Requirements
10+ years of experience in information security, with at least 3 years in a security architecture role.Proficiency in securing multi-cloud environments, identity and access management (IAM), zero-trust architectures, and security automation.Expertise in developing and maintaining cybersecurity standards, mapping and tailoring controls, and overseeing security metrics to ensure alignment with security objectives and compliance requirementsProficient knowledge of security frameworks (i.e. ISO27001, NIST Cybersecurity Framework (CSF), PCI DSS, COBIT, MITRE ATT&CK, STRIDE, NIST SP 800-53, CIS Benchmarks), compliance standards (i.e. GDPR, CPRA), and best practices.Experience with security technologies, such as firewalls, WAFs, SIEM, CASB, CSPM, IPS, SWG, CNAPP, SCA, SAST, DAST, and endpoint protection tools.Hands-on experience with cloud platform security (AWS, Azure, or GCP) and PaaS platforms..Strong analytical and problem-solving skills, with the ability to work effectively under pressure.Exceptional verbal and written communication skills to articulate complex security concepts to technical and non-technical stakeholders.Preferably one or more security industry certifications, such as CISSP, CISM, GSEC, CCSK, CCSP, CEH or other relevant industry certifications.Familiarity with emerging security technologies such as AI/ML-based threat detection.Ability to respond to security incidents after hours Ability to work on premise from our Boston Headquarters 4 days per week.This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office. Interested in the role, but don’t meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.