Director of Product Security
Generate a McCoy IQ challenge in 30 seconds.
See how candidates think and approach the work this role demands, before the phone screen. We'll build a video challenge from this posting, and you can edit or share it before it goes live.
Key details
Job Description
At WHOOP, we're on a mission to unlock human performance and healthspan. WHOOP empowers members to perform at a higher level and live longer through a deeper understanding of their bodies and daily lives. Protecting our members’ data and ensuring our systems scale securely and reliably is core to this mission.
As a Director of Product Security you will play a critical role in shaping, driving, and leading our software engineering teams towards a secure software development lifecycle and strengthening product-facing identity and authentication capabilities that protect our members. This role will strategically craft the roadmap in collaboration with stakeholders across the business and staff the team to fulfill growing security needs across engineering.
In addition to core product security responsibilities, you will partner closely with functions across Product, Software, Legal, Compliance, and enterprise security to meaningfully move the security posture of the company. We are seeking a leader and strategic partner with prior experience driving the engineering side of security for software teams.
RESPONSIBILITIES
Build, lead, and grow multiple engineering teams executing on product-facing security strategy, including member authentication, code security, cloud security across AWS accounts, privacy by design, and threat modeling.
Lead application vulnerability management programs across bug bounties, code vulnerabilities, container vulnerabilities, and infrastructure vulnerabilities.
Build, integrate, and mature DevSecOps tooling and developer security controls, including SAST, SCA, container scanning, secrets detection, CI/CD security checks, and secure-by-default developer workflows.
Define and communicate long-term product security strategy, product architecture standards, and design principles for product-facing systems.
Partner with engineering, office of the CISO, and compliance leadership to embed privacy and security by design across the software development lifecycle.
Establish and enforce best practices, standards, and processes for secure software development, testing, and deployment.
Provide mentorship, guidance, and career development for engineering managers and individual contributors.
Foster a culture of innovation, teamwork, psychological safety, and continuous learning within the Product Security organization.
QUALIFICATIONS
Demonstrated success scaling a security team whilst crafting clear and efficient team domains.
Proven experience as a technical leader managing multiple teams or a growing security engineering organization.
Experience growing high level individual contributor career growth at the staff level or higher.
Deep understanding of product security principles, including vulnerability management, data privacy, threat modeling, secure SDLC practices,and secure-by-default engineering patterns.
Experience building or integrating developer security tooling to improve secure-by-default practices.
Strong technical background in software development, testing, and deployment processes.
Excellent communication, interpersonal, and leadership skills with the ability to influence across teams and levels.
BONUS QUALIFICATIONS
Experience with AWS cloud environments and data-driven decision-making.
Hands-on experience with containerized microservice environments.
Background in incident response and post-mortem analysis for security events.
Familiarity with automation frameworks for vulnerability scanning, compliance checks, or infrastructure security.
ABOUT YOU
You’re a strategic and people-focused leader who thrives on balancing hands-on technical oversight with long-term organizational growth.
You have experience building and scaling security engineering focused teams.
You’re passionate about creating secure, privacy-first systems that protect member data and enable innovation.
You collaborate effectively across technical and non-technical teams and can operate confidently in both strategic and tactical domains.
Above all, you believe that security enables innovation, and you lead by fostering a culture that supports both speed and safety.
Learn more about our Software Org and how to be successful in your engineering career at WHOOP via our Career Framework.
This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.
Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Audit details(provenance, verification trail, raw fields)
Core fields
whoop:09c99198-208e-476c-9bb1-bd01e67089d9Provenance
whoopVerification trail
This posting hasn't been probed by our closure verifier yet. Stream C runs on a rolling schedule against postings approaching the close-decision threshold.
LLM enrichment
See how we measure for definitions, or our corrections log for known issues. Found something wrong? Flag a correction.
