安全工程师,事件响应
查看雇主原标题
Security Engineer, Incident ResponsePeloton · New York, New York
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 42/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 稀有职位+1
- 公司来源健康度+8
该职位未包含:已披露薪资、远程职位、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译关于该职位
Peloton 持续发展,致力于打造面向未来的互联健身平台,帮助我们的会员成为更好的自己。作为一家技术驱动的企业,我们的安全运营方式必须与我们的服务和会员一同演进和成长。我们正在寻找一名安全工程师,具备多样化的技能,能够在充满挑战、节奏快速且回报丰厚的环境中茁壮成长。我们没有传统的 SOC 分级结构,因此你可以期待帮助我们改进检测能力,同时创建更多检测、构建自动化,并研究及协助定义解决方案路线图以实现规模化。合适的候选人应高度注重结果、自我驱动,并对处理各种多样化的问题、威胁和警报充满热情。
你在 PELOTON 的日常影响
• 直接支持 Peloton 的安全计划,同时对来自各种来源的情报数据进行深入研究和战略分析,以用于威胁狩猎
• 及时了解相关漏洞、威胁行为者、妥协指标(IOC)战术、技术和程序(TTP)以及趋势,识别可采取行动的关注领域和威胁
• 提供情报驱动的洞察,分析现有和新兴威胁,利用这些洞察在 Peloton 企业内搜索异常和/或恶意活动
• 与安全工程团队和安全运营中心合作,为用户行为和事件建立基线,并构建新的检测和响应工作流
• 作为 Peloton 安全与运营团队及其他内部团队的一部分,为事件响应和调查工作提供分类支持
• 基于威胁分析、情报和预测,推荐并构建对策
• 开发、实施和维护安全事件手册/运行手册
• 根据需要,以简报、报告和仪表板的形式准备并向经理、各团队负责人和高级领导层展示包含发现和建议的分析
• 识别重复性、高容量的 SOC 工作流,并通过 AI 驱动的分类流水线、LLM 辅助调查和端到端自动化系统地消除它们
• 在商业解决方案不足的地方,设计并交付自研安全工具,负责从需求到迭代的完整生命周期——利用 AI 辅助开发快速推进并保持高质量
• 将威胁情报和事件经验转化为按优先级排序、可操作的控制建议,在不拖慢业务的情况下降低风险
• 需要考虑的事项: • 我们是一家高增长公司,我们的流程处于不同的成熟阶段
• 我们以非常快的速度做很多事情——你可能会不时被要求承担职责之外的工作。另一方面,我们相信适当的工作/生活平衡,你会被定期要求评估自己的能力以应对新的工作,防止超负荷
你为 PELOTON 带来
• 至少 3 年信息安全经验
• 需要具备事件响应或威胁检测经验;我们重视对云环境(AWS、GCP、Azure、Kubernetes)、SaaS 平台(O365、Google Workspace)或 IAM 的深入了解
• 对事件响应原则和流程有扎实的了解
• 具备自动化经验,特别是用于警报接收/分类/事件处理
• 具备 SIEM 工具或数据湖的专家级经验
• 具备剖析攻击者方法论和技术,和/或 EDR 工具的经验
• 出色的分析和问题解决能力
• 能够熟练使用 AI 编
岗位职责
Peloton 持续发展,致力于打造面向未来的互联健身平台,帮助我们的会员成为更好的自己。作为一家技术驱动的企业,我们的安全运营方式必须与我们的服务和会员一同演进和成长。我们正在寻找一名安全工程师,具备多样化的技能,能够在充满挑战、节奏快速且回报丰厚的环境中茁壮成长。我们没有传统的 SOC 分级结构,因此你可以期待帮助我们改进检测能力,同时创建更多检测、构建自动化,并研究及协助定义解决方案路线图以实现规模化。合适的候选人应高度注重结果、自我驱动,并对处理各种多样化的问题、威胁和警报充满热情。
你在 PELOTON 的日常影响
• 直接支持 Peloton 的安全计划,同时对来自各种来源的情报数据进行深入研究和战略分析,以用于威胁狩猎
• 及时了解相关漏洞、威胁行为者、妥协指标(IOC)战术、技术和程序(TTP)以及趋势,识别可采取行动的关注领域和威胁
• 提供情报驱动的洞察,分析现有和新兴威胁,利用这些洞察在 Peloton 企业内搜索异常和/或恶意活动
• 与安全工程团队和安全运营中心合作,为用户行为和事件建立基线,并构建新的检测和响应工作流
• 作为 Peloton 安全与运营团队及其他内部团队的一部分,为事件响应和调查工作提供分类支持
• 基于威胁分析、情报和预测,推荐并构建对策
• 开发、实施和维护安全事件手册/运行手册
• 根据需要,以简报、报告和仪表板的形式准备并向经理、各团队负责人和高级领导层展示包含发现和建议的分析
• 识别重复性、高容量的 SOC 工作流,并通过 AI 驱动的分类流水线、LLM 辅助调查和端到端自动化系统地消除它们
• 在商业解决方案不足的地方,设计并交付自研安全工具,负责从需求到迭代的完整生命周期——利用 AI 辅助开发快速推进并保持高质量
• 将威胁情报和事件经验转化为按优先级排序、可操作的控制建议,在不拖慢业务的情况下降低风险
• 需要考虑的事项: • 我们是一家高增长公司,我们的流程处于不同的成熟阶段
• 我们以非常快的速度做很多事情——你可能会不时被要求承担职责之外的工作。另一方面,我们相信适当的工作/生活平衡,你会被定期要求评估自己的能力以应对新的工作,防止超负荷
你为 PELOTON 带来
• 至少 3 年信息安全经验
• 需要具备事件响应或威胁检测经验;我们重视对云环境(AWS、GCP、Azure、Kubernetes)、SaaS 平台(O365、Google Workspace)或 IAM 的深入了解
• 对事件响应原则和流程有扎实的了解
•
任职要求
• 具备 SIEM 工具或数据湖的专家级经验
•
• 出色的分析与问题解决能力
• 能够熟练使用 AI 编码工具作为主要开发加速器,以构建并交付自研安全解决方案
• 具备学习心态,并热衷于学习新技术或安全领域
• 相关认证:GCIH、GCFE、GCIA、GCFA、AWS Security Specialty
#LI-DD1 #LI-Hybrid 基本薪资范围代表该职位在纽约市总部任职时的预期薪资区间下限和上限。该职位实际提供的基本薪资将取决于众多因素,包括但不限于经验、业务目标,以及职位所在地是否发生变化。我们的基本薪资只是 Peloton 具有竞争力的全面薪酬策略的一部分,该策略还包括年度股权奖励和员工购股计划,以及其他针对特定地区的健康与福利保障。
作为一家组织,我们的首要任务之一是维护员工及其家人的健康与福祉。为实现这一目标,我们提供全面而完善的福利,包括:
• 医疗、牙科和视力保险
• 优厚的带薪休假政策
• 短期和长期伤残保险
• 心理健康服务
• 401k、学费报销和学生贷款偿还计划
• 员工购股计划
• 生育和收养支持,以及最多 18 周的带薪育儿假
• 儿童照护和家庭照护折扣
• 免费使用 Peloton Digital App,以及服装和产品折扣
• 通勤福利和 Citi Bike 折扣
• 宠物保险等等!
基本薪资范围 $112,300 — $151,500 USD
关于 PELOTON:
Peloton(NASDAQ: PTON)为会员提供专业指导和世界级内容,为任何人、在任何地点、处于健身旅程任何阶段的人打造有影响力且富有娱乐性的锻炼体验。无论是在家中、户外、旅行途中还是健身房,Peloton 都将创新硬件、独特软件和独家内容结合在一起。Peloton 成立于 2012 年,总部位于纽约市,在美国、英国、加拿大、德国、澳大利亚和奥地利拥有数百万会员。如需了解更多信息,请访问 www.onepeloton.com。
Peloton 是提供平等机会的雇主,并遵守所有适用的联邦、州和地方公平就业实践法律。平等就业机会一直是并将继续是 Peloton 的基本原则。在 Peloton,所有团队成员、申请人和其他受保护人员均根据其个人能力和资质获得考虑,不因种族、肤色、宗教、性别、年龄、国籍、残疾、怀孕、遗传信息、军人或退伍军人身份、性取向、性别认同或表达、婚姻和民事伴侣/结合状况、外国人身份或公民身份、信仰、遗传易感性或携带者状态、失业状况、家庭状况、家庭暴力、性暴力或跟踪受害者身份、照护者身份,或适用法律规定的任何其他受保护特征而受到歧视。这项平等就业机会政策适用于与招聘和雇用、薪酬、福利、解雇以及所有其他雇佣条款和条件相关的所有实践和程序。如果您希望从申请到面试过程中申请任何便利安排,请发送电子邮件至:applicantaccommodations@onepeloton.com 。
在 Peloton,我们拥抱包括 AI 在内的技术,以提高生产力并加速我们为会员所做工作的创新。然而,在我们的招聘流程中,我们的首要任务仍然是了解您和您的独特资质。为确保公平公正的流程,我们不允许在申请和面试流程的任何阶段使用 AI 工具。在考虑您作为申请人时,我们希望了解您的技能、经历和动机,而不是通过 AI 系统进行中介。我们也希望在不使用 AI 工具的情况下直接评估您的沟通能力。
有逮捕或定罪记录的合格申请人将根据《洛杉矶县雇主公平机会条例》和《加利福尼亚州公平机会法案》、《洛杉矶市公平机会招聘倡议条例》以及《旧金山公平机会条例》(如适用于在这些司法管辖区申请职位的申请人)获得就业考虑。
请注意,互联网上可能流传虚假职位空缺、咨询合作、招揽或录用通知,试图获取特权信息,或诱导您支付与招聘或培训相关的服务费用。Peloton 在招聘或雇用流程的任何阶段都不会收取任何申请、处理或培训费用。所有真实职位空缺都将发布在我们的招聘页面上,Peloton 招聘团队和/或招聘经理的所有沟通都将来自 @ onepeloton.com 电子邮件地址。
如果您对据称来自 Peloton、代表 Peloton 或为 Peloton 发出的电子邮件、信件或电话沟通的真实性有任何疑问,请在就该通信采取任何进一步行动之前,发送电子邮件至 applicantaccommodations@onepeloton.com。
Peloton 不接受未经请求的代理机构简历。代理机构不应将简历转发至我们的职位别名、Peloton 员工或任何其他组织地点。Peloton 对与未经请求的简历相关的任何代理费用不承担责任。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
ABOUT THE ROLE
Peloton continues to grow and deliver the connected fitness platform of the future to help our members be the best version of themselves. As a technology-enabled business, our approach to security operations must evolve and grow alongside our services and members. We are looking for a Security Engineer with a diverse set of skills that can thrive in a challenging, fast-paced, and rewarding environment. We do not have a traditional SOC tier structure, so you can expect to help us improve our detections as well as create additional detections, build automations, and research & help define the solutions roadmap to achieve scale. The right candidate should have a strong focus on results, be self-driven, and be excited by working on a diverse set of problems, threats, and alerts.
YOUR DAILY IMPACT AT PELOTON
• Directly support Peloton’s Security Program while conducting in-depth research and strategic analysis of intelligence data from various sources to leverage in threat hunting
• Stay up to date with relevant vulnerabilities, threat actors, indicators of compromise (IOCs) tactics, techniques, and procedures (TTPs), and trends, identifying actionable areas of interest and threats
• Provide intel-driven insights into existing and emerging threats, use insights to search Peloton enterprise for activity that is anomalous and/or malicious
• Work with Security Engineering and the Security Operations Center to baseline user behaviors and events as well as build out new detections and response workflows
• Provide triage support for incident response and investigation efforts as part of Peloton’s Security and Operations team and other internal teams
• Recommend and build countermeasures based on threat analysis, intelligence, and forecasting
• Develop, implement, and maintain security incident playbooks/runbooks
• Prepare and present analysis with findings and recommendations in the form of briefings, reports, and dashboards to managers, various team leads and senior leadership as required
• Identify repetitive, high-volume SOC workflows and systematically eliminate them through AI-powered triage pipelines, LLM-assisted investigation, and end-to-end automation
• Design and ship homegrown security tooling where commercial solutions fall short, owning the full lifecycle from requirements through iteration — leveraging AI-assisted development to move fast and maintain high quality
• Translate threat intelligence and incident learnings into prioritized, actionable control recommendations that reduce risk without slowing the business
• Things to consider: • We’re a high-growth company, and our processes are in various states of maturity
• We’re doing a lot really fast - you may be asked to flex outside of your role from time to time. On the other hand, we believe in appropriate work/life balance, and you’ll be asked regularly to gauge your capacity against new efforts to prevent overloading
YOU BRING TO PELOTON
• Minimum 3 years in Information Security
• Experience in incident response or threat detection required; we value in-depth knowledge of cloud environments (AWS, GCP, Azure, Kubernetes), SaaS platforms (O365, Google Workspace), or IAM
• Strong knowledge of Incident Response principles and processes
• Experience with Automation specifically for Alert Intake/Triage/Incident Handling
• Expert experience with SIEM tools or data lakes
• Experience with dissecting attacker methodologies and techniques and/or EDR tooling
• Excellent analytical and problem solving skills
• Comfortable using AI cod
岗位职责
Peloton continues to grow and deliver the connected fitness platform of the future to help our members be the best version of themselves. As a technology-enabled business, our approach to security operations must evolve and grow alongside our services and members. We are looking for a Security Engineer with a diverse set of skills that can thrive in a challenging, fast-paced, and rewarding environment. We do not have a traditional SOC tier structure, so you can expect to help us improve our detections as well as create additional detections, build automations, and research & help define the solutions roadmap to achieve scale. The right candidate should have a strong focus on results, be self-driven, and be excited by working on a diverse set of problems, threats, and alerts.
YOUR DAILY IMPACT AT PELOTON
• Directly support Peloton’s Security Program while conducting in-depth research and strategic analysis of intelligence data from various sources to leverage in threat hunting
• Stay up to date with relevant vulnerabilities, threat actors, indicators of compromise (IOCs) tactics, techniques, and procedures (TTPs), and trends, identifying actionable areas of interest and threats
• Provide intel-driven insights into existing and emerging threats, use insights to search Peloton enterprise for activity that is anomalous and/or malicious
• Work with Security Engineering and the Security Operations Center to baseline user behaviors and events as well as build out new detections and response workflows
• Provide triage support for incident response and investigation efforts as part of Peloton’s Security and Operations team and other internal teams
• Recommend and build countermeasures based on threat analysis, intelligence, and forecasting
• Develop, implement, and maintain security incident playbooks/runbooks
• Prepare and present analysis with findings and recommendations in the form of briefings, reports, and dashboards to managers, various team leads and senior leadership as required
• Identify repetitive, high-volume SOC workflows and systematically eliminate them through AI-powered triage pipelines, LLM-assisted investigation, and end-to-end automation
• Design and ship homegrown security tooling where commercial solutions fall short, owning the full lifecycle from requirements through iteration — leveraging AI-assisted development to move fast and maintain high quality
• Translate threat intelligence and incident learnings into prioritized, actionable control recommendations that reduce risk without slowing the business
• Things to consider: • We’re a high-growth company, and our processes are in various states of maturity
• We’re doing a lot really fast - you may be asked to flex outside of your role from time to time. On the other hand, we believe in appropriate work/life balance, and you’ll be asked regularly to gauge your capacity against new efforts to prevent overloading
YOU BRING TO PELOTON
• Minimum 3 years in Information Security
• Experience in incident response or threat detection required; we value in-depth knowledge of cloud environments (AWS, GCP, Azure, Kubernetes), SaaS platforms (O365, Google Workspace), or IAM
• Strong knowledge of Incident Response principles and processes
•
任职要求
• Expert experience with SIEM tools or data lakes
•
• Excellent analytical and problem solving skills
• Comfortable using AI coding tools as a primary development accelerator to build and ship homegrown security solutions
• A learning mindset and excitement for learning new technologies or security areas
• Relevant certifications: GCIH, GCFE, GCIA, GCFA, AWS Security Specialty
#LI-DD1 #LI-Hybrid The base salary range represents the low and high end of the anticipated salary range for this position based at our New York City headquarters. The actual base salary offered for this position will depend on numerous factors including, without limitation, experience and business objectives and if the location for the job changes. Our base salary is just one component of Peloton’s competitive total rewards strategy that also includes annual equity awards and an Employee Stock Purchase Plan as well as other region-specific health and welfare benefits.
As an organization, one of our top priorities is to maintain the health and wellbeing for our employees and their family. To achieve this goal, we offer robust and comprehensive benefits including:
• Medical, dental and vision insurance
• Generous paid time off policy
• Short-term and long-term disability
• Access to mental health services
• 401k, tuition reimbursement and student loan paydown plans
• Employee Stock Purchase Plan
• Fertility and adoption support and up to 18 weeks of paid parental leave
• Child care and family care discounts
• Free access to Peloton Digital App and apparel and product discounts
• Commuter benefits and Citi Bike Discount
• Pet insurance and so much more!
Base Salary Range $112,300 — $151,500 USD
ABOUT PELOTON:
Peloton (NASDAQ: PTON) provides Members with expert instruction, and world class content to create impactful and entertaining workout experiences for anyone, anywhere and at any stage in their fitness journey. At home, outdoors, traveling, or at the gym, Peloton brings together innovative hardware, distinctive software, and exclusive content. Founded in 2012 and headquartered in New York City, Peloton has millions of Members across the US, UK, Canada, Germany, Australia, and Austria. For more information, visit www.onepeloton.com.
Peloton is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws. Equal employment opportunity has been, and will continue to be, a fundamental principle at Peloton, where all team members, applicants, and other covered persons are considered on the basis of their personal capabilities and qualifications without discrimination because of race, color, religion, sex, age, national origin, disability, pregnancy, genetic information, military or veteran status, sexual orientation, gender identity or expression, marital and civil partnership/union status, alienage or citizenship status, creed, genetic predisposition or carrier status, unemployment status, familial status, domestic violence, sexual violence or stalking victim status, caregiver status, or any other protected characteristic as established by applicable law. This policy of equal employment opportunity applies to all practices and procedures relating to recruitment and hiring, compensation, benefits, termination, and all other terms and conditions of employment. If you would like to request any accommodations from application through to interview, please email: applicantaccommodations@onepeloton.com .
At Peloton, we embrace technology, including AI, to enhance productivity and accelerate innovation in the work we do for our members. However, in our hiring process, our priority remains in getting to know you and your unique qualifications. To ensure a fair and equitable process, we do not permit the use of AI tools during any stage of the application and interview process. In considering you as an applicant, we want to understand your skills, experiences, and motivations without mediation through an AI system. We also want to directly assess your communication skills without the use of an AI tool.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act, the City of Los Angeles Fair Chance Initiative for Hiring Ordinance and the San Francisco Fair Chance Ordinance, as applicable to applicants applying for positions in these jurisdictions.
Please be aware that fictitious job openings, consulting engagements, solicitations, or employment offers may be circulated on the Internet in an attempt to obtain privileged information, or to induce you to pay a fee for services related to recruitment or training. Peloton does NOT charge any application, processing, or training fee at any stage of the recruitment or hiring process. All genuine job openings will be posted here on our careers page and all communications from the Peloton recruiting team and/or hiring managers will be from an @ onepeloton.com email address.
If you have any doubts about the authenticity of an email, letter or telephone communication purportedly from, for, or on behalf of Peloton, please email applicantaccommodations@onepeloton.com before taking any further action in relation to the correspondence.
Peloton does not accept unsolicited agency resumes. Agencies should not forward resumes to our jobs alias, Peloton employees or any other organization location. Peloton is not responsible for any agency fees related to unsolicited resumes.