RESPONSIBILITIES:
- Serve as a technical lead and subject matter expert on key security initiatives and cross-functional projects, collaborating with IT, GRC, Software, and other stakeholders to reduce risk across the organization.
- Design, implement, and continuously improve security controls, automation, and monitoring solutions to protect WHOOP systems, infrastructure, and data at scale.
- Lead and execute complex security assessments, vulnerability testing, and risk analysis efforts, providing recommendations and driving remediation plans.
- Drive incident response efforts, including investigation, coordination, containment, remediation, root cause analysis, and post-incident reviews.
- Oversee and enhance IAM architecture and policies, including SSO, SCIM, MFA, RBAC, and user lifecycle management.
- Provide technical leadership in securing IaaS/PaaS and SaaS applications by defining best practices, conducting reviews, and hardening security controls.
- Guide the deployment, integration, and tuning of security tools such as CASB, EDR, DLP, SIEM, CNAPP, and MDM solutions to maximize effectiveness and coverage.
- Lead efforts to identify, triage, prioritize, and support the remediation of vulnerabilities across cloud environments, infrastructure, and SaaS platforms.
- Lead and mentor team members by providing guidance on security best practices, project execution, work review, and knowledge sharing.
- Promote a culture of security-first thinking across engineering, IT, and product teams by driving awareness, training, and secure development practices.
- Track emerging threats, technologies, and regulatory changes; propose and drive forward-looking security strategies to ensure WHOOP maintains a resilient security posture.
- Continuously assess and improve security operations, workflows, and tooling to meet evolving business and security requirements.
- Participate in and help improve the on-call rotation to support critical security incidents, offering guidance and escalation support as needed.
QUALIFICATIONS:
- Bachelor’s degree in Computer Science, Information Security, or a related technical field.
- 6+ years of hands-on experience in Information Security, IT Security, or a related role, including at least 2 years in a senior or lead capacity.
- Proven track record implementing and managing advanced security technologies (e.g., CASB, CNAPP, CSPM, SIEM, SOAR, DLP, SWG).
- Strong understanding of modern cloud security architecture (AWS, Azure, GCP) and experience performing threat modeling and risk assessments on cloud-based systems.
- Demonstrated leadership in security incident response, investigations, and root cause analysis.
- Excellent communication and interpersonal skills with the ability to influence stakeholders and explain security concepts to technical and non-technical audiences.
- Strong project management skills and the ability to drive initiatives to completion in a fast-paced environment.
- Experience mentoring junior engineers and promoting best practices across teams.
- Solid documentation and operational tracking skills with familiarity in tools such as Jira, Confluence, and ticketing systems.
Other Jobs from WHOOP
Software Engineer II (MLOps)
Senior IT Systems Engineer
Staff Electrical Engineer
Senior Data Scientist (Insights)
Similar Jobs
Senior Backend Software Engineer
Senior Software Engineer - Messaging API
Software Engineer - Messaging
Data Engineer
Lead Software Engineer
Software Engineer I
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say