WHOOP

Incident Response Lead

WHOOP$130K — $170K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in incident response, digital forensics, or SOC operations
  • Proven leadership in complex, cloud-native incident investigations
  • Hands-on expertise with host, cloud, and log-based investigations
  • Strong working knowledge of SIEM platforms and EDR tools
  • Experience coordinating with external SOC or MDR providers
  • Familiarity with attack frameworks like MITRE ATT&CK
  • Knowledge of breach response obligations under GDPR, HIPAA, PCI
  • Excellent communication skills for cross-functional coordination
  • Bachelor's degree or relevant certifications (GCIH, GCFA, CISSP, or equivalent)

Responsibilities

  • Lead hands-on incident response activities and serve as the primary escalation point
  • Act as the incident commander across Security, IT, GRC, and Legal during security incidents
  • Collaborate with the SOC to validate alerts and guide investigations
  • Conduct investigations and coordinate with external forensic firms when needed
  • Maintain and improve incident response playbooks and communication workflows
  • Lead post-incident reviews and ensure clear tracking of remediation actions
  • Develop and execute tabletop exercises to enhance incident response readiness
  • Drive continuous improvement of detection capabilities across various systems
  • Own incident metrics reporting and respond to trends and risks
  • Participate in on-call rotation for after-hours incident leadership

Benefits

  • Generous equity package aligned with long-term success
  • Diverse and inclusive work environment
  • Encouragement for candidates who meet some but not all requirements to apply
  • Collaborative culture focused on character as well as experience
Full Job Description
We are seeking a Incident Response Lead to drive security incident response across the enterprise. In this role, you will serve as the primary internal escalation point and hands-on responder for security incidents, partnering closely with WHOOP's 24x7 SOC provider and cross-functional stakeholders to investigate, contain, and remediate threats.

This is a highly technical individual contributor role with significant ownership and visibility across Security, IT, GRC, and Legal.

RESPONSIBILITIES:
  • Lead hands-on incident response activities, serving as the primary internal escalation point for security events
  • Serve as the central incident commander across Security, IT, GRC, and Legal during active incidents
  • Partner with the SOC to validate alerts, guide investigations, and drive containment and eradication efforts
  • Conduct host, cloud, and log-based investigations, and coordinate with external forensic firms when needed
  • Maintain and continuously improve incident response playbooks, escalation procedures, and communication workflows
  • Lead post-incident reviews and root cause analysis, ensuring remediation actions are clearly defined and tracked
  • Develop and execute tabletop exercises and incident simulations to test and strengthen response readiness
  • Partner with GRC and Legal to support breach impact assessments and regulatory notification processes
  • Drive continuous improvement of detection and response capabilities across SIEM, EDR, cloud monitoring, and identity systems
  • Own incident metrics and reporting, including response times, trends, and systemic risk reduction initiatives
  • Participate in an on-call escalation rotation to provide after-hours incident leadership when required

QUALIFICATIONS:
  • 7+ years of experience in incident response, digital forensics, threat detection, or SOC operations
  • Proven experience leading incident investigations in complex, cloud-native environments
  • Strong experience conducting host, cloud, and log-based investigations
  • Hands-on expertise with SIEM platforms, EDR tools, and cloud security monitoring
  • Experience working with external SOC or MDR providers
  • Strong understanding of attack frameworks (MITRE ATT&CK) and their application to detection and response
  • Experience supporting breach response obligations under GDPR, HIPAA, PCI, or similar regulatory frameworks
  • Excellent communication skills with the ability to coordinate cross-functional stakeholders under pressure
  • Bachelor's degree or relevant certifications (GCIH, GCFA, CISSP, or equivalent)

This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.

Interested in the role, but don't meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.

The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.

At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company's long-term growth and success.

The U.S. base salary range for this full-time position is $130,000 - $170,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training.

In addition to the base salary, the successful candidate will also receive benefits and a generous equity package.

These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate's specific qualifications, expertise, and alignment with the role's requirements.

About WHOOP

WHOOP is a wearable technology company that specializes in fitness tracking. The company was founded in 2012 and is based in Boston, Massachusetts. WHOOP's flagship product is a wristband that tracks various metrics related to fitness and health, such as heart rate variability, sleep quality, and recovery time. The company also offers a subscription service that provides personalized insights and recommendations based on the data collected by the wristband. WHOOP has raised over $200 million in funding and has partnerships with several professional sports leagues and teams.
Learn more about WHOOP
Size
500 employees
Industry
Founded
2011

Similar Jobs

More Jobs at WHOOP

More Information Technology Jobs

Find similar Incident Response Lead jobs: