At WHOOP, we're on a mission to unlock human performance. WHOOP empowers people to perform at a higher level through a deeper understanding of their bodies and daily lives. We handle massive amounts of data continuously streaming up to the cloud collected from the worlds greatest sports teams and athletes mandating a fault-tolerant and highly available product. With such sensitive data we carry an immense responsibility to securely manage our members data.
Our Cybersecurity team is located within the Platform organization. Our work is at the intersection of security, privacy, cloud excellence, developer experience and product development. We are responsible for building foundational software services and libraries that enable our backend engineers to develop compliant applications securely. We provide cybersecurity for existing applications as well as enable new business capabilities by getting security and privacy requirements met during the engineering process.
A successful candidate for this position should have experience in software engineering, data privacy, and exposure to cybersecurity systems and practices. Ideally they would also have familiarity with public cloud management.
RESPONSIBILITIES:
- Design, develop, and maintain software applications to ensure compliance with data privacy regulations.
- Work in a cross functional team that works closely with multiple teams including, Software, Product, InfoSec, GRC, IT and Legal
- Collaborate with engineers to maintain and continually improve existing privacy tools
- Manage and improve Transcend system that governs our compliance with data privacy regulations
- Be creative and solve problems with solutions that can scale
- Review and contribute to application designs and solutions that span code and infrastructure
- Identify and define application security requirements and security baselines
- Maintain knowledge of current and emerging secure application technologies/products/trends
QUALIFICATIONS:
- 5+ years of proven and extensive Software Engineering experience developing and maintaining scalable, cloud-native software solutions
- 1+ years of experience in data privacy and/or information security - we are open to a diverse set of backgrounds
- Proven and extensive experience in building RESTful APIs and background workers in Java, C#, go or rust
- Proven and extensive experience in secure software development principles
- Hands-on experience with compliance programs
- Hands-on experience with permission systems
- Hands-on experience working with DevOps and Agile-driven product teams
- You have excellent written and verbal communication skills
- You thrive in a fast paced and data driven environment
- You are a team player who thrives on continuous learning and direct feedback
WE WOULD LOVE TO SEE:
- Hands-on experience with systems governing GDPR compliance and customer data rights
- Hands-on experience in a Bug Bounty program (either triaging bugs or submitting bugs)
- Hands-on experience with Security observability tools for alarming, diagnostic and forensic use cases
- Hands-on experience with Policy As Code such as Open Policy Agent, AWS Cedar or Hashicorp Sentinel
- Hands-on experience with Infrastructure As Code such as AWS CDK and Terraform
Find out more about us: "WHOOP Software Principles"
This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.
Interested in the role, but dont meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility