
Director, Security Engineering & Operations
Most applications go out cold — see where you stand first. No sign-up to start.
Don't just apply. Show up ready.
Olive works from this exact posting — no sign-up to start.
At a glance
Job overview
WHOOP seeks a Director of Security Engineering & Operations to lead enterprise security engineering and operations, shaping strategy, guiding managers, engineers, and analysts, and delivering measurable security outcomes across a fast‑moving technology environment.
Skills & qualifications
Skills
Qualifications
Full job description
At WHOOP, we're on a mission to unlock human performance and healthspan. Our technology provides personalized insights that help millions of members better understand their bodies and make informed decisions about performance, recovery, and long-term health. WHOOP is seeking a Director, Security Engineering & Operations to lead the teams responsible for enterprise security engineering and security operations. Reporting directly to the CISO and serving as a senior member of the Security leadership team, this leader will shape strategy, lead a growing team of managers, engineers, and analysts, and drive measurable security outcomes across a fast-moving technology environment. This is a leadership role for someone who has successfully scaled security operations in complex, high-growth environments and brings strong security engineering experience. The right leader combines strategic judgment with strong technical depth, staying close enough to the work to set a high bar for engineering quality, guide critical technical decisions, and lead effectively through significant security events. This leader will play a significant role in shaping the team, operating model, and technical roadmap as WHOOP scales, advancing capabilities across security engineering, detection and response, incident management, security automation, identity, cloud, endpoint, SaaS, data protection, and other enterprise security domains. As WHOOP expands its use of AI across member-facing products, internal technology, and engineering, and continues to evolve its capabilities in health, this leader will help ensure security scales alongside the company's technology, data, regulatory, and threat landscape.
Responsibilities
-
Lead Security Engineering and Security Operations, defining strategy, priorities, technical standards, performance expectations, and measurable outcomes across both functions.
-
Advance a risk and threat-informed detection and response program that connects priority threat scenarios to the telemetry, detections, investigation capabilities, response procedures, and operational controls required to address them, including identity-centric, data protection, and insider risk scenarios.
-
Lead security incident readiness and response, including escalation, incident command for significant events, cross-functional coordination, post-incident review, and accountability for follow-up actions.
-
Guide the engineering and operationalization of preventive and detective security controls across identity, endpoint, cloud, SaaS, infrastructure, data, AI-enabled systems, and other high-value enterprise environments, while setting a high bar for technical design, testing, documentation, maintainability, and lifecycle management.
-
Lead the security strategy and engineering approach for AI-enabled products and enterprise AI adoption, including access controls, sensitive data handling, model and application security, third-party integrations, tool and agent permissions, monitoring, auditability, and secure use of AI across the company.
-
Drive an outcome-oriented approach to security technology and managed services, maximizing the effectiveness of existing capabilities, making disciplined decisions about when to automate, build, buy, or use external partners, and holding security partners accountable to measurable outcomes.
-
Drive disciplined execution across the security engineering and operations portfolio through effective prioritization, roadmap and backlog management, capacity planning, metrics, ownership, and operating cadence.
-
Lead, coach, and develop managers, engineers, and analysts, setting clear expectations for technical quality, judgment, ownership, execution, and professional growth.
-
Strengthen collaboration across Product Security, Security Architecture, Platform, Fraud, Engineering, IT, GRC, Legal, Privacy, and other business functions, creating clear ownership and effective operating relationships across organizational boundaries.
-
Partner with the CISO on organizational design, workforce planning, hiring, and development of the capabilities required as the Security organization evolves, while providing clear, data-driven communication on security posture, operational performance, significant risks, and strategic priorities.
Qualifications
-
10+ years of experience in information security, with deep experience in Security Operations and meaningful experience across Security Engineering in complex technology environments.
-
5+ years of people leadership experience, including multiple years managing managers and senior technical individual contributors. This is not a first-time people leadership role. Demonstrated strength in hiring, coaching, performance management, organizational design, and raising the bar for team quality and execution.
-
Deep technical expertise in detection engineering, SIEM and telemetry strategy, incident response, and modern security operations, including experience leading significant security incidents.
-
Proven ability to drive disciplined execution across priorities, roadmaps, backlogs, metrics, and ownership, while maximizing existing capabilities before introducing additional technology.
-
Experience managing MDR, MSSP, or similar security partners and holding them accountable to measurable operational outcomes.
-
Experience securing AI-enabled products, enterprise AI adoption, or AI development environments, including risks related to sensitive data, models, agents, third-party services, access, and monitoring.
-
Strong judgment and relationship-building skills, with a track record of working effectively across technical, product, risk, legal, and senior leadership teams.
-
Experience in health technology or another sensitive-data environment is a plus. This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.
Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply. WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values. At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company’s long-term growth and success. The U.S. base salary range for this full-time position is $220,000-$245,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training. In addition to the base salary, the successful candidate will also receive benefits and a generous equity package. These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate’s specific qualifications, expertise, and alignment with the role’s requirements.
You've read the whole posting — now see how you match it.