1 month ago
Boston, MA, USASenior / Staff+
H1B sponsor
Base Salary
$155k - $195k/yr
Responsibilities
- Partner with engineering, product, infrastructure, IT, and security teams to incorporate security into software and system design.
- Establish and mature security architecture governance, review methodologies, standards, engagement models, and operating practices.
- Develop security principles, reference architectures, reusable design patterns, technical standards, and implementation guidance.
- Review application, cloud, infrastructure, AI, enterprise, vendor, and third-party technology initiatives for architectural risks and security controls.
- Lead architecture reviews and threat modeling covering trust boundaries, data flows, identity patterns, and secure service-to-service communications.
- Provide technical leadership across application, cloud, infrastructure, API, identity and access management, secrets, network, and data security.
- Translate HIPAA, PCI DSS, ISO 27001, SOC 2, and NIST requirements into practical engineering guidance and architectural controls.
- Mentor engineers and security team members and advise leaders on security, operational efficiency, and business objectives.
- Define the long-term Security Architecture vision, roadmap, success metrics, and secure-by-design culture.
Requirements
- 8–12+ years of experience in security architecture, application security, cloud security, infrastructure security, or senior security engineering roles.
- Experience designing and securing cloud-native applications and infrastructure, including strong knowledge of AWS security services and modern cloud architecture.
- Strong understanding of application security, secure software development, infrastructure security, cloud security, API security, identity and access management, enterprise networking, and security architecture principles.
- Previous software engineering or application development experience with knowledge of application design, architecture, implementation tradeoffs, and engineering workflows.
- Experience conducting architecture reviews, security design assessments, and threat modeling for complex distributed systems.
- Familiarity with healthcare, regulated environments, HIPAA, PCI DSS, ISO 27001, SOC 2, NIST 800-53, or similar frameworks.
- Ability to provide practical, risk-based recommendations and influence technical decisions across engineering, product, IT, and security organizations.
- Strong written, verbal, interpersonal, collaboration, judgment, and communication skills.
- Professional certifications such as CISSP, CCSP, AWS Certified Security – Specialty, GIAC, or TOGAF are preferred.
- Ability to work independently while establishing security processes, standards, governance models, and architectural practices.
Benefits
- U.S. base salary range of $155,000–$195,000, plus meaningful equity and benefits.
- Full-time role based in WHOOP’s Boston, Massachusetts office; relocation is required if necessary.
- Generous equity package and benefits are provided in addition to base salary.
- WHOOP is an Equal Opportunity Employer and participates in E-Verify.
About WHOOP
Solving problems that sit at a unique intersection of hardware, tech, health, fitness and design.
