WHOOP

Director, Information Security

WHOOP$190K — $220K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in information security or related fields, including 5+ years in a managerial role
  • Proven track record in developing and mentoring high-performing security teams
  • Experience managing security incidents and crisis communication effectively
  • Familiarity with partnering with managed security service providers
  • Ability to navigate complex, high-growth environments while prioritizing tasks
  • Experience in designing security programs focused on metrics and automation
  • Knowledge of regulatory frameworks including HIPAA, GDPR, and AI compliance

Responsibilities

  • Lead the Information Security function with a focus on security engineering and operations
  • Translate regulatory requirements into effective technical controls in collaboration with Security Architecture
  • Own security operations including incident management and operational readiness
  • Establish and maintain standard operating procedures and metrics for security operations
  • Oversee security posture for enterprise AI technologies and secure adoption of workflows
  • Manage information security managers, setting performance expectations and facilitating team growth
  • Collaborate with GRC and Legal for audits and communicate risk posture to senior leadership

Benefits

  • Competitive base salary and generous equity package
  • Focus on total compensation, aligning employees with company success
  • Relocation support for candidates moving to the Boston office
  • Inclusive recruitment practices that value character and potential
  • Dynamic team environment fostering professional growth opportunities
Full Job Description
WHOOP is seeking a Director of Information Security to lead the execution of the company's security engineering and security operations capabilities. This role is accountable for delivering reliable, scalable security programs aligned with business and regulatory requirements in a growing, regulated technology environment.

The Director of Information Security will manage an existing security team, oversee the operating model for security engineering and ops, and partner closely with Product Security, Security Architecture, Engineering, IT, GRC, and Legal. This role carries direct accountability for team performance and operational outcomes and is expected to drive execution through metrics, documented processes, and automation.

RESPONSIBILITIES:
  • Lead the Information Security function with accountability for security engineering delivery, day-to-day security operations, and the evolving operating model as WHOOP grows and regulatory and risk requirements change
  • Translate regulatory, privacy, and risk requirements into effective, auditable technical controls, partnering with Security Architecture to ensure execution aligns with secure-by-design principles and target-state architecture
  • Own security operations including detection, response, escalation, incident follow-up, and operational readiness, serving as Incident Commander during security events and acting as on-call executive escalation outside of business hours as needed, coordinating internal teams, external partners, and managed security service providers
  • Establish and maintain standard operating procedures, metrics, automation, and process improvements to measure effectiveness, reduce risk, and scale security operations reliably
  • Own the security posture for enterprise and internal use of AI technologies, including guardrails for access, data handling, monitoring, auditability, and the secure adoption of AI-enabled workflows in partnership with Architecture, Product Security, IT, and Legal
  • Directly manage information security managers and senior individual contributors, setting clear expectations for performance, documentation, and accountability, and partnering with the CISO on hiring strategy, team growth, and capability development
  • Partner with GRC and Legal to support audits, assessments, and regulatory obligations, providing technical evidence and subject-matter expertise, and communicate clearly with senior leadership on risk posture, priorities, and program progress

QUALIFICATIONS:
  • 10+ years of experience in information security, security engineering, or security operations, including 5+ years managing managers and senior individual contributors; this role is not intended for first-time people managers
  • Demonstrated experience hiring, developing, and holding high-performing security teams accountable through measurable goals, repeatable processes, and clear documentation
  • Proven leadership during high-impact security incidents and crisis situations, including coordination across internal teams and external partners
  • Experience partnering with managed security service providers to drive consistent, outcome-based security operations
  • Strong ability to prioritize effectively and drive execution in complex, high-growth environments
  • Experience designing, building, or scaling security programs grounded in metrics, automation, and operational rigor
  • Familiarity with regulatory frameworks including HIPAA, GDPR, PCI, and emerging AI-related compliance requirements
  • Experience supporting healthcare, biometric, or other health-adjacent data environments is preferred
  • Background in high-growth technology organizations is preferred
  • Security certifications such as CISSP, CISM, or equivalent are a plus

This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.

Interested in the role, but don't meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.

The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.

At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company's long-term growth and success.

The U.S. base salary range for this full-time position is $190,000-$220,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training.

In addition to the base salary, the successful candidate will also receive benefits and a generous equity package.

These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate's specific qualifications, expertise, and alignment with the role's requirements.

About WHOOP

WHOOP is a wearable technology company that specializes in fitness tracking. The company was founded in 2012 and is based in Boston, Massachusetts. WHOOP's flagship product is a wristband that tracks various metrics related to fitness and health, such as heart rate variability, sleep quality, and recovery time. The company also offers a subscription service that provides personalized insights and recommendations based on the data collected by the wristband. WHOOP has raised over $200 million in funding and has partnerships with several professional sports leagues and teams.
Learn more about WHOOP
Size
500 employees
Industry
Founded
2011

Similar Jobs

More Jobs at WHOOP

More Information Technology Jobs

Find similar Director, Information Security jobs: