Security Engineer, Incident Response
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
Peloton continues to grow and deliver the connected fitness platform of the future to help our members be the best version of themselves. As a technology-enabled business, our approach to security operations must evolve and grow alongside our services and members. We are looking for a Security Engineer with a diverse set of skills that can thrive in a challenging, fast-paced, and rewarding environment. We do not have a traditional SOC tier structure, so you can expect to help us improve our detections as well as create additional detections, build automations, and research & help define the solutions roadmap to achieve scale. The right candidate should have a strong focus on results, be self-driven, and be excited by working on a diverse set of problems, threats, and alerts. YOUR DAILY IMPACT AT PELOTON
- Directly support Peloton’s Security Program while conducting in-depth research and strategic analysis of intelligence data from various sources to leverage in threat hunting
- Stay up to date with relevant vulnerabilities, threat actors, indicators of compromise (IOCs) tactics, techniques, and procedures (TTPs), and trends, identifying actionable areas of interest and threats
- Provide intel-driven insights into existing and emerging threats, use insights to search Peloton enterprise for activity that is anomalous and/or malicious
- Work with Security Engineering and the Security Operations Center to baseline user behaviors and events as well as build out new detections and response workflows
- Provide triage support for incident response and investigation efforts as part of Peloton’s Security and Operations team and other internal teams
- Recommend and build countermeasures based on threat analysis, intelligence, and forecasting
- Develop, implement, and maintain security incident playbooks/runbooks
- Prepare and present analysis with findings and recommendations in the form of briefings, reports, and dashboards to managers, various team leads and senior leadership as required
- Identify repetitive, high-volume SOC workflows and systematically eliminate them through AI-powered triage pipelines, LLM-assisted investigation, and end-to-end automation
- Design and ship homegrown security tooling where commercial solutions fall short, owning the full lifecycle from requirements through iteration - leveraging AI-assisted development to move fast and maintain high quality
- Translate threat intelligence and incident learnings into prioritized, actionable control recommendations that reduce risk without slowing the business
- Things to consider:
- We’re a high-growth company, and our processes are in various states of maturity
- We’re doing a lot really fast - you may be asked to flex outside of your role from time to time. On the other hand, we believe in appropriate work/life balance, and you’ll be asked regularly to gauge your capacity against new efforts to prevent overloading
Requirements
- Minimum 3 years in Information Security
- Experience in incident response or threat detection required; we value in-depth knowledge of cloud environments (AWS, GCP, Azure, Kubernetes), SaaS platforms (O365, Google Workspace), or IAM
- Strong knowledge of Incident Response principles and processes
- Experience with Automation specifically for Alert Intake/Triage/Incident Handling
- Expert experience with SIEM tools or data lakes
- Experience with dissecting attacker methodologies and techniques and/or EDR tooling
- Excellent analytical and problem solving skills
- Comfortable using AI coding tools as a primary development accelerator to build and ship homegrown security solutions
- A learning mindset and excitement for learning new technologies or security areas
- Relevant certifications: GCIH, GCFE, GCIA, GCFA, AWS Security Specialty
LI-DD1
#LI-Hybrid
Benefits & conditions
140 W 23rd St Frnt 1, New York, NY 10011, Hybrid work $112,300 - $151,500 a year
About the company
Peloton (NASDAQ: PTON) provides Members with expert instruction, and world class content to create impactful and entertaining workout experiences for anyone, anywhere and at any stage in their fitness journey. At home, outdoors, traveling, or at the gym, Peloton brings together innovative hardware, distinctive software, and exclusive content. Founded in 2012 and headquartered in New York City, Peloton has millions of Members across the US, UK, Canada, Germany, Australia, and Austria. For more information, visit www.onepeloton.com.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 120 - Apple and peers
Dev Digest 134 - Where pixels sing?
Highest Paying Tech Companies for Developers
Fully Remote Software Engineer Jobs