Senior Software Engineering Manager, Product Security

Whoop Whoop · Consumer · Boston, MA · Software

Senior Software Engineering Manager, Product Security at Whoop, responsible for leading multiple engineering teams focused on product security strategy, including authentication, vulnerability management, cloud governance, privacy, and threat modeling. The role also oversees HIPAA compliance readiness and defines long-term security strategy and design principles. Requires proven technical leadership in security or compliance within regulated environments.

What you'd actually do

  1. Build, lead, and grow multiple engineering teams executing on WHOOP’s product security strategy, including member authentication, vulnerability management, cloud governance, privacy rights fulfillment, and threat modeling.
  2. Oversee and drive WHOOP’s engineering readiness for HIPAA compliance, coordinating technical implementation, evidence collection, and ongoing governance activities across teams.
  3. Define and communicate long-term security strategy, architecture, and design principles for product-facing systems.
  4. Partner with engineering and compliance leadership to embed security and privacy by design across the software development lifecycle.
  5. Establish and enforce best practices, standards, and processes for secure software development, testing, and deployment.

Skills

Required

  • Technical leadership managing multiple teams or a growing security engineering organization
  • Growing high level individual contributor career growth at the staff level or higher
  • Leading security or compliance initiatives in a regulated environment, preferably HIPAA or other health data compliance frameworks
  • Deep understanding of product security principles, including vulnerability management, data privacy, threat modeling, and secure software development
  • Building or integrating developer security tooling to improve secure-by-default practices
  • Strong technical background in software development, testing, and deployment processes
  • Excellent communication, interpersonal, and leadership skills

Nice to have

  • Experience with AWS cloud environments
  • Hands-on experience with infrastructure and cloud security in containerized environments (e.g., Docker, Kubernetes)
  • Background in incident response and post-mortem analysis for security events
  • Familiarity with automation frameworks for vulnerability scanning, compliance checks, or infrastructure security
  • Prior experience scaling a product security or compliance engineering organization through major regulatory transitions (e.g., SOC 2 → HIPAA, or HIPAA → HITRUST)

What the JD emphasized

  • HIPAA compliance
  • regulated environment
  • security and privacy by design