About this role
ABOUT THE ROLE
Peloton continues to grow and deliver the connected fitness platform of the future to help our members be the best version of themselves. As a technology-enabled business, our approach to security operations must evolve and grow alongside our services and members. We are looking for a Security Engineer with a diverse set of skills that can thrive in a challenging, fast-paced, and rewarding environment. We do not have a traditional SOC tier structure, so you can expect to help us improve our detections as well as create additional detections, build automations, and research & help define the solutions roadmap to achieve scale. The right candidate should have a strong focus on results, be self-driven, and be excited by working on a diverse set of problems, threats, and alerts.
YOUR DAILY IMPACT AT PELOTON
• Directly support Peloton’s Security Program while conducting in-depth research and strategic analysis of intelligence data from various sources to leverage in threat hunting
• Stay up to date with relevant vulnerabilities, threat actors, indicators of compromise (IOCs) tactics, techniques, and procedures (TTPs), and trends, identifying actionable areas of interest and threats
• Provide intel-driven insights into existing and emerging threats, use insights to search Peloton enterprise for activity that is anomalous and/or malicious
• Work with Security Engineering and the Security Operations Center to baseline user behaviors and events as well as build out new detections and response workflows
• Provide triage support for incident response and investigation efforts as part of Peloton’s Security and Operations team and other internal teams
• Recommend and build countermeasures based on threat analysis, intelligence, and forecasting
• Develop, implement, and maintain security incident playbooks/runbooks
• Prepare and present analysis with findings and recommendations in the form of briefings, reports, and dashboards to managers, various team leads and senior leadership as required
• Identify repetitive, high-volume SOC workflows and systematically eliminate them through AI-powered triage pipelines, LLM-assisted investigation, and end-to-end automation
• Design and ship homegrown security tooling where commercial solutions fall short, owning the full lifecycle from requirements through iteration — leveraging AI-assisted development to move fast and maintain high quality
• Translate threat intelligence and incident learnings into prioritized, actionable control recommendations that reduce risk without slowing the business
• Things to consider:
• We’re a high-growth company, and our processes are in various states of maturity
• We’re doing a lot really fast - you may be asked to flex outside of your role from time to time. On the other hand, we believe in appropriate work/life balance, and you’ll be asked regularly to gauge your capacity again