Security Architect
WHOOP · Boston, MA · 1 wk ago
On-siteInformation Technology$155k–$195k/yrFull-time
Responsibilities
- Partner with Engineering, Product, Infrastructure, IT, and Security teams to provide architectural guidance throughout the software development lifecycle, ensuring security is incorporated early into design decisions.
- Help establish and mature WHOOP's Security Architecture practice by defining architecture governance, review methodologies, security standards, and engagement models that scale with the organization.
- Develop and maintain security architecture principles, standards, reference architectures, and reusable design patterns that enable engineering teams to build secure systems consistently.
- Review application, cloud, infrastructure, AI, and enterprise technology initiatives to identify architectural risks, validate security controls, and recommend practical mitigation strategies.
- Lead architecture reviews and collaborate with engineering teams on threat models, trust boundaries, data flows, identity patterns, secure service-to-service communications, and security design decisions.
- Provide technical leadership across application security, cloud security, infrastructure security, API security, identity and access management, secrets management, network security, and data protection.
- Work closely with Product Security, Infrastructure Security, and Engineering teams to establish consistent security expectations across new products, internal platforms, and third-party integrations.
- Evaluate the security architecture of strategic vendors and technology solutions as part of WHOOP's Third-Party Risk Assessment process.
- Translate regulatory and compliance requirements—including HIPAA, PCI DSS, ISO 27001, SOC 2, and NIST frameworks—into practical engineering guidance and architectural controls.
- Mentor engineers and security team members on secure design principles, helping raise the organization's overall security maturity through collaboration, education, and trusted technical leadership.
- Produce clear architectural documentation, technical standards, design reviews, and implementation guidance that can be consistently applied across engineering teams.
- Partner with Security leadership to define the long-term vision, operating model, roadmap, and success metrics for Security Architecture as a strategic capability within the Information Security organization.
- Serve as a trusted advisor to engineering and business leaders, balancing security, operational efficiency, and business objectives while promoting a secure-by-design culture across WHOOP.
Qualifications
- 8–12+ years of experience in security architecture, application security, cloud security, infrastructure security, or senior security engineering roles supporting modern distributed systems.
- Demonstrated experience designing and securing cloud-native applications and infrastructure, with deep knowledge of AWS security services and modern cloud architecture.
- Strong understanding of application security, secure software development, infrastructure security, cloud security, API security, identity and access management, enterprise networking, and modern security architecture principles.
- Previous software engineering or application development experience with the ability to understand application design, architecture, implementation tradeoffs, and engineering workflows.
- Experience performing architecture reviews, security design assessments, and threat modeling for complex distributed systems.
- Familiarity with healthcare, regulated environments, or security programs supporting HIPAA, PCI DSS, ISO 27001, SOC 2, NIST 800-53, or similar regulatory and compliance frameworks.
- Ability to balance security requirements with business objectives and provide practical, risk-based recommendations that engineering teams can successfully implement.
- Exceptional interpersonal, written, and verbal communication skills with a proven ability to build trust, influence technical decisions, and collaborate effectively across engineering, product, IT, and security organizations.
- A collaborative, approachable, and service-oriented mindset with the ability to establish strong working relationships across teams and become a trusted partner to engineers and technical leaders.
- Comfortable working independently while helping establish new security processes, standards, governance models, and architectural practices in a growing organization.
- High integrity, sound judgment, intellectual curiosity, and a pragmatic, solution-oriented approach to solving complex security challenges.
- Professional security certifications such as CISSP, CCSP, AWS Certified Security – Specialty, GIAC, TOGAF, or equivalent are considered a plus.