Senior Information Security Engineer
4 days ago
At WHOOP, we're on a mission to unlock human performance. WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives.
WHOOP is seeking a Senior Information Security Engineer to serve as a technical leader in our Security team reporting to our Information Security Manager. In this role, you will drive the deployment and continuous enhancement of controls that protect millions of users' biometric and health data, build scalable defenses across our infrastructure and applications, and lead incident response efforts with visibility across the business. This is an opportunity to have direct impact at scale, working alongside engineers, product teams, and executives to drive forward-looking security strategies.
Responsibilities
- Implement and enhance security controls by leading the deployment, integration, and tuning of solutions such as CNAPP, SIEM, CASB, EDR, DLP, and MDM to maximize effectiveness.
- Support security design decisions by providing subject matter expertise on cloud and SaaS security best practices while influencing architecture led by the Security Architect role.
- Lead incident response and investigations by guiding containment, remediation, root cause analysis, and post-incident improvements.
- Strengthen application security by overseeing secure development practices and managing SAST, SCA, and DAST tooling.
- Advance identity and access management by supporting IAM policy enforcement, SSO, MFA, SCIM, RBAC, and user lifecycle governance.
- Secure AI systems and integrations by assessing and protecting embedded APIs and organizational AI tool usage to ensure resilience, privacy, and compliance.
- Collaborate cross-functionally by working with Engineering, IT, and GRC teams to embed security into systems and workflows.
- Mentor and influence by providing technical guidance, reviewing work, and promoting security-first thinking across the organization.
- Stay ahead of threats and regulations by tracking emerging risks, technologies, and compliance requirements to inform forward-looking strategies.
- Participate in and help improve the on-call rotation by providing guidance, escalation support, and driving improvements in response processes.
Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related technical field and/or advanced certifications (CISSP, CISM, AWS Security Specialty, SANS, etc.).
- 8+ years of hands-on experience in Information Security, IT Security, or a related role, including at least 2 years in a senior or lead capacity.
- Proven track record implementing and managing advanced security technologies (e.g., CASB, CNAPP, CSPM, SIEM, SOAR, DLP, SWG).
- Experience securing AI/ML systems or APIs, including governance of third-party AI integrations and organizational use of AI tools.
- Strong understanding of modern cloud security architecture (AWS, Azure, GCP) and experience performing threat modeling and risk assessments on cloud-based systems.
- Hands-on experience with application security tooling (SAST, SCA, DAST) and embedding secure development practices.
- Demonstrated leadership in security incident response, investigations, and root cause analysis.
- Effective communicator with the ability to influence stakeholders and explain security concepts to technical and non-technical audiences.
- Strong project management skills and the ability to drive initiatives to completion in a fast-paced environment.
- Experience mentoring engineers and setting operational standards.
- Familiarity with compliance and risk frameworks relevant to health and AI (SOC 2, ISO 27001, PCI, GDPR, FTC guidance, HIPAA-adjacent state laws) is a plus.
Interested in the role, but don't meet every qualification? We encourage you to still apply At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
-
Information Security Engineer
15 hours ago
Boston, Massachusetts, United States firstPRO, Inc Full time $120,000 - $200,000 per yearThe Senior Information Security Engineer will serve as a trusted security leader and subject matter expert, partnering closely with the Information Security Manager to advance the firm's cybersecurity strategy, architecture, and operations. This role will take ownership of critical security initiatives, lead the design and enhancement of security programs,...
-
Senior Security Achitect
4 days ago
Boston, Massachusetts, United States GuidePoint Security Full time $120,000 - $180,000 per yearGuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation's top organizations, such as Fortune 500 companies and U.S. government agencies,...
-
RSA - Senior Software Engineer
11 hours ago
Boston, Massachusetts, United States RSA Security Full time $120,000 - $200,000 per year*Location:*Boston, MA (U.S. Citizen Required)*Domain:*Identity and Access Management (IAM), SecurityRSA provides trusted identity and access management for 12,000 organizations around the world, managing 25 million enterprise identities and providing secure, convenient access to millions of users. RSA specializes in empowering security-first organizations in...
-
Information Systems Security Officer
2 days ago
Boston, Massachusetts, United States General Dynamics Information Technology Full time $95,285 - $128,915 per year*Job Description:Type of Requisition:*Regular*Clearance Level Must Currently Possess:*Top Secret/SCI*Clearance Level Must Be Able To Obtain:*Top Secret SCI + Polygraph*Public Trust/Other Required:*None*Job Family:*Cyber and IT Risk Management*Skills:Job Qualifications:*Information Security, Information Security Management, Information System...
-
Senior Security Engineer
4 days ago
Boston, Massachusetts, United States Klaviyo Full time $152,000 - $228,000At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements. If you're a close but not exact match with the...
-
Senior Cyber Security Engineer
2 days ago
Boston, Massachusetts, United States Recorded Future Full time $127,500 - $191,500 per yearWith 1,000+ intelligence professionals serving over 1,900 clients worldwide, Recorded Future is the world's most advanced, and largest, intelligence companyThe Role:Recorded Future supports security teams at some of the most ambitious organizations on the planet. The Senior Cyber Security Engineer - Tech Lead is a function of our Professional Services group,...
-
Boston, Massachusetts, United States American Tower Full time $200,000 - $250,000 per yearJob DescriptionThe TeamWe are seeking a Senior Manager, Information Security Programs and Policies to join American Tower's Information Security organization. The Information Security team is responsible for protecting the confidential, integrity, and availability of American Tower's data and systems in our core systems and platforms. Day to day you will...
-
Senior Information Technology Auditor
2 days ago
Boston, Massachusetts, United States DraftKings Inc. Full time $117,600 - $147,000At DraftKings, AI is becoming an integral part of both our present and future, powering how work gets done today, guiding smarter decisions, and sparking bold ideas. It's transforming how we enhance customer experiences, streamline operations, and unlock new possibilities. Our teams are energized by innovation and readily embrace emerging technology. We're...
-
RSA - Manager 2, Software Engineering
4 days ago
Boston, Massachusetts, United States RSA Security Full time $144,000 - $200,000 per year*Location:*Boston, MA (U.S. Citizen Required)*Domain:*Identity and Access Management (IAM), SecurityRSA provides trusted identity and access management for 12,000 organizations around the world, managing 25 million enterprise identities and providing secure, convenient access to millions of users. RSA specializes in empowering security-first organizations in...
-
RSA - Principal Software Engineer
3 days ago
Boston, Massachusetts, United States RSA Security Full time $140,000 - $250,000 per yearLocation: Boston, MA (U.S. Citizen Required)Domain: Identity and Access Management (IAM), SecurityRSA is seeking a skilled and motivated Principal Software Engineer to help design, develop, and maintain our hybrid cloud and mobile secure identity platform, RSA ID Plus. You will work on building cloud-native, scalable SaaS solutions that solve real-world...