Incident Response Lead
Job description
About the role
You will own the end to end lifecycle of security incidents for the WHOOP platform from initial alert through full remediation and lessons learned. You will act as the primary technical escalation point and hands on incident commander guiding the response across Security IT GRC and Legal. You will partner directly with our 24x7 SOC provider to validate alerts drive investigations and ensure timely containment and eradication. You will continuously refine how we detect and respond to threats by improving playbooks and strengthening our detection and response controls. You will lead practical exercises that test our readiness and improve our real world response capabilities. You will also manage external forensic engagements when deep technical analysis is required.
Key facts
What you'll do
- Lead hands on incident response activities serving as the primary internal escalation point for security events across the enterprise.
- Serve as the central incident commander coordinating Security IT GRC and Legal during active incidents to ensure a unified response.
- Partner with the SOC to validate alerts guide investigations and drive containment and eradication efforts in real time.
- Conduct host cloud and log based investigations analyzing artifacts and evidence to determine the scope and impact of threats.
- Coordinate with external forensic firms when complex analysis requires specialized tools or expertise.
- Maintain and continuously improve incident response playbooks escalation procedures and communication workflows for clarity and efficiency.
- Lead post incident reviews and root cause analysis ensuring remediation actions are clearly defined tracked and closed.
- Develop and execute tabletop exercises and incident simulations to test and strengthen response readiness and team confidence.
- Partner with GRC and Legal to support breach impact assessments and regulatory notification processes under applicable frameworks.
- Drive continuous improvement of detection and response capabilities across SIEM EDR cloud monitoring and identity systems.
- Own incident metrics and reporting including response times trends and systemic risk reduction initiatives to inform executive leadership.
- Participate in an on call escalation rotation to provide after hours incident leadership when required during nights weekends and holidays.
Requirements
- Bring 7 plus years of experience in incident response digital forensics threat detection or SOC operations building a strong foundation in real world scenarios.
- Demonstrate proven experience leading incident investigations in complex cloud native environments where systems are distributed and highly automated.
- Show strong experience conducting host cloud and log based investigations using a variety of tools and data sources to uncover the full picture of an event.
- Possess hands on expertise with SIEM platforms EDR tools and cloud security monitoring to collect analyze and interpret security related data.
- Have experience working with external SOC or MDR providers understanding how to integrate their findings into an internal response.
- Show a strong understanding of attack frameworks such as MITRE ATT&CK and how they apply to detection response and hardening efforts.
- Have experience supporting breach response obligations under GDPR HIPAA PCI or similar regulatory frameworks ensuring that legal and compliance requirements are met.
- Communicate excellently with the ability to coordinate cross functional stakeholders under pressure while maintaining clarity and focus.
- Hold a Bachelor's degree or relevant certifications such as GCIH GCFA CISSP or equivalent that demonstrate your knowledge and commitment.
- Be prepared to relocate if necessary to work out of the Boston MA office to ensure you can fully engage with the team on site.
Nice to have
No additional preferred items are specified beyond the core qualifications and responsibilities.
Practical notes
This position is based in Boston MA and requires the successful candidate to be prepared to relocate if necessary to work out of the Boston MA office. The role operates during standard business hours with participation in an on call rotation for after hours incidents as needed. Travel is not required for this position and the role is fully remote compatible with the on site office location.