Incident Response Lead

Whoop

3h ago • 1 views • 0 applications
Full-time On-site
Boston, MA
Competitive
Full-time
Incident Response

Job Description

Incident Response Lead

At WHOOP, our mission is to unlock and inspire peak performance for life. We're seeking a highly skilled and proactive Incident Response Lead to be the frontline defender of our enterprise security. This is an unparalleled opportunity for a hands-on technical expert to own and drive security incident response, acting as the primary internal escalation point and pivotal resolver for all security incidents.

You'll thrive in this highly technical individual contributor role, wielding significant ownership and visibility across Security, IT, GRC, and Legal. Partner closely with our 24x7 SOC provider and cross-functional stakeholders to swiftly investigate, contain, and remediate sophisticated threats, ensuring WHOOP's systems and data remain secure.

What You'll Do:

Lead the Charge: Serve as the primary internal escalation point, orchestrating hands-on incident response activities from detection through resolution.
Command and Control: Act as the central incident commander, coordinating efforts across Security, IT, GRC, and Legal during active incidents.
Strategic Partnership: Collaborate with our SOC provider to validate alerts, guide forensic investigations, and execute containment and eradication strategies.
Deep Investigations: Conduct comprehensive host, cloud, and log-based investigations, engaging external forensic firms when complex expertise is required.
Evolve & Optimize: Continuously refine and improve incident response playbooks, escalation procedures, and critical communication workflows.
Learn & Adapt: Lead post-incident reviews and root cause analysis, meticulously defining and tracking remediation actions to prevent recurrence.
Fortify Defenses: Develop and execute rigorous tabletop exercises and incident simulations to test and strengthen our organizational response readiness.
Compliance & Reporting: Partner with GRC and Legal to support breach impact assessments and navigate regulatory notification processes (GDPR, HIPAA, PCI, etc.).
Innovate & Enhance: Drive continuous improvement of our detection and response capabilities across SIEM, EDR, cloud monitoring, and identity systems.
Metrics & Insights: Own incident metrics and reporting, tracking response times, identifying trends, and championing systemic risk reduction initiatives.
Always Ready: Participate in an on-call escalation rotation, providing critical after-hours incident leadership as needed.

What You'll Bring:

7+ years of dedicated experience in incident response, digital forensics, threat detection, or SOC operations.
Proven track record of successfully leading incident investigations within complex, cloud-native environments.
Extensive hands-on experience conducting host, cloud, and log-based investigations.
Expertise with leading SIEM platforms, EDR tools, and cloud security monitoring solutions.
Experience collaborating effectively with external SOC or MDR providers.
Strong understanding of modern attack frameworks (e.g., MITRE ATT&CK) and their practical application to detection and response.
Experience supporting breach response obligations under frameworks like GDPR, HIPAA, PCI, or similar regulatory requirements.
Exceptional communication skills, with a demonstrated ability to coordinate diverse cross-functional stakeholders under pressure.
Bachelor’s degree or relevant industry certifications (GCIH, GCFA, CISSP, or equivalent) are highly valued.

This pivotal role is based in our vibrant WHOOP office in Boston, MA. Candidates must be prepared to relocate if necessary to join us in person.

Are you interested in this role but perhaps don't meet every single qualification? We strongly encourage you to apply! At WHOOP, we believe that character, potential, and diverse perspectives are just as crucial as experience. As we continue to build an inclusive environment, we welcome all passionate individuals to consider joining our team.

WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility.

Our compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.

At WHOOP, total compensation encompasses a competitive base salary, robust benefits, and a generous equity package. We believe equity is a key differentiator, aligning our employees with the long-term success of the company and allowing every member of our corporate team to own a piece of WHOOP and share in its growth.

The U.S. base salary range for this full-time position is $130,000 - $170,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training.

While most offers will typically fall toward the starting point of the range, total compensation will ultimately depend on the candidate’s specific qualifications, expertise, and alignment with the role’s comprehensive requirements.

CyberJob.app

Your trusted source for cybersecurity job opportunities worldwide.


© 2026 CyberJob.app. All rights reserved.