WHOOP
Technology
IncidentResponseLead
Neural analysis suggests this role is
optimal for Lead candidates.
“Incident Response Lead at WHOOP. Skills: Incident response, Digital forensics, Threat detection, SOC operations. Lead incident response activities. Serve as incident commander”
What You'll Achieve.
Systemic risk reduction
Industry & Context.
Root cause analysis
On-call escalation rotation
What They're Looking For.
Must Have
7+ years incident response, Lead incident investigations, Host, cloud, log investigations, SIEM platforms expertise, EDR tools expertise, Cloud security monitoring expertise, Work with external SOC, Attack frameworks understanding, GDPR, HIPAA, PCI support, Excellent communication skills, Bachelor's degree or certifications
Nice to Have
GCIH certification, GCFA certification, CISSP certification
What You'll Do.
Lead incident response activities
Serve as incident commander
Conduct host investigations
Conduct cloud investigations
Conduct log investigations
Coordinate with forensic firms
Maintain incident response playbooks
Improve escalation procedures
Improve communication workflows
Lead post-incident reviews
Lead root cause analysis
Define remediation actions
Track remediation actions
Develop tabletop exercises
Execute incident simulations
Support breach impact assessments
Support regulatory notification
Improve detection capabilities
Improve response capabilities
Own incident reporting
Report response times
Report risk reduction
How You'll Work.
Team & Collaboration
24x7 SOC provider; Cross-functional stakeholders; Security, IT, GRC, Legal
Communication Scope
Cross-functional coordination
Process & Methodology
Remediation tracking
Full Job Description
At WHOOP, we’re on a mission to unlock human performance and healthspan. Our wearable technology provides personalized insights that help millions of members better understand their bodies and make smarter decisions about training, recovery, and lifestyle. We are seeking a Incident Response Lead to drive security incident response across the enterprise. In this role, you will serve as the primary internal escalation point and hands-on responder for security incidents, partnering closely with WHOOP’s 24x7 SOC provider and cross-functional stakeholders to investigate, contain, and remediate threats. This is a highly technical individual contributor role with significant ownership and visibility across Security, IT, GRC, and Legal. RESPONSIBILITIES: - - Lead hands-on incident response activities, serving as the primary internal escalation point for security events - Serve as the central incident commander across Security, IT, GRC, and Legal during active incidents - Partner with the SOC to validate alerts, guide investigations, and drive containment and eradication efforts - Conduct host, cloud, and log-based investigations, and coordinate with external forensic firms when needed - Maintain and continuously improve incident response playbooks, escalation procedures, and communication workflows - Lead post-incident reviews and root cause analysis, ensuring remediation actions are clearly defined and tracked - Develop and execute tabletop exercises and incident simulations to test and strengthen response readiness - Partner with GRC and Legal to support breach impact assessments and regulatory notification processes - Drive continuous improvement of detection and response capabilities across SIEM, EDR, cloud monitoring, and identity systems - Own incident metrics and reporting, including response times, trends, and systemic risk reduction initiatives - Participate in an on-call escalation rotation to provide after-hours incident leadership when required QUALIFICATIONS: -
Applying for this Incident Response Lead role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about WHOOP?
Real rants from real employees. Read before you apply.