Director, Security Engineering & Operations

Whoop

3h ago • 1 views • 0 applications
Full-time On-site
Boston, MA
Competitive
Full-time
Security Engineer

Job Description

Director, Security Engineering & Operations

At WHOOP, we're not just building technology; we're on a mission to unlock and inspire human performance for life. Our members rely on us to deliver insights that enhance their health, recovery, and performance. This mission demands an equally high-performing and robust security posture, especially as we integrate cutting-edge AI across our products and operations.

We are seeking a visionary and results-driven Director, Security Engineering & Operations to lead the teams responsible for fortifying our enterprise security. Reporting directly to our CISO and a senior member of the Security leadership team, you will play a pivotal role in shaping our security strategy, leading a growing team of managers, engineers, and analysts, and driving measurable security outcomes across our fast-moving technology environment.

This is a leadership opportunity for a seasoned professional who has successfully scaled security operations in complex, high-growth environments and brings a strong background in security engineering. The ideal leader combines strategic judgment with profound technical depth, staying close enough to the work to set a high bar for engineering quality, guide critical technical decisions, and lead effectively through significant security events.

As WHOOP expands its use of AI across member-facing products, internal technology, and engineering, and continues to evolve its capabilities in health technology, you will be instrumental in ensuring security scales seamlessly alongside our company's technology, data, regulatory, and threat landscape. You will actively shape our team, operating model, and technical roadmap, advancing capabilities across security engineering, detection and response, incident management, security automation, identity, cloud, endpoint, SaaS, data protection, and other critical enterprise security domains.

What You'll Drive:

Strategic Leadership: Lead Security Engineering and Security Operations, defining strategy, priorities, technical standards, performance expectations, and measurable outcomes for both functions.
Advanced Detection & Response: Architect and advance a risk and threat-informed detection and response program, linking priority threat scenarios to comprehensive telemetry, detections, investigation capabilities, response procedures, and operational controls, including identity-centric, data protection, and insider risk scenarios.
Incident Command: Lead security incident readiness and response, including escalation, incident command for significant events, cross-functional coordination, post-incident review, and accountability for follow-up actions.
Robust Security Engineering: Guide the engineering and operationalization of preventive and detective security controls across identity, endpoint, cloud, SaaS, infrastructure, data, AI-enabled systems, and other high-value enterprise environments, setting a high bar for technical design, testing, documentation, maintainability, and lifecycle management.
AI Security Pioneer: Lead the security strategy and engineering approach for AI-enabled products and enterprise AI adoption, encompassing access controls, sensitive data handling, model and application security, third-party integrations, tool and agent permissions, monitoring, auditability, and secure use of AI across the company.
Outcome-Driven Operations: Drive an outcome-oriented approach to security technology and managed services, maximizing the effectiveness of existing capabilities, making disciplined decisions about when to automate, build, buy, or use external partners, and holding security partners accountable to measurable outcomes.
Operational Excellence: Drive disciplined execution across the security engineering and operations portfolio through effective prioritization, roadmap and backlog management, capacity planning, metrics, ownership, and operating cadence.
Team Empowerment: Lead, coach, and develop managers, engineers, and analysts, setting clear expectations for technical quality, judgment, ownership, execution, and professional growth.
Cross-Functional Collaboration: Strengthen collaboration across Product Security, Security Architecture, Platform, Fraud, Engineering, IT, GRC, Legal, Privacy, and other business functions, establishing clear ownership and effective operating relationships across organizational boundaries.
Strategic Partnership: Partner with the CISO on organizational design, workforce planning, hiring, and development of capabilities as the Security organization evolves, providing clear, data-driven communication on security posture, operational performance, significant risks, and strategic priorities.

What You Bring:

10+ years of progressive experience in information security, with deep expertise in Security Operations and significant experience across Security Engineering in complex technology environments.
5+ years of people leadership experience, including multiple years managing managers and senior technical individual contributors. This is not a first-time people leadership role. Demonstrated strength in hiring, coaching, performance management, organizational design, and raising the bar for team quality and execution.
Deep technical expertise in detection engineering, SIEM and telemetry strategy, incident response, and modern security operations, including experience leading significant security incidents.
Proven ability to drive disciplined execution across priorities, roadmaps, backlogs, metrics, and ownership, while maximizing existing capabilities before introducing additional technology.
Experience managing MDR, MSSP, or similar security partners and holding them accountable to measurable operational outcomes.
Experience securing AI-enabled products, enterprise AI adoption, or AI development environments, including risks related to sensitive data, models, agents, third-party services, access, and monitoring.
Strong judgment and relationship-building skills, with a track record of working effectively across technical, product, risk, legal, and senior leadership teams.
Experience in health technology or another sensitive-data environment is a significant plus.

This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.

Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.

WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility.

The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values. At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company’s long-term growth and success.

The U.S. base salary range for this full-time position is $220,000-$245,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training. In addition to the base salary, the successful candidate will also receive benefits and a generous equity package. These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate’s specific qualifications, expertise, and alignment with the role’s requirements.

CyberJob.app

Your trusted source for cybersecurity job opportunities worldwide.


© 2026 CyberJob.app. All rights reserved.