Skip to content
WHOOPWHOOPBoston, MA

Incident Response Lead

Lead technical incident response as primary escalation point and incident commander. Conduct investigations across hosts, cloud, and logs; improve playbooks, run simulations, and support regulatory breach processes in a cloud-native environment.

Salary not listed
On-site7+ YOESecurity Engineering

About the role

Responsibilities

  • Lead hands-on incident response activities, serving as the primary internal escalation point for security events
  • Serve as the central incident commander across Security, IT, GRC, and Legal during active incidents
  • Partner with the SOC to validate alerts, guide investigations, and drive containment and eradication efforts
  • Conduct host, cloud, and log-based investigations, and coordinate with external forensic firms when needed
  • Maintain and continuously improve incident response playbooks, escalation procedures, and communication workflows
  • Lead post-incident reviews and root cause analysis, ensuring remediation actions are clearly defined and tracked
  • Develop and execute tabletop exercises and incident simulations to test and strengthen response readiness
  • Partner with GRC and Legal to support breach impact assessments and regulatory notification processes
  • Drive continuous improvement of detection and response capabilities across SIEM, EDR, cloud monitoring, and identity systems
  • Own incident metrics and reporting, including response times, trends, and systemic risk reduction initiatives
  • Participate in an on-call escalation rotation to provide after-hours incident leadership when required

Qualifications

  • 7+ years of experience in incident response, digital forensics, threat detection, or SOC operations
  • Proven experience leading incident investigations in complex, cloud-native environments
  • Strong experience conducting host, cloud, and log-based investigations
  • Hands-on expertise with SIEM platforms, EDR tools, and cloud security monitoring
  • Experience working with external SOC or MDR providers
  • Strong understanding of attack frameworks (MITRE ATT&CK) and their application to detection and response
  • Experience supporting breach response obligations under GDPR, HIPAA, PCI, or similar regulatory frameworks
  • Excellent communication skills with the ability to coordinate cross-functional stakeholders under pressure
  • Bachelor’s degree or relevant certifications (GCIH, GCFA, CISSP, or equivalent)

Nice-to-Haves

  • Relevant certifications (GCIH, GCFA, CISSP, or equivalent)

Skills

Incident Responsedigital forensicsSIEMedrmitre att&ckCloud SecurityGDPRHIPAAPCIgcihgcfacissp
GitLab

Senior Software Security Engineer

GitLabUnited States

Senior engineer on Trust and Safety team building and maintaining abuse prevention systems, anomaly detection, and agentic AI tools for the GitLab SaaS platform. Requires strong Ruby/Rails software engineering background; security experience preferred but not required.

139k – 196k/yr
Remote5+ YOESecurity Engineering
Fluidstack

Senior Detection Engineer

FluidstackNew York, NY +3

Own end-to-end detection engineering program including threat modeling, detection-as-code pipelines, threat hunting, SIEM/EDR tuning, alert triage and incident response for rapidly scaling AI compute infrastructure. Requires 5+ years in detection engineering or threat hunting with deep SIEM/EDR and scripting experience.

176k – 218k/yr
On-site5+ YOESecurity Engineering
Mozilla

Senior Security Engineer, Bug Bounty

MozillaUnited States

Own and scale Mozilla's web bug bounty program. Triage and validate reports from HackerOne/Bugzilla, drive vulnerability remediation with engineering teams, perform code reviews, and collaborate with SIRT on incidents. Requires 3+ years security engineering experience and bug bounty or bug hunting background.

116k – 183k/yr
Remote3+ YOESecurity Engineering
Mozilla

Senior Security Engineer, Bug Bounty

MozillaUnited States

Own and scale Mozilla's web bug bounty program as the primary interface with external researchers. Lead triage, validation, remediation of reports, collaborate with SIRT on incidents, perform code reviews, and drive secure development improvements. Requires 3+ years security engineering experience and bug bounty or bug hunting background.

Salary not listed
Remote3+ YOESecurity Engineering
Fluidstack

Regional Site Security Lead, Deployment & Ops

FluidstackAustin, TX +1

Lead physical security operations and teams across multiple data center sites in a region. Own end-to-end posture, standardize procedures, support customer audits, and integrate security into facility growth for frontier AI compute infrastructure.

225k – 325k/yr
On-site7+ YOESecurity Engineering