Job Description
ABOUT THE ROLE
Peloton inspires and motivates millions of people every day. A key part of delivering on that mission is not only an amazing experience that our instructors and platforms provide, but also the data, telemetry, and insights that empower our members to be the best version of themselves anywhere, anytime. Earning and maintaining our members’ trust and safeguarding their data is key to everything we do.
The Security Governance, Risk & Compliance (GRC) Analyst is a critical position within the team, and has risk and compliance responsibilities from a technology and security perspective across the organization globally. The main objective of the Security GRC team is to deliver best in class Security Governance, Risk and Compliance, services to ensure that Peloton operates in a risk mitigated, security managed environment and that Peloton’s security compliance objectives are being met. Their responsibilities span Peloton’s products and services and the internal applications, tools, and infrastructure that support them.
YOUR DAILY IMPACT AT PELOTON:
- Working closely with the entire GRC team and stakeholders across the organization, this individual will be directly responsible for implementing, maintaining and improving internal controls to assure compliance with applicable regulatory and legal requirements.Â
- Drive risk analysis, operate controls, and help implement industry best practices for teams and technologies used across the organization.Â
- Responsible for executing internal Information Technology (IT) controls in support of regulatory and compliance frameworks for in-scope applications, operating systems and databases.
- Partner effectively with Information Security, Product, Platform, Internal Audit, Legal, and other internal peers to support Peloton’s compliance with applicable legal, regulatory, and security frameworks.
- Work closely with the Internal Audit Team to ensure alignment on timing, controls reliance, external audit reliance, etc.
- Support the development of new testing automations through the GRC platform, or similar tool-sets, to automate the IT internal controls testing (i.e. SOX user access review controls, data analytics, etc).
- Maintains updated knowledge in the field of risk management and compliance to efficiently work on frameworks including NIST CSF, CIS Controls, PCI-DSS, SOX 404, etc.
YOU BRING TO PELOTON:
- 4+ years of relevant internal audit and SOX experience, with a mix of private and public accounting experience preferred.Â
- Working knowledge of IT systems - SAP, WMS, ADP, Salesforce, Coupa, etc.Â
- Highly organized, motivated, and detail-oriented with the ability to work independently in a fast-paced environment. Â
- Flexible and able to adapt quickly in a fast-moving environment.
- Excellent problem-solving skills and ability to manage competing priorities and deadlines.
- Strong degree of comfort working alongside, engaging and communicating with senior software engineering and business-side stakeholders.
- Experience developing, championing, and managing internal compliance programs.
- One or more of the following certifications is preferred: CISA, CISM, CISSP.Â
#LI-SV2 #LI-Remote
ABOUT PELOTON:
Peloton is the leading interactive fitness platform globally, with a passionate community of nearly 7 million Members in the US, UK, Canada, Germany, and Australia. Peloton makes fitness entertaining, approachable, effective, and convenient, while fostering social connections that motivate its Members to commit to their fitness journeys. An innovator at the nexus of fitness, technology, and media, Peloton reinvented the fitness industry by developing a first-of-its-kind subscription platform that seamlessly combines the best equipment, proprietary networked software, world-class streaming digital fitness and wellness content, and best-in-class fitness experts and Instructors..
Peloton is an equal opportunity employer and committed to creating an inclusive environment for all of our applicants. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
Please be aware that fictitious job openings, consulting engagements, solicitations, or employment offers may be circulated on the Internet in an attempt to obtain privileged information, or to induce you to pay a fee for services related to recruitment or training. Peloton does NOT charge any application, processing, or training fee at any stage of the recruitment or hiring process. All genuine job openings will be posted here on our careers page and all communications from the Peloton recruiting team and/or hiring managers will be from an @onepeloton.com email address.Â
If you have any doubts about the authenticity of an email, letter or telephone communication purportedly from, for, or on behalf of Peloton, please email [email protected] before taking any further action in relation to the correspondence.
Peloton does not accept unsolicited agency resumes. Agencies should not forward resumes to our jobs alias, Peloton employees or any other organization location. Peloton is not responsible for any agency fees related to unsolicited resumes.
Date Posted
10/14/2022
Views
5
Similar Jobs
Senior Product Designer - Org & Security - Typeform
Views in the last 30 days - 0
This job description outlines a role in developing an intelligent contact management system with AI capabilities The position involves designing user ...
View DetailsRecovery Analyst Underpayments - Trend Health Partners
Views in the last 30 days - 0
TREND Health Partners seeks an Underpayment Recovery Analyst to optimize client reimbursement through collaboration and detailed claim analysis The ro...
View DetailsSenior Business Analyst - Xpansiv
Views in the last 30 days - 0
Xpansiv promotes its role as an energy market innovator with a global platform for environmental commodities The job posting seeks a Business Analyst ...
View DetailsFraud Investigation Analyst - Vonage
Views in the last 30 days - 0
The text describes the Trust Safety Teams mission to protect Vonages services from fraud and abuse detailing their proactive monitoring fraud detecti...
View DetailsSenior Design Manager (Infrastructure) - Canonical
Views in the last 30 days - 0
Canonical a leading opensource provider seeks a Senior Design Manager to drive innovation in cloud and AI technologies The role offers remote work glo...
View DetailsExecutive Director Patient Advocacy - Kyverna Therapeutics
Views in the last 30 days - 0
Kyverna Therapeutics is seeking an Executive Director for Patient Advocacy to lead initiatives in autoimmune disease treatment The role involves build...
View Details