Security Engineer, Incident Response

Peloton Peloton · Consumer · United States · Remote · Security & Risk

Security Engineer focused on incident response, threat hunting, and automation. The role involves improving detections, building automations, and defining solutions roadmap. It emphasizes using AI-powered triage pipelines, LLM-assisted investigation, and AI-assisted development for security tooling.

What you'd actually do

  1. Directly support Peloton’s Security Program while conducting in-depth research and strategic analysis of intelligence data from various sources to leverage in threat hunting
  2. Stay up to date with relevant vulnerabilities, threat actors, indicators of compromise (IOCs) tactics, techniques, and procedures (TTPs), and trends, identifying actionable areas of interest and threats
  3. Provide intel-driven insights into existing and emerging threats, use insights to search Peloton enterprise for activity that is anomalous and/or malicious
  4. Work with Security Engineering and the Security Operations Center to baseline user behaviors and events as well as build out new detections and response workflows
  5. Provide triage support for incident response and investigation efforts as part of Peloton’s Security and Operations team and other internal teams

Skills

Required

  • Minimum 3 years in Information Security
  • Experience in incident response or threat detection
  • Strong knowledge of Incident Response principles and processes
  • Experience with Automation specifically for Alert Intake/Triage/Incident Handling
  • Expert experience with SIEM tools or data lakes
  • Experience with dissecting attacker methodologies and techniques and/or EDR tooling
  • Excellent analytical and problem solving skills
  • Comfortable using AI coding tools as a primary development accelerator to build and ship homegrown security solutions

Nice to have

  • in-depth knowledge of cloud environments (AWS, GCP, Azure, Kubernetes)
  • in-depth knowledge of SaaS platforms (O365, Google Workspace)
  • in-depth knowledge of IAM
  • Relevant certifications: GCIH, GCFE, GCIA, GCFA, AWS Security Specialty

What the JD emphasized

  • AI-powered triage pipelines
  • LLM-assisted investigation
  • end-to-end automation
  • AI-assisted development