> Markdown version of [/jobs/ext/478980-security-analyst](https://www.wearedevelopers.com/jobs/ext/478980-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Analyst - **Company:** Whoop, Inc. - **Location:** Boston, MA, United States - **Experience:** Experienced - **Salary:** $70,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing, Cyber Security, Issue Tracking Systems, Intrusion Detection and Prevention, Log Analysis, Phishing, Security Information and Event Management, Simulation Software, Software Vulnerability Management, Data Logging, Scripting, Mitre Att&ck, Cybercrime - **Published:** June 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b86330cc925a919f ## About the Role Do you have experience in Vulnerability management?, The ideal candidate combines strong analytical skills with operational discipline and enjoys working across security and engineering teams to investigate potential threats and improve security processes., * 3+ years of experience in security operations, incident response, threat detection, or a related cybersecurity role. * Experience investigating security alerts or suspicious activity across environments such as endpoint, identity, cloud, or SaaS systems. * Experience triaging and managing security investigation workflows, including ticket queues or incident tracking systems. * Familiarity with SIEM platforms, log analysis, and security monitoring tools. * Understanding of common attacker techniques and frameworks such as MITRE ATT&CK. * Experience working with security tools such as EDR platforms, identity systems, cloud logging platforms, or similar technologies. * Familiarity with modern AI-enabled tools used in enterprise environments and an understanding of risks associated. * Experience improving security operations through automation, scripting, or responsible use of AI to increase operational efficiency. * Strong analytical and investigative skills with the ability to evaluate security events and determine potential impact. * Ability to coordinate investigations across multiple teams and communicate findings clearly to technical and non-technical stakeholders. * Strong written documentation skills for incident records, investigation notes, and operational procedures. * Relevant security certifications such as Security+, CySA+, SSCP, GSEC, or GCIH are a plus. This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office. ## Description * Triage and investigate security alerts originating from internal security tooling as well as those escalated by external security monitoring partners. * Monitor and manage the internal security operations ticket queue, ensuring alerts and investigations are prioritized, tracked, and resolved in a timely manner. * Assist with investigation of security events across endpoint, identity, cloud, and SaaS platforms. * Support incident response activities including investigation, containment coordination, documentation, and post-incident analysis. * Respond to external threat intelligence and digital risk alerts related to potential brand abuse, impersonation, or exposed credentials. * Collaborate with security engineering teams and external security partners to improve detection coverage and reduce false positives. * Help identify gaps in logging, telemetry, or investigation workflows across security platforms. * Assist with threat hunting and security investigations using data from SIEM and other security tools. * Support vulnerability management workflows by assisting with triage, prioritization, and tracking of remediation activities. * Own and manage the security operations queue while serving as a central intake point for security questions, alerts, and reports across the organization, ensuring items are triaged, prioritized, and driven through investigation or resolution. * Operate the organization's phishing simulation program to reduce susceptibility to social engineering threats, including managing phishing campaigns and coordinating targeted remediation training for users with repeated failures. * Identify opportunities to improve security operations through process improvements, automation, and responsible use of AI to streamline investigation, triage, and reporting workflows. * Maintain documentation for incident response procedures, investigation workflows, and operational playbooks. * Participate in the security team's on-call rotation to support investigation and response activities when needed. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)