Senior Security Engineer

Ripple · San Francisco, CA, United States · Engineering

Posted 2026-09-30

Apply for this role →

THE WORK:

As a Senior Security Engineer on the Security Operations team, you will help Ripple detect, investigate, and respond to security threats across our environment. You'll work across detection and data engineering, incident response, and security automation — building the tooling and detection logic that lets the team scale. You'll operate independently on sophisticated investigations and detection initiatives, and you'll be a technical reference point for less senior engineers on the team.

WHAT YOU’LL DO:

Design, build, and tune detections across our security stack (Google Security Operations) to improve our ability to identify and mitigate threats.

Lead incident response for sophisticated and high-severity investigations, from initial triage through root cause and remediation.

Build and maintain security automation workflows (e.g., in Tines) that reduce manual toil in detection, triage, and response.

Own and improve SIEM/data pipeline health, including log source coverage, parsing/normalization, and alert quality.

Develop cross-functional relationships (IT, engineering, other Ripple teams) to influence security initiatives and drive adoption of security tooling.

Maintain awareness of the evolving threat landscape and translate that awareness into concrete improvements to our detection coverage and response playbooks.

Use AI tools as more than a chatbot — agentic coding tools like Claude Code or OpenAI Codex for detection engineering and automation work — while knowing when a given tool is (and isn't) the right fit, and verifying output before it ships.

Mentor and provide technical guidance to less experienced engineers.

WHAT YOU'LL BRING:

5+ years of experience in security operations, detection engineering, or incident response, with a track record of owning incident response and detection work end-to-end.

Advanced knowledge of security principles, tools, and practices used in detection and response operations.

Strong scripting/automation skills (Python or SOAR) — comfortable building and maintaining automation for response workflows and working with REST APIs to connect security tools.

Experience with SIEM platforms and security data pipelines (e.g., Google SecOps) — you understand log source onboarding, parsing, and alert tuning, not just querying.

Hands-on experience with EDR, identity, email security, and network security tooling at a level where you can extend and tune the tooling, not just operate it.

Ability to write clean technical specs, identify risks before starting major projects, and reason clearly about trade-offs between alternative approaches.

Problem-solving skills to resolve ambiguous or high-pressure situations effectively and creatively, while maintaining flexibility, professionalism, and integrity.

Understands and anticipates people's needs, skills, and abilities, to coach, motivate, and empower them for success.

Other common names for this role: Security Engineer, Incident Response

For positions that will be based in CA, the annual salary range for this position is below. Actual salaries may vary based on numerous factors including, among other things, an individual applicant’s experience and qualifications for the position. This range does not include equity or additional compensation, such as bonuses or commissions.

CA Annual Base Salary Range

$172,000—$215,000 USD

Apply for this role →

← Back to all jobs