Security GRC Senior Analyst

Peloton · Remote

Company

Peloton

Location

Remote

Type

Full Time

Job Description

ABOUT THE ROLE

Peloton inspires and motivates millions of people every day. A key part of delivering on that mission is not only an outstanding experience that our instructors and platforms provide, but also the data, telemetry, and insights that empower our members to be the best version of themselves anywhere, anytime. Earning and maintaining our members’ trust and safeguarding their data is key to everything we do.

The Security Governance, Risk & Compliance (GRC) Analyst is a critical position within the team, and has risk and compliance responsibilities from a technology and security perspective across the organization globally. The main objective of the Security GRC team is to deliver best in class Security Governance, Risk and Compliance, services to ensure that Peloton operates in a risk mitigated, security managed environment and that Peloton’s security compliance objectives are being met. Their responsibilities span Peloton’s products and services and the internal applications, tools, and infrastructure that support them.

YOUR DAILY IMPACT AT PELOTON:

  • Lead the strategy, approach, and compliance activities for Peloton’s compliance to PCI DSS.
  • Execute multiple PCI DSS control validation programs simultaneously with specific deadlines. 
  • Manage the progress of remediation steps on identified control deficiencies.
  • Ensure reports and findings are delivered in a timely and appropriate manner to management.
  • Coordinate certified PCI ASV scans, ensure passing scan for each quarter, and drive remediation of scans.
  • Advise on proposed security tool and process changes that could impact PCI DSS compliance.
  • Knowledge of all requirements of PCI DSS v3.2.1 with some knowledge of the changes in PCI DSS v4.0.
  • Administer the annual PCI DSS assessment process with our Qualified Security Assessor (PCI QSA).

YOU BRING TO PELOTON:

  • 6+ years of experience executing PCI DSS compliance programs.
  • Highly organized, motivated, and detail-oriented with the ability to work independently in a fast-paced environment. 
  • Flexible and able to adapt quickly in a fast-moving environment. 
  • Excellent problem-solving skills and ability to manage competing priorities and deadlines.
  • Strong degree of comfort working alongside, engaging and communicating with senior software engineering and business-side stakeholders. 
  • Must have familiarity with systems, networks, and a variety of the security concepts, practices, and procedures.
  • Must be able to read and interpret network diagrams and technical architecture drawings.
  • Experience developing, championing, and managing complex internal and external compliance efforts.
  • Ability to work independently and effectively with all levels of staff and management both internally and externally.
  • Expert knowledge of the ISO, COBIT and PCI DSS control frameworks is expected.
  • One or more of the following certifications is preferred: CISA, CISM, CRISC, CISSP. 

#LI-SV2 #LI-Remote

ABOUT PELOTON:

Peloton is the leading interactive fitness platform globally, with a passionate community of 7 million Members in the US, UK, Canada, Germany, and Australia. Peloton makes fitness entertaining, approachable, effective, and convenient, while fostering social connections that motivate its Members to commit to their fitness journeys. An innovator at the nexus of fitness, technology, and media, Peloton reinvented the fitness industry by developing a first-of-its-kind subscription platform that seamlessly combines the best equipment, proprietary networked software, world-class streaming digital fitness and wellness content, and best-in-class fitness experts and Instructors.

At Peloton, we motivate the world to live better. “Together We Go Far” means that we are greater than the sum of our parts, stronger collectively when each one of us is at our best. By combining hardware, software, content, retail, apparel, manufacturing, Member support, and so much more, we deliver an exhilarating fitness experience that unlocks our members' greatness. Join our team to unlock yours.

Peloton is an equal opportunity employer and committed to creating an inclusive environment for all of our applicants. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. If you would like to request any accommodations from application through to interview, please email:  [email protected]

Peloton has a COVID-19 vaccination policy to safeguard the health and well-being of our employees and customers globally. All employees based in the U.S. and Canada are required to provide proof of vaccination, unless the employee has a Peloton-approved reasonable accommodation or as otherwise required by law.

Peloton values the side-by-side collaboration that comes with working together in an office. Our Hybrid Working Policy requires team members in US office-based roles to be in the office every Tuesday, Wednesday and Thursday.

Please be aware that fictitious job openings, consulting engagements, solicitations, or employment offers may be circulated on the Internet in an attempt to obtain privileged information, or to induce you to pay a fee for services related to recruitment or training. Peloton does NOT charge any application, processing, or training fee at any stage of the recruitment or hiring process. All genuine job openings will be posted here on our careers page and all communications from the Peloton recruiting team and/or hiring managers will be from an @onepeloton.com email address. 

If you have any doubts about the authenticity of an email, letter or telephone communication purportedly from, for, or on behalf of Peloton, please email [email protected] before taking any further action in relation to the correspondence.

Peloton does not accept unsolicited agency resumes. Agencies should not forward resumes to our jobs alias, Peloton employees or any other organization location. Peloton is not responsible for any agency fees related to unsolicited resumes.

Apply Now

Date Posted

09/19/2022

Views

6

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Senior Product Designer - Org & Security - Typeform

Views in the last 30 days - 0

This job description outlines a role in developing an intelligent contact management system with AI capabilities The position involves designing user ...

View Details

Senior Business Analyst - Xpansiv

Views in the last 30 days - 0

Xpansiv promotes its role as an energy market innovator with a global platform for environmental commodities The job posting seeks a Business Analyst ...

View Details

Senior Design Manager (Infrastructure) - Canonical

Views in the last 30 days - 0

Canonical a leading opensource provider seeks a Senior Design Manager to drive innovation in cloud and AI technologies The role offers remote work glo...

View Details

Recovery Analyst Underpayments - Trend Health Partners

Views in the last 30 days - 0

TREND Health Partners seeks an Underpayment Recovery Analyst to optimize client reimbursement through collaboration and detailed claim analysis The ro...

View Details

Senior Specialist Senior Accountant Shared Financial Services - Make-A-Wish America

Views in the last 30 days - 0

The text describes Make a Wish Foundations mission to grant childrens wishes and their community efforts It outlines job positions with remotehybrid o...

View Details

Fraud Investigation Analyst - Vonage

Views in the last 30 days - 0

The text describes the Trust Safety Teams mission to protect Vonages services from fraud and abuse detailing their proactive monitoring fraud detecti...

View Details