Security Engineer, Incident Response

Peloton Interactive, Inc.
New York, NY, United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$112,300.0 - $151,500.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Software as a Service Cyber Security Identity and Access Management Data Intelligence Intrusion Detection and Prevention Security Information and Event Management Google Cloud Cloud Platform System Office365
+4 more
Large Language Models Data Lakes Kubernetes Gsuite

Job description

Peloton continues to grow and deliver the connected fitness platform of the future to help our members be the best version of themselves. As a technology-enabled business, our approach to security operations must evolve and grow alongside our services and members. We are looking for a Security Engineer with a diverse set of skills that can thrive in a challenging, fast-paced, and rewarding environment. We do not have a traditional SOC tier structure, so you can expect to help us improve our detections as well as create additional detections, build automations, and research & help define the solutions roadmap to achieve scale. The right candidate should have a strong focus on results, be self-driven, and be excited by working on a diverse set of problems, threats, and alerts. YOUR DAILY IMPACT AT PELOTON

  • Directly support Peloton’s Security Program while conducting in-depth research and strategic analysis of intelligence data from various sources to leverage in threat hunting
  • Stay up to date with relevant vulnerabilities, threat actors, indicators of compromise (IOCs) tactics, techniques, and procedures (TTPs), and trends, identifying actionable areas of interest and threats
  • Provide intel-driven insights into existing and emerging threats, use insights to search Peloton enterprise for activity that is anomalous and/or malicious
  • Work with Security Engineering and the Security Operations Center to baseline user behaviors and events as well as build out new detections and response workflows
  • Provide triage support for incident response and investigation efforts as part of Peloton’s Security and Operations team and other internal teams
  • Recommend and build countermeasures based on threat analysis, intelligence, and forecasting
  • Develop, implement, and maintain security incident playbooks/runbooks
  • Prepare and present analysis with findings and recommendations in the form of briefings, reports, and dashboards to managers, various team leads and senior leadership as required
  • Identify repetitive, high-volume SOC workflows and systematically eliminate them through AI-powered triage pipelines, LLM-assisted investigation, and end-to-end automation
  • Design and ship homegrown security tooling where commercial solutions fall short, owning the full lifecycle from requirements through iteration - leveraging AI-assisted development to move fast and maintain high quality
  • Translate threat intelligence and incident learnings into prioritized, actionable control recommendations that reduce risk without slowing the business
  • Things to consider:
  • We’re a high-growth company, and our processes are in various states of maturity
  • We’re doing a lot really fast - you may be asked to flex outside of your role from time to time. On the other hand, we believe in appropriate work/life balance, and you’ll be asked regularly to gauge your capacity against new efforts to prevent overloading

Requirements

  • Minimum 3 years in Information Security
  • Experience in incident response or threat detection required; we value in-depth knowledge of cloud environments (AWS, GCP, Azure, Kubernetes), SaaS platforms (O365, Google Workspace), or IAM
  • Strong knowledge of Incident Response principles and processes
  • Experience with Automation specifically for Alert Intake/Triage/Incident Handling
  • Expert experience with SIEM tools or data lakes
  • Experience with dissecting attacker methodologies and techniques and/or EDR tooling
  • Excellent analytical and problem solving skills
  • Comfortable using AI coding tools as a primary development accelerator to build and ship homegrown security solutions
  • A learning mindset and excitement for learning new technologies or security areas
  • Relevant certifications: GCIH, GCFE, GCIA, GCFA, AWS Security Specialty

LI-DD1

#LI-Hybrid

Benefits & conditions

140 W 23rd St Frnt 1, New York, NY 10011, Hybrid work $112,300 - $151,500 a year

About the company

Peloton (NASDAQ: PTON) provides Members with expert instruction, and world class content to create impactful and entertaining workout experiences for anyone, anywhere and at any stage in their fitness journey. At home, outdoors, traveling, or at the gym, Peloton brings together innovative hardware, distinctive software, and exclusive content. Founded in 2012 and headquartered in New York City, Peloton has millions of Members across the US, UK, Canada, Germany, Australia, and Austria. For more information, visit www.onepeloton.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:24 min

The governance failures of centralized data lakes

Mario Meir-Huber · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

6:24 min

Distributed data lakes and containerized computing clusters

Ulrich Wurstbauer +1 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:56 min

Core data lake environment and infrastructure requirements

Christoph Fassbach Christoph Fassbach +1 · World Congress 2024

Videos

See all

Related articles

See all