Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Architect image - Rise Careers
Job details

Security Architect

At WHOOP, we're on a mission to unlock human performance. WHOOP empowers members to perform at a higher level through a deeper understanding of their bodies and daily lives.


The Security Architect will be key in developing and implementing a robust security posture that aligns with business objectives. Reporting to the CISO, this role will provide cybersecurity expertise to internal and external stakeholders while moving a high-value threat informed security strategy across the organization.


The successful candidate will promote a 'secure-by-design' approach, working with teams to deliver on best practices and maintain evolving security protections. The ideal candidate will have the right mix of skills, which include effective communication of complex security concepts to various stakeholders, a strategic mindset, deep technical expertise, and the ability to balance risk management with hands-on implementation and operational excellence.


RESPONSIBILITIES:
  • Build and evolve a strong security architecture that is fitting with industry best practices (i.e. NIST, ISO 27001, CIS Controls) and business goals.
  • Conduct regular security assessments, vulnerability analyses, and threat modeling to identify and mitigate risks across the organization
  • Design and enforce security configurations for on-premises and cloud environments (i.e. AWS, Azure, GCP), ensuring compliance with regulatory requirements.
  • Provide strategic guidance and oversight during critical security incidents, serving as a key decision-maker and escalation point for complex and potentially high-impact events.
  • Evaluate, implement, and optimize security tools and endpoint protection to enhance threat detection and response capabilities.
  • Collaborate with business units and cross functional teams to gather security requirements and ensure the effective implementation of controls and enhance secure architectures for established enterprise platforms and business-critical systems.
  • Recommend and help implement changes to the enterprise security ecosystem, including policies, practices, and tools, to mitigate security challenges and improve the overall security posture.
  • Partner with cross-functional teams to integrate security into operational workflows.
  • Partner with application development teams to integrate security into all stages of the Software Development Lifecycle (SDLC) by utilizing appropriate tools and methodologies, while training and coaching development teams on secure coding practices to foster a culture of security within engineering.
  • Collaborate with the CISO to develop security roadmaps aligned with business objectives and security principles.
  • Serve as a key technical advisor and advocate for enhanced security across the organization, collaborating with business units and stakeholders to ensure the effective implementation of security best practices, drive continuous improvement, and enhance the overall security posture.
  • Create, maintain, and communicate appropriate architecture diagrams and technical documentation (e.g., configuration guides, operational procedures) to support the security architecture and transition operational responsibilities of new security tools and processes to appropriate teams.
  • Support the GRC team in Third Party Security Assessments to evaluate feasibility, integrations, and ensure secure implementation of solutions.
  • Stay updated on emerging security trends, technologies, and regulations.


QUALIFICATIONS:
  • 10+ years of experience in information security, with at least 3 years in a security architecture role.
  • Proficiency in securing multi-cloud environments, identity and access management (IAM), zero-trust architectures, and security automation.
  • Expertise in developing and maintaining cybersecurity standards, mapping and tailoring controls, and overseeing security metrics to ensure alignment with security objectives and compliance requirements
  • Proficient knowledge of security frameworks (i.e. ISO27001, NIST Cybersecurity Framework (CSF), PCI DSS, COBIT, MITRE ATT&CK, STRIDE, NIST SP 800-53, CIS Benchmarks), compliance standards (i.e. GDPR, CPRA), and best practices.
  • Experience with security technologies, such as firewalls, WAFs, SIEM, CASB, CSPM, IPS, SWG, CNAPP, SCA, SAST, DAST, and endpoint protection tools.
  • Hands-on experience with cloud platform security (AWS, Azure, or GCP) and PaaS platforms..
  • Strong analytical and problem-solving skills, with the ability to work effectively under pressure.
  • Exceptional verbal and written communication skills to articulate complex security concepts to technical and non-technical stakeholders.
  • Preferably one or more security industry certifications, such as CISSP, CISM, GSEC, CCSK, CCSP, CEH or other relevant industry certifications.
  • Familiarity with emerging security technologies such as AI/ML-based threat detection.
  • Ability to respond to security incidents after hours 
  • Ability to work on premise from our Boston Headquarters 4 days per week.


This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office. 


Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.


WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility.  It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

WHOOP Glassdoor Company Review
3.4 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
WHOOP DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of WHOOP
WHOOP CEO photo
Will Ahmed
Approve of CEO

Average salary estimate

$140000 / YEARLY (est.)
min
max
$120000K
$160000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Architect, WHOOP

At WHOOP, we're all about unlocking human performance, and we're seeking a talented Security Architect to join our innovative team in Boston, MA. This pivotal role revolves around developing and implementing a robust security posture that aligns seamlessly with our business objectives. Reporting directly to the CISO, you'll be the go-to expert on cybersecurity, providing invaluable guidance to both internal and external stakeholders. Your mission? To promote a 'secure-by-design' approach that incorporates security best practices and maintains evolving protections across the organization. We’re looking for someone with a strategic mindset who can effectively communicate complex security concepts to a variety of audiences. As a Security Architect, you'll design and enforce security configurations in both on-premises and cloud environments, conduct regular assessments and threat modeling, and partner with development teams to embed security throughout the Software Development Lifecycle. In addition, you will collaborate with cross-functional teams to gather requirements, optimize security tools, and create comprehensive documentation to support our security architecture. Your expertise will play a crucial role in driving WHOOP's security strategy forward, contributing to a culture of continuous improvement. If you're passionate about cybersecurity and ready to make a difference at a forward-thinking company, we want to hear from you!

Frequently Asked Questions (FAQs) for Security Architect Role at WHOOP
What are the main responsibilities of a Security Architect at WHOOP?

As a Security Architect at WHOOP, you'll be responsible for building and evolving a strong security architecture that adheres to industry best practices while aligning with our business goals. Your duties will include conducting regular security assessments, designing security configurations for cloud and on-premises environments, providing strategic oversight during security incidents, and collaborating with various business units to enhance our security posture.

Join Rise to see the full answer
What qualifications are required for the Security Architect position at WHOOP?

To qualify for the Security Architect role at WHOOP, candidates should have over 10 years of experience in information security, with at least 3 years specifically in a security architecture role. Proficiency in securing multi-cloud environments and in-depth knowledge of various security frameworks and compliance standards are critical. A strong analytical mindset and excellent communication skills are also essential. Security industry certifications such as CISSP or CISM are preferred.

Join Rise to see the full answer
What is the work environment like for a Security Architect at WHOOP?

The work environment for the Security Architect role at WHOOP is collaborative and dynamic. Located in our Boston headquarters, you’ll work closely with cross-functional teams, actively participate in critical security decisions, and have the opportunity to influence the entire security strategy of the organization. With flexible culture and emphasis on teamwork, WHOOP fosters a supportive atmosphere for innovation and growth.

Join Rise to see the full answer
How does WHOOP support professional development for its Security Architects?

WHOOP is committed to professional development, providing opportunities for continuous learning and skill enhancement. As a Security Architect, you will have access to training programs, conferences, and resources to stay updated on emerging security trends and technologies. Mentorship and collaboration with experienced professionals within the organization also contribute to your growth and career advancement.

Join Rise to see the full answer
What types of technologies will a Security Architect work with at WHOOP?

In your role as a Security Architect at WHOOP, you'll gain hands-on experience with various security technologies, such as firewalls, SIEM, endpoint protection tools, and IAM solutions. You'll also work extensively with cloud security platforms like AWS, Azure, and GCP, as well as leverage security automation technologies and zero-trust architectures to enhance WHOOP's cybersecurity framework.

Join Rise to see the full answer
Common Interview Questions for Security Architect
Can you describe your experience with security architecture frameworks?

When answering this question, provide specific frameworks you are familiar with, such as NIST or ISO 27001, and explain how you’ve applied them in previous roles. Highlight your understanding of key concepts like risk management, compliance, and architecture design.

Join Rise to see the full answer
How do you approach conducting threat modeling for a new application?

Discuss your process for identifying potential threats through various methodologies like STRIDE or PASTA. Emphasize the importance of collaboration with development teams to understand application functionalities and ensure that security is built in from the outset.

Join Rise to see the full answer
What strategies would you recommend for implementing zero-trust security?

Explain your understanding of zero-trust principles and provide actionable strategies such as enforcing strict identity verification for all users, segmenting networks, and continuously monitoring for unauthorized access. Using real-world examples can strengthen your response.

Join Rise to see the full answer
How do you ensure compliance with industry regulations in your security architecture?

Detail how you familiarize yourself with applicable regulations, such as GDPR or PCI DSS. Mention your methods for integrating compliance checks into architecture design and emphasize your experience with audits and assessments to validate compliance.

Join Rise to see the full answer
Can you give an example of a challenging security incident you managed?

Share a specific incident where you played a critical role in managing the response. Illustrate the steps you took, the tools you used, and the lessons learned. Highlight your ability to stay calm under pressure and lead a successful resolution.

Join Rise to see the full answer
What tools do you prefer for conducting vulnerability assessments?

Discuss specific assessment tools you have experience with, such as Nessus or Qualys. Explain your rationale for choosing various tools depending on the environment and how you prioritize findings to ensure effective risk management.

Join Rise to see the full answer
How do you communicate security concepts to non-technical stakeholders?

Highlight your communication strategies, such as using simple analogies or visual aids. Emphasize the importance of tailoring your message to different audiences and how this fosters collaboration and understanding in security initiatives.

Join Rise to see the full answer
What steps do you take to stay current with emerging cybersecurity trends?

Share the resources you utilize, such as industry publications, conferences, and professional networks. Mention any certifications or training programs you are pursuing to enhance your knowledge and remain relevant in the field.

Join Rise to see the full answer
How do you evaluate security tools before implementation?

Explain your evaluation process, which may include conducting a needs assessment, reviewing product documentation, and running pilot testing. Discuss how you gather feedback from stakeholders and measure success post-implementation.

Join Rise to see the full answer
What is your experience with integrating security into the Software Development Lifecycle (SDLC)?

Describe successful techniques you've used, such as conducting secure code reviews, providing training on secure coding practices, and defining security requirements early in the SDLC. Emphasize collaboration with development teams to foster a security-first mindset.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
WHOOP Hybrid Boston, MA
Posted 4 days ago
Photo of the Rise User
Posted 3 days ago
Posted 22 hours ago
Posted 13 days ago
Photo of the Rise User
Posted 4 days ago
Photo of the Rise User
BlackStone eIT Remote No location specified
Posted 3 hours ago

Our mission at WHOOP is to unlock human performance. We believe that every individual has an inner potential that can be enhanced through continuous monitoring. As such we've built a system across hardware, software, and analytics designed to coll...

55 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
January 7, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!