Security Architect

WHOOP - Boston, MA

Hiring: Security Architect Company: WHOOP Location: Boston, MA Job Posted Time: 2026-09-10 11:48:42 Target Skills & Keywords : AWS, HIPAA, PCI DSS, SOC 2 About the job Experience: •12+ years of experience in security architecture, application security, cloud security, infrastructure security, or senior security engineering roles supporting modern distributed systems. Required Skills: •Partner with Engineering, Product, Infrastructure, IT, and Security teams to provide architectural guidance throughout the software development lifecycle, ensuring security is incorporated early into design decisions. •Help establish and mature WHOOP's Security Architecture practice by defining architecture governance, review methodologies, security standards, and engagement models that scale with the organization. •Develop and maintain security architecture principles, standards, reference architectures, and reusable design patterns that enable engineering teams to build secure systems consistently. •Review application, cloud, infrastructure, AI, and enterprise technology initiatives to identify architectural risks, validate security controls, and recommend practical mitigation strategies. •Lead architecture reviews and collaborate with engineering teams on threat models, trust boundaries, data flows, identity patterns, secure service-to-service communications, and security design decisions. •Provide technical leadership across application security, cloud security, infrastructure security, API security, identity and access management, secrets management, network security, and data protection. •Work closely with Product Security, Infrastructure Security, and Engineering teams to establish consistent security expectations across new products, internal platforms, and third-party integrations. •Evaluate the security architecture of strategic vendors and technology solutions as part of WHOOP's Third-Party Risk Assessment process. Qualifications: •8–12+ years of experience in security architecture, application security, cloud security, infrastructure security, or senior security engineering roles supporting modern distributed systems. •Demonstrated experience designing and securing cloud-native applications and infrastructure, with deep knowledge of AWS security services and modern cloud architecture. •In-depth knowledge of application security, secure software development, infrastructure security, cloud security, API security, identity and access management, enterprise networking, and modern security architecture principles. •Previous software engineering or application development experience with the ability to understand application design, architecture, implementation tradeoffs, and engineering workflows. •Operational familiarity with healthcare, regulated environments, or security programs supporting HIPAA, PCI DSS, ISO 27001, SOC 2, NIST 800-53, or similar regulatory and compliance frameworks. •Demonstrated capacity to balance security requirements with business objectives and provide practical, risk-based recommendations that engineering teams can successfully implement. •Exceptional interpersonal, written, and verbal communication skills with a proven ability to build trust, influence technical decisions, and collaborate effectively across engineering, product, IT, and security organizations. •A collaborative, approachable, and service-oriented mindset with the ability to establish strong working relationships across teams and become a trusted partner to engineers and technical leaders. •Comfortable working independently while helping establish new security processes, standards, governance models, and architectural practices in a growing organization. •High integrity, sound judgment, intellectual curiosity, and a pragmatic, solution-oriented approach to solving complex security challenges. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!