Full-Time

Staff Application Security Engineer

Posted on 3/10/2025

Peloton

Peloton

1,001-5,000 employees

Offers indoor cycling and fitness subscriptions

Compensation Overview

$215k - $290.3k/yr

+ Annual Equity Awards + Employee Stock Purchase Plan

Senior, Expert

Company Historically Provides H1B Sponsorship

New York, NY, USA

The job is hybrid, requiring some in-office presence at the New York City headquarters.

Category
Cybersecurity
IT & Security
Required Skills
Python
Requirements
  • 7+ years of application security experience
  • 2+ years experience with understanding devsecops pipelines
  • Has proven experience in security automation, DevSecOps, SRE, or a similar role.
  • Working knowledge of one or more general purpose programming/script languages, preferably Python
  • Has a solid understanding of cybersecurity threats, vulnerabilities, and mitigations.
  • Has excellent problem-solving skills, with the ability to work independently and handle multiple tasks.
  • Experience writing software that enables security processes
  • Breadth of applied knowledge across application and infrastructure security
  • Exceptional ability to build relationships across diverse multi-functional teams.
  • Exceptional written/oral communication skills.
  • Exceptional bias for action and ownership.
Responsibilities
  • Security Design Reviews/threat models: Ensure security guarantees are integrated into products by conducting thorough reviews of design and implementations.
  • Developer Guidance: Provide guidance and education to engineering and product teams on available security controls and their appropriate use to help prevent vulnerabilities.
  • Collaboration with Engineering Teams: Partner closely with product and engineering teams to design solutions that are secure by default.
  • Expertise in Web and Mobile Security: Serve as a trusted advisor, offering web and mobile security expertise to enable engineering and product teams to make informed, confident decisions.
  • Automated Analysis and Secure Frameworks: Scale security efforts by integrating automation for the identification, prioritization, and remediation of vulnerabilities. Empower engineering teams through automation, security guidance, tooling, patterns, and training to scale security practices across the organization.
Desired Qualifications
  • 3+ years experience with software development preferred but not required
  • Contributions to the security community (public research, blogging, presentations, bug bounty, etc.) would be a plus.
  • The capability to establish clear next steps when facing uncertain situations without clear lines of ownership.
  • An ability to think creatively and holistically about reducing risk in a complex environment.
  • Demonstrates a focused approach, consistently achieving measurable improvements to the security posture of applications and systems.

Peloton provides high-energy indoor cycling workouts through its exercise bike, which streams live and on-demand classes to users' homes. The bike features a large screen for classes led by professional instructors, catering to all fitness levels. Peloton's business model combines hardware sales with a subscription service for access to its extensive library of classes, creating a steady revenue stream. The company's goal is to offer a convenient and engaging way for people to work out at home, building a loyal community of fitness enthusiasts.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

New York City, New York

Founded

2011

Simplify Jobs

Simplify's Take

What believers are saying

  • AI-driven personalized fitness plans could enhance user engagement and retention.
  • Partnerships with educational institutions enhance brand visibility and community engagement.
  • New fitness modalities like kettlebell training diversify offerings and attract varied users.

What critics are saying

  • Echelon's AI chatbot may draw users away with its unique voice interaction feature.
  • Closure at Bellevue Square indicates challenges in maintaining physical retail presence.
  • Leadership changes may lead to strategic shifts affecting company stability.

What makes Peloton unique

  • Peloton merges high design with technology for a unique fitness experience.
  • Offers live and on-demand classes led by elite NYC instructors.
  • Combines hardware, software, and content for an efficient workout experience.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Comprehensive health & life benefits

Supporting families

Future planning

Education

Product discounts

Supporting our communities

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

0%
The Clip Out
Apr 21st, 2025
FTP Test on Peloton: What You Need to Know

This week, Peloton is set to launch a new Power Zone program that combines live and on-demand classes called "Boost Your Base," along with a badge and flash challenge.

PeloBuddy
Apr 17th, 2025
Peloton Can (Manually) Refresh Daily Streaks to Award New 75, 100, 150, 250 Day Daily Streak Badges

Last month Peloton launched a new expanded set of daily streak achievement badges - a fun incentive for those who have been consistent about showing up day after day, whether on their Peloton hardware device or the digital app.

On Partners
Apr 16th, 2025
Peloton Announces New Chief Operating Officer and Additional Leadership Changes To Lay the Foundation for Growth

Charles Kirol joins Peloton as Chief Operating Officer.

SGB Media
Apr 9th, 2025
Peloton Names Chief Operating Officer and Chief Commercial Officer

Peloton also named Chief Emerging Business Officer Dion Camp Sanders chief commercial officer, "recognizing [his] central role in returning Peloton to growth, including his responsibility for first-party retail, inside sales, third-party retail, bike rental and sales of pre-owned refurbished equipment, international strategy and operations, B2B channels, Precor, M&A, and business development."

PYMNTS
Mar 25th, 2025
Echelon’S New Ai Chatbot Targets Consumer Retention Through Hyper-Personalized Fitness

Echelon Fitness is rolling out a generative artificial intelligence (GenAI) assistant for the users of its fitness equipment that adds a unique personalization capability: You can “talk” to a chatbot to make changes to your custom workout plan. See too many 45-minute workouts in the schedule? Audibly tell the AI to swap those out with shorter regimens, just like one would speak to ChatGPT. Going on a business trip? Tell the AI to only schedule exercises that don’t require gym equipment for the days you’re out of town. The launch comes at a time of increasing interest in AI-powered fitness capabilities, such as those offered by Peloton, Google Coach, Strava and others. While many fitness companies or apps use AI to customize workouts for the individual, most don’t offer a voice conversational AI

INACTIVE