Director of Product Security
At WHOOP, we are on a relentless mission to unlock and inspire performance for life. Our members rely on us to understand their bodies and daily lives at a profound level. This means protecting their sensitive data and ensuring our systems scale with uncompromising security and reliability isn't just a priority—it's foundational to everything we do.
Are you a visionary cybersecurity leader passionate about building secure-by-design products at scale? Join WHOOP as our Director of Product Security and take the helm in shaping the future of our secure software development lifecycle. This critical role empowers you to fortify our product-facing identity and authentication capabilities, directly safeguarding our members' trust and privacy.
You will be instrumental in strategically crafting the product security roadmap, collaborating closely with stakeholders across Product, Software, Legal, Compliance, and Enterprise Security. This is an unparalleled opportunity to build, lead, and grow high-performing security engineering teams, ensuring WHOOP continues to innovate securely.
What You'll Drive & Lead
Strategic Team Leadership & Growth: Build, mentor, and lead multiple engineering teams focused on product-facing security strategy, encompassing member authentication, robust code security, comprehensive cloud security across AWS accounts, privacy by design, and proactive threat modeling.
Advanced Vulnerability Management: Spearhead and mature application vulnerability management programs, orchestrating bug bounties, and addressing code, container, and infrastructure vulnerabilities across our ecosystem.
DevSecOps & Automation Excellence: Architect, integrate, and evolve DevSecOps tooling and developer security controls, including SAST, SCA, container scanning, secrets detection, CI/CD security checks, and fostering secure-by-default developer workflows.
Security Architecture & Standards: Define and articulate long-term product security strategy, product architecture standards, and design principles that guide the development of all product-facing systems.
SDLC Integration & Partnership: Collaborate strategically with engineering, the Office of the CISO, and compliance leadership to embed privacy and security by design seamlessly across the entire software development lifecycle.
Process & Best Practice Enforcement: Establish, champion, and enforce industry-leading best practices, standards, and processes for secure software development, rigorous testing, and resilient deployment.
Mentorship & Career Development: Provide impactful mentorship, guidance, and career development opportunities for engineering managers and individual contributors, fostering growth at all levels.
Cultivate a Secure-First Culture: Champion a culture of innovation, collaborative teamwork, psychological safety, and continuous learning within the Product Security organization.
Who You Are
Proven Leader & Builder: Demonstrated success in scaling security teams, defining clear and efficient team domains, and leading multiple engineering teams or a growing security engineering organization.
Technical Domain Expert: Deep understanding of core product security principles, including vulnerability management, data privacy, threat modeling, secure SDLC practices, and secure-by-default engineering patterns.
DevSecOps Integrator: Hands-on experience building or integrating developer security tooling to significantly enhance secure-by-default practices.
Software Development Foundation: Strong technical background in software development, testing, and deployment processes.
Collaborative Influencer: Excellent communication, interpersonal, and leadership skills, with a proven ability to influence and align diverse teams and stakeholders across all organizational levels.
Growth Advocate: Experience fostering high-level individual contributor career growth, including staff-level and above.
Bonus Points If You Have
Extensive experience with AWS cloud environments and data-driven decision-making.
Hands-on experience with containerized microservice environments.
A solid background in incident response and conducting thorough post-mortem analysis for security events.
Familiarity with automation frameworks for vulnerability scanning, compliance checks, or infrastructure security.
Why You'll Thrive at WHOOP
You are a strategic and people-focused leader who masterfully balances hands-on technical oversight with long-term organizational growth. You possess a passion for crafting secure, privacy-first systems that not only protect member data but also accelerate innovation.
You excel at cross-functional collaboration, confidently navigating both strategic and tactical domains across technical and non-technical teams. Above all, you firmly believe that robust security is an enabler of innovation, and you lead by fostering a culture that champions both speed and safety.
Discover more about our Software Organization and how to advance your engineering career at WHOOP through our Career Framework.
Location & Inclusivity
This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.
Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.