DevOps Engineer II (Cloud Security)
Team: Software
Location: Boston, MA
Workplace Type: onsite
At WHOOP, we're on a mission to unlock human performance and healthspan. WHOOP empowers members to perform at a higher level and live longer through a deeper understanding of their bodies and daily lives. Protecting our members’ data and ensuring our systems scale securely and reliably is core to this mission.
As a DevOps Engineer II on the Cloud Security team, you will play a key role in building and operating the infrastructure, tooling, and guardrails that protect WHOOP’s cloud environments. You will work at the intersection of security, infrastructure, and developer experience, helping ensure that secure-by-default practices are embedded into how systems are designed, deployed, and operated.
The Cloud Security team focuses on reducing risk across WHOOP’s cloud footprint by enforcing least-privilege access, strengthening IAM and secrets management, and detecting and preventing unauthorized access or lateral movement. This role is ideal for an engineer who enjoys automating security, improving developer workflows, and building scalable systems that make the secure path the easiest path.
RESPONSIBILITIES:
-
Design, implement, and manage scalable, secure cloud infrastructure in AWS using Infrastructure as Code (IaC) tools such as Terraform
-
Build and manage IAM systems, access controls, and least-privilege policies to reduce risk and limit blast radius
-
Implement automation and tooling to detect misconfigurations, privilege escalation risks, and anomalous behavior
-
Build and maintain secure, reliable, and auditable AWS and Kubernetes environments across multiple accounts and services
-
Improve secrets management, key rotation, and secure service-to-service authentication patterns
-
Collaborate with platform, product, and data science teams to deliver resilient infrastructure that enables rapid product development and member trust.
-
Contribute to the automation of cloud operations, from CI/CD pipelines to monitoring and alerting systems.
-
Develop and enforce guardrails for cloud security and compliance, including IAM, backups, logging, and configuration management.
-
Participate in incident response and troubleshooting for infrastructure and security events.
-
Participate in audits and compliance efforts by ensuring infrastructure is observable, auditable, and well-documented
-
Drive best practices in reliability, performance, cost optimization, and security across the platform.
QUALIFICATIONS:
-
2-4 years of experience in DevOps, Site Reliability Engineering, or Cloud Infrastructure roles
-
Hands-on experience with AWS services, including IAM, VPC, EC2, S3, and CloudTrail
-
Experience with Infrastructure as Code in production environments (Terraform preferred).
-
Strong understanding of cloud security and reliability principles, including least privilege, logging/monitoring, resource isolation, and disaster recovery.
-
Experience with containerized platforms such as Kubernetes or Amazon EKS.
-
Proficiency with scripting or programming languages (Python, Go, Java, or Bash).
-
Familiarity with CI/CD pipelines, secrets management, and automated security or reliability tooling.
-
Strong problem-solving skills and ability to debug complex distributed systems
-
Effective communication skills and ability to collaborate across teams
BONUS QUALIFICATIONS:
-
Experience with cloud security tooling (e.g., CSPM, CNAPP, SIEM platforms)
-
Experience with compliance frameworks (e.g. SOC 2, HIPAA, GDPR, SOX, and/or SaMD).
-
Experience implementing policy-as-code or access control frameworks
-
Exposure to modern edge and delivery technologies such as Cloudflare, CDN configuration, and TLS/SSL certificate management.
ABOUT YOU:
-
You thrive on ownership and want to shape the foundation of WHOOP’s platform.
-
You believe security should enable developers, not block them, and strive to build guardrails over gates
-
You enjoy automating manual processes and building scalable solutions to reduce risk
-
You are curious about how systems fail and motivated to proactively prevent issues
-
You value simplicity, reliability, and clarity in system design
-
You collaborate well across teams and communicate technical concepts clearly
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say
