Security Architect

Posted 5 Days Ago
Be an Early Applicant
Boston, MA, USA
Hybrid
155K-195K Annually
Expert/Leader
Fitness • Hardware • Healthtech • Sports • Wearables
Power your performance with 24/7 data
The Role
Build and mature WHOOP’s Security Architecture practice by establishing governance, standards, reference architectures, and reusable security patterns. Provide architectural guidance across application, cloud, infrastructure, API, identity, networking, AI, and enterprise systems. Lead threat modeling and architecture reviews, assess vendor security, translate compliance requirements into engineering controls, mentor teams, document guidance, and advise leaders on security strategy and risk-based decisions.
Summary Generated by Built In

At WHOOP, we're on a mission to unlock human performance and healthspan. Our wearable technology provides personalized insights that help millions of members better understand their bodies, and make smarter decisions about training, recovery, and lifestyle.

WHOOP is seeking a Security Architect to help build and scale the Security Architecture function within the Information Security organization. This role will play a foundational part in defining how security architecture is practiced across the company by establishing standards, governance, reusable design patterns, and trusted partnerships with engineering teams.

The successful candidate will bring broad technical expertise across application, infrastructure, cloud, and enterprise security while building strong relationships throughout the organization. They will help create practical security standards, influence technical strategy, mentor engineering teams, and enable the business to move quickly without compromising security. This role requires someone who enjoys working with people as much as solving technical problems and can translate complex security concepts into clear, actionable guidance. Working closely with the Security Architecture Lead and the broader CISO organization, this individual will help shape the long-term vision and operating model for Security Architecture at WHOOP.

RESPONSIBILITIES
  • Partner with Engineering, Product, Infrastructure, IT, and Security teams to provide architectural guidance throughout the software development lifecycle, ensuring security is incorporated early into design decisions.

  • Help establish and mature WHOOP's Security Architecture practice by defining architecture governance, review methodologies, security standards, and engagement models that scale with the organization.

  • Develop and maintain security architecture principles, standards, reference architectures, and reusable design patterns that enable engineering teams to build secure systems consistently.

  • Review application, cloud, infrastructure, AI, and enterprise technology initiatives to identify architectural risks, validate security controls, and recommend practical mitigation strategies.

  • Lead architecture reviews and collaborate with engineering teams on threat models, trust boundaries, data flows, identity patterns, secure service-to-service communications, and security design decisions.

  • Provide technical leadership across application security, cloud security, infrastructure security, API security, identity and access management, secrets management, network security, and data protection.

  • Work closely with Product Security, Infrastructure Security, and Engineering teams to establish consistent security expectations across new products, internal platforms, and third-party integrations.

  • Evaluate the security architecture of strategic vendors and technology solutions as part of WHOOP's Third-Party Risk Assessment process.

  • Translate regulatory and compliance requirements—including HIPAA, PCI DSS, ISO 27001, SOC 2, and NIST frameworks—into practical engineering guidance and architectural controls.

  • Mentor engineers and security team members on secure design principles, helping raise the organization's overall security maturity through collaboration, education, and trusted technical leadership.

  • Produce clear architectural documentation, technical standards, design reviews, and implementation guidance that can be consistently applied across engineering teams.

  • Partner with Security leadership to define the long-term vision, operating model, roadmap, and success metrics for Security Architecture as a strategic capability within the Information Security organization.

  • Serve as a trusted advisor to engineering and business leaders, balancing security, operational efficiency, and business objectives while promoting a secure-by-design culture across WHOOP.

QUALIFICATIONS
  • 8–12+ years of experience in security architecture, application security, cloud security, infrastructure security, or senior security engineering roles supporting modern distributed systems.

  • Demonstrated experience designing and securing cloud-native applications and infrastructure, with deep knowledge of AWS security services and modern cloud architecture.

  • Strong understanding of application security, secure software development, infrastructure security, cloud security, API security, identity and access management, enterprise networking, and modern security architecture principles.

  • Previous software engineering or application development experience with the ability to understand application design, architecture, implementation tradeoffs, and engineering workflows.

  • Experience performing architecture reviews, security design assessments, and threat modeling for complex distributed systems.

  • Familiarity with healthcare, regulated environments, or security programs supporting HIPAA, PCI DSS, ISO 27001, SOC 2, NIST 800-53, or similar regulatory and compliance frameworks.

  • Ability to balance security requirements with business objectives and provide practical, risk-based recommendations that engineering teams can successfully implement.

  • Exceptional interpersonal, written, and verbal communication skills with a proven ability to build trust, influence technical decisions, and collaborate effectively across engineering, product, IT, and security organizations.

  • A collaborative, approachable, and service-oriented mindset with the ability to establish strong working relationships across teams and become a trusted partner to engineers and technical leaders.

  • Comfortable working independently while helping establish new security processes, standards, governance models, and architectural practices in a growing organization.

  • High integrity, sound judgment, intellectual curiosity, and a pragmatic, solution-oriented approach to solving complex security challenges.

  • Professional security certifications such as CISSP, CCSP, AWS Certified Security – Specialty, GIAC, TOGAF, or equivalent are considered a plus.

This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.

Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.

WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility

The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.

At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company’s long-term growth and success.

The U.S. base salary range for this full-time position is $155,000 - $195,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training.

In addition to the base salary, the successful candidate will also receive benefits and a generous equity package.

These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate’s specific qualifications, expertise, and alignment with the role’s requirements.

Skills Required

  • 8-12+ years of experience in security architecture, application security, cloud security, infrastructure security, or senior security engineering roles supporting modern distributed systems
  • Experience designing and securing cloud-native applications and infrastructure
  • Deep knowledge of AWS security services and modern cloud architecture
  • Strong understanding of application security, secure software development, infrastructure security, cloud security, API security, identity and access management, enterprise networking, and security architecture principles
  • Previous software engineering or application development experience
  • Experience conducting architecture reviews, security design assessments, and threat modeling for complex distributed systems
  • Familiarity with healthcare, regulated environments, HIPAA, PCI DSS, ISO 27001, SOC 2, NIST 800-53, or similar frameworks
  • Ability to balance security requirements with business objectives and provide practical, risk-based recommendations
  • Exceptional interpersonal, written, and verbal communication skills
  • Ability to build trust and collaborate across engineering, product, IT, and security organizations
  • Collaborative, approachable, and service-oriented mindset
  • Ability to work independently while establishing security processes, standards, governance models, and architectural practices
  • High integrity, sound judgment, intellectual curiosity, and pragmatic problem-solving approach
  • CISSP, CCSP, AWS Certified Security Specialty, GIAC, TOGAF, or equivalent certification

What the Team is Saying

Josh
Manan Dedhia
Anahis

WHOOP Compensation & Benefits Highlights

  • Parental & Family Support Paid parental leave is listed at 18 weeks with an additional 2‑week transition period, signaling strong support for new parents. This depth stands out relative to typical packages highlighted in the materials.
  • Wellbeing & Lifestyle Benefits Medical, dental, and vision coverage are paired with a $500 annual wellness stipend, a free WHOOP membership plus one to gift, daily meals at the Boston HQ, and access to a gym and recovery tools. These health‑aligned perks reinforce a recovery‑first total rewards philosophy.
  • Equity Value & Accessibility Roles are described as eligible for stock options alongside salary, indicating accessible ownership as part of total rewards. This equity component is consistently highlighted in company materials and third‑party summaries.

WHOOP Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
500 Employees
Year Founded: 2012

What We Do

At WHOOP, we’re on a mission to unlock human performance. WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives. Our wearable device and performance optimization platform has been adopted by many of the world's greatest athletes and consumers alike.

Why Work With Us

At WHOOP, we’re focused on building an inclusive and equitable team with a strong sense of belonging for everyone—increasing representation in every way as our team grows. We believe that our differences are our source of strength—so much so it’s one of our core values.


Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

WHOOP Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: 4 days a week
HQBoston, MA
Limerick, Limerick, V94 4D83 Ireland
Learn more

Similar Jobs

WHOOP Logo WHOOP

Manager, Immigration & Global Mobility

Fitness • Hardware • Healthtech • Sports • Wearables
Hybrid
Boston, MA, USA
500 Employees
125K-150K Annually

WHOOP Logo WHOOP

Director, Data Governance

Fitness • Hardware • Healthtech • Sports • Wearables
Hybrid
Boston, MA, USA
500 Employees
190K-230K Annually

WHOOP Logo WHOOP

Director, Enablement- Membership Services

Fitness • Hardware • Healthtech • Sports • Wearables
Hybrid
Boston, MA, USA
500 Employees
130K-175K Annually

WHOOP Logo WHOOP

Senior Product Manager

Fitness • Hardware • Healthtech • Sports • Wearables
Hybrid
Boston, MA, USA
500 Employees
155K-215K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account