# Incident Response Lead

**Company:** [WHOOP](https://hotfix.jobs/companies/whoop)
**Location:** Boston, MA
**Role:** Security Engineering
**Experience:** 7+ years
**Skills:** Incident Response, digital forensics, SIEM, edr, mitre att&ck, Cloud Security, GDPR, HIPAA, PCI, gcih, gcfa, cissp
**Posted:** 2026-07-17

> Lead technical incident response as primary escalation point and incident commander. Conduct investigations across hosts, cloud, and logs; improve playbooks, run simulations, and support regulatory breach processes in a cloud-native environment.

## Job Description

## Responsibilities
- Lead hands-on incident response activities, serving as the primary internal escalation point for security events
- Serve as the central incident commander across Security, IT, GRC, and Legal during active incidents
- Partner with the SOC to validate alerts, guide investigations, and drive containment and eradication efforts
- Conduct host, cloud, and log-based investigations, and coordinate with external forensic firms when needed
- Maintain and continuously improve incident response playbooks, escalation procedures, and communication workflows
- Lead post-incident reviews and root cause analysis, ensuring remediation actions are clearly defined and tracked
- Develop and execute tabletop exercises and incident simulations to test and strengthen response readiness
- Partner with GRC and Legal to support breach impact assessments and regulatory notification processes
- Drive continuous improvement of detection and response capabilities across SIEM, EDR, cloud monitoring, and identity systems
- Own incident metrics and reporting, including response times, trends, and systemic risk reduction initiatives
- Participate in an on-call escalation rotation to provide after-hours incident leadership when required

## Qualifications
- 7+ years of experience in incident response, digital forensics, threat detection, or SOC operations
- Proven experience leading incident investigations in complex, cloud-native environments
- Strong experience conducting host, cloud, and log-based investigations
- Hands-on expertise with SIEM platforms, EDR tools, and cloud security monitoring
- Experience working with external SOC or MDR providers
- Strong understanding of attack frameworks (MITRE ATT&CK) and their application to detection and response
- Experience supporting breach response obligations under GDPR, HIPAA, PCI, or similar regulatory frameworks
- Excellent communication skills with the ability to coordinate cross-functional stakeholders under pressure
- Bachelor’s degree or relevant certifications (GCIH, GCFA, CISSP, or equivalent)

## Nice-to-Haves
- Relevant certifications (GCIH, GCFA, CISSP, or equivalent)

## Similar roles

- [Senior Software Security Engineer](https://hotfix.jobs/jobs/bd83bbb8-d7c1-42bd-811f-3cdd8a53d7ca) - GitLab - Remote - $139k – $196k/yr
- [Senior Detection Engineer](https://hotfix.jobs/jobs/6e9f5f26-7b5d-45a6-ad57-701c49e31283) - Fluidstack - New York, NY - $176k – $218k/yr
- [Senior Security Engineer, Bug Bounty](https://hotfix.jobs/jobs/5532c56d-7528-4966-9a33-ffec20c4a012) - Mozilla - Remote - $116k – $183k/yr
- [Senior Security Engineer, Bug Bounty](https://hotfix.jobs/jobs/7b8b62b3-cb93-4615-9276-eea6ffc68ccf) - Mozilla - Remote
- [Regional Site Security Lead, Deployment & Ops](https://hotfix.jobs/jobs/230fbb8b-e9a3-4d1c-a92a-ddc985723452) - Fluidstack - Austin, TX - $225k – $325k/yr

**Apply:** https://hotfix.jobs/jobs/93e34b6a-3c86-493d-bd61-8dac0f9ebb7c
**Canonical:** https://hotfix.jobs/jobs/93e34b6a-3c86-493d-bd61-8dac0f9ebb7c