Director of Product Security

WHOOP - Boston, MA

Hiring: Director of Product Security Company: WHOOP Location: Boston, MA Job Posted Time: 2026-09-12 11:48:42 Target Skills & Keywords : AWS, CI/CD, Microservices, SAST, SCA About the job Required Skills: •Build, lead, and grow multiple engineering teams executing on product-facing security strategy, including member authentication, code security, cloud security across AWS accounts, privacy by design, and threat modeling. •Lead application vulnerability management programs across bug bounties, code vulnerabilities, container vulnerabilities, and infrastructure vulnerabilities. •Build, integrate, and mature DevSecOps tooling and developer security controls, including SAST, SCA, container scanning, secrets detection, CI/CD security checks, and secure-by-default developer workflows. •Define and communicate long-term product security strategy, product architecture standards, and design principles for product-facing systems. •Partner with engineering, office of the CISO, and compliance leadership to embed privacy and security by design across the software development lifecycle. •Establish and enforce best practices, standards, and processes for secure software development, testing, and deployment. •Provide mentorship, guidance, and career development for engineering managers and individual contributors. •Foster a culture of innovation, teamwork, psychological safety, and continuous learning within the Product Security organization. Qualifications: •Demonstrated success scaling a security team whilst crafting clear and efficient team domains. •Proven experience as a technical leader managing multiple teams or a growing security engineering organization. •Comprehensive expertise in product security principles, including vulnerability management, data privacy, threat modeling, secure SDLC practices,and secure-by-default engineering patterns. •Strong technical background in software development, testing, and deployment processes. •Excellent communication, interpersonal, and leadership skills with the ability to influence across teams and levels. •Applied hands-on capability in containerized microservice environments. •Background in incident response and post-mortem analysis for security events. •Operational familiarity with automation frameworks for vulnerability scanning, compliance checks, or infrastructure security. •You’re a strategic and people-focused leader who thrives on balancing hands-on technical oversight with long-term organizational growth. •You have experience building and scaling security engineering focused teams. Compensation: •$220,000 - $270,000 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!