Director of Product Security

WhoopBoston, MA
Onsite

About The Position

At WHOOP, we're on a mission to unlock human performance and healthspan. WHOOP empowers members to perform at a higher level and live longer through a deeper understanding of their bodies and daily lives. Protecting our members’ data and ensuring our systems scale securely and reliably is core to this mission. As a Director of Product Security you will play a critical role in shaping, driving, and leading our software engineering teams towards a secure software development lifecycle and strengthening product-facing identity and authentication capabilities that protect our members. This role will strategically craft the roadmap in collaboration with stakeholders across the business and staff the team to fulfill growing security needs across engineering. In addition to core product security responsibilities, you will partner closely with functions across Product, Software, Legal, Compliance, and enterprise security to meaningfully move the security posture of the company. We are seeking a leader and strategic partner with prior experience driving the engineering side of security for software teams.

Requirements

  • Demonstrated success scaling a security team whilst crafting clear and efficient team domains.
  • Proven experience as a technical leader managing multiple teams or a growing security engineering organization.
  • Experience growing high level individual contributor career growth at the staff level or higher.
  • Deep understanding of product security principles, including vulnerability management, data privacy, threat modeling, secure SDLC practices,and secure-by-default engineering patterns.
  • Experience building or integrating developer security tooling to improve secure-by-default practices.
  • Strong technical background in software development, testing, and deployment processes.
  • Excellent communication, interpersonal, and leadership skills with the ability to influence across teams and levels.

Nice To Haves

  • Experience with AWS cloud environments and data-driven decision-making.
  • Hands-on experience with containerized microservice environments.
  • Background in incident response and post-mortem analysis for security events.
  • Familiarity with automation frameworks for vulnerability scanning, compliance checks, or infrastructure security.

Responsibilities

  • Build, lead, and grow multiple engineering teams executing on product-facing security strategy, including member authentication, code security, cloud security across AWS accounts, privacy by design, and threat modeling.
  • Lead application vulnerability management programs across bug bounties, code vulnerabilities, container vulnerabilities, and infrastructure vulnerabilities.
  • Build, integrate, and mature DevSecOps tooling and developer security controls, including SAST, SCA, container scanning, secrets detection, CI/CD security checks, and secure-by-default developer workflows.
  • Define and communicate long-term product security strategy, product architecture standards, and design principles for product-facing systems.
  • Partner with engineering, office of the CISO, and compliance leadership to embed privacy and security by design across the software development lifecycle.
  • Establish and enforce best practices, standards, and processes for secure software development, testing, and deployment.
  • Provide mentorship, guidance, and career development for engineering managers and individual contributors.
  • Foster a culture of innovation, teamwork, psychological safety, and continuous learning within the Product Security organization.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service