrations, including application onboarding and SCIM provisioning, to guarantee accurate user lifecycle management and data integrity.
Partner with Engineering to secure application authentication flows, API access, service-to-service authentication, and token management for resilient and tamper-resistant communication.
Harden and optimize identity provider configurations, including lifecycle management, federation, and SCIM provisioning, to enhance reliability, performance, and auditability.
Support AWS IAM security, including policy implementation, role configuration, cross-account access management, and identity federation to safeguard cloud resources and minimize lateral movement.
Implement privileged access and identity lifecycle controls, including provisioning, deprovisioning, access reviews, entitlement governance, least privilege enforcement, and just-in-time access mechanisms to mitigate insider risk.
Secure APIs, service accounts, and non-human identities used in automation and CI/CD workflows to prevent unauthorized execution and maintain pipeline integrity.
Implement and improve identity monitoring and detection capabilities, including anomaly detection, session risk analysis, and identity threat response to enable rapid recognition and remediation of suspicious behavior.
Partner with GRC to support identity-related audits, evidence collection, and control validation across frameworks such as ISO 27001, SOC 2, PCI DSS, and GDPR to ensure compliance and transparency.
Contribute to incident response efforts involving identity compromise, credential abuse, or unauthorized access events by coordinating forensic analysis, containment, and recovery procedures.
Promote security best practices through documentation, knowledge sharing, and cross-functional training to elevate the identity security posture of the entire organization.
Requirements
3+ years of experience in IAM engineering or identity architecture to ensure you have sufficient depth to operate independently in complex environments.
Hands-on experience with enterprise identity providers such as Okta, Azure AD, or similar enterprise IAM platforms to manage large-scale identity operations and integrations.
Strong understanding of modern authentication and authorization protocols, including SAML, OAuth 2.0, OIDC, SCIM, and JWT to implement interoperable and secure identity exchanges.
Experience designing and implementing RBAC and/or ABAC models in cloud-native environments to enforce granular, context-aware access decisions.
Strong knowledge of AWS IAM, cross-account access models, and cloud identity federation to secure hybrid and multi-account architectures.
Experience securing APIs, service accounts, machine identities, and CI/CD authentication workflows to protect automated processes and critical pipelines.
Experience with privileged access management concepts and least privilege enforcement to reduce risk and improve governance across systems.
Experience automating IAM tasks using scripting or infrastructure-as-code tools (i.e., Python, Terraform, or similar infrastructure-as-code tooling) to increase efficiency and repeatability.
Familiarity with identity threat detection and response methodologies to proactively identify and neutralize advanced identity-based attacks.
Bachelor's degree in Computer Science, Cybersecurity, or related field; relevant certifications (i.e., CISSP, CISM, GIAC, AWS Security Specialty, Okta Certified Professional) or equivalent practical experience will also be considered.
Practical notes
This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.
WHOOP is an Equal Opportunity Employer and participates in E-verify https://www.e-verify.gov/to determine employment eligibility
The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.
At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company's long-term growth and success.
The U.S. base salary range for this full-time position is $130,000 - $170,000. Sal