<div>At WHOOP, we are on a mission to unlock human performance and extend healthspan. The security organization supports this mission by protecting the systems, data, and infrastructure that power the platform and enable trusted member experiences.</div>
<div><br>WHOOP is seeking a Security Analyst to support day-to-day security operations and maintain operational visibility across the security environment. This role works closely with the internal security team and external security partners to investigate alerts, coordinate response activities, and ensure security issues are triaged and addressed efficiently.</div>
<div><br>The ideal candidate combines strong analytical skills with operational discipline and enjoys working across security and engineering teams to investigate potential threats and improve security processes.</div>
<div> </div>
<div><em>This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office. </em></div>
RESPONSIBILITIES:
β’ Triage and investigate security alerts originating from internal security tooling as well as those escalated by external security monitoring partners.
β’ Monitor and manage the internal security operations ticket queue, ensuring alerts and investigations are prioritized, tracked, and resolved in a timely manner.
β’ Assist with investigation of security events across endpoint, identity, cloud, and SaaS platforms.
β’ Support incident response activities including investigation, containment coordination, documentation, and post-incident analysis.
β’ Respond to external threat intelligence and digital risk alerts related to potential brand abuse, impersonation, or exposed credentials.
β’ Collaborate with security engineering teams and external security partners to improve detection coverage and reduce false positives.
β’ Help identify gaps in logging, telemetry, or investigation workflows across security platforms.
β’ Assist with threat hunting and security investigations using data from SIEM and other security tools.
β’ Support vulnerability management workflows by assisting with triage, prioritization, and tracking of remediation activities.
β’ Own and manage the security operations queue while serving as a central intake point for security questions, alerts, and reports across the organization, ensuring items are triaged, prioritized, and driven through investigation or resolution.
β’ Operate the organizationβs phishing simulation program to reduce susceptibility to social engineering threats, including managing phishing campaigns and coordinating targeted remediation training for users with repeated failures.
β’ Identify opportunities to improve security operations through process improvements, automation, and responsible use of AI to streamline investigation, triage, and reporting workflows.
β’ Maintain documentation for incident response procedures, investigation workflows, and operational playbooks.
β’ Participate in the security teamβs on-call rotation to support investigation and response activities when needed.
QUALIFICATIONS:
β’ 3+ years of experience in security operations, incident response, threat detection, or a related cybersecurity role.
β’ Experience investigating security alerts or suspicious activity across environments such as endpoint, identity, cloud, or SaaS systems.
β’ Experience triaging and managing security investigation workflows, including ticket queues or incident tracking systems.
β’ Familiarity with SIEM platforms, log analysis, and security monitoring tools.
β’ Understanding of common attacker techniques and frameworks such as MITRE ATT&CK.
β’ Experience working with security tools such as EDR platforms, identity systems, cloud logging platforms, or similar technologies.
β’ Familiarity with modern AI-enabled tools used in enterprise environments and an understanding of risks associated.
β’ Experience improving security operations through automation, scripting, or responsible use of AI to increase operational efficiency.
β’ Strong analytical and investigative skills with the ability to evaluate security events and determine potential impact.
β’ Ability to coordinate investigations across multiple teams and communicate findings clearly to technical and non-technical stakeholders.
β’ Strong written documentation skills for incident records, investigation notes, and operational procedures.
β’ Relevant security certifications such as Security+, CySA+, SSCP, GSEC, or GCIH are a plus.
Interested in the role, but donβt meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.
At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the companyβs long-term growth and success.
The U.S. base salary range for this full-time position is $70,000 - $110,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training.
In addition to the base salary, the successful candidate will also receive benefits and a generous equity package.
These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidateβs specific qualifications, expertise, and alignment with the roleβs requirements.