Staff Security Engineer
THE WORK:
As a Staff Security Engineer on the Security Operations team, you will help Ripple detect, investigate, and respond to security threats across our environment. You'll work across detection and data engineering, incident response, and security automation — building the tooling and detection logic that lets the team scale. You'll operate independently on sophisticated investigations and detection initiatives, and you'll be a technical reference point for less senior engineers on the team.
WHAT YOU’LL DO:
Design, build, and tune detections across our security stack (Google Security Operations) to improve our ability to identify and mitigate threats.
Lead incident response for the most complex and high-severity investigations, from initial triage through root cause and remediation.
Build and maintain security automation workflows (e.g., in Tines) that reduce manual toil in detection, triage, and response.
Own and improve SIEM/data pipeline health, including log source coverage, parsing/normalization, and alert quality.
Develop cross-functional relationships to influence security initiatives and drive adoption of security tooling.
Maintain awareness of the evolving threat landscape and translate that awareness into concrete improvements to our detection coverage and response playbooks.
Use AI tools as more than a chatbot — agentic coding tools like Claude Code or OpenAI Codex for detection engineering and automation work — while knowing when a given tool is (and isn't) the right fit, and verifying output before it ships.
Participate in the design review process, giving and receiving constructive feedback to keep detection and automation projects on track — and break complex detection challenges into simple systems and repeatable processes other engineers can build and maintain.
WHAT YOU'LL BRING:
7+ years of experience in security operations, detection engineering, or incident response, with a track record of owning incident response and detection work end-to-end.
Advanced knowledge of security principles, tools, and practices used in blue teaming operations, with advanced proficiency in at least one scripting language for tasks like response automation and using REST APIs to automate security operations work.
Experience with SIEM platforms and security data pipelines (e.g., Google SecOps) — you understand log source onboarding, parsing, and alert tuning, not just querying.
Hands-on experience with EDR, identity, email security, and network security tooling at a level where you can extend and tune the tooling, not just operate it.
Ability to write clean technical specs, identify risks before starting major projects, and reason clearly about trade-offs between alternative approaches.
Ability to break down complex projects into simple systems and repeatable processes that other engineers can build and maintain, and to seek and give constructive feedback in design review.
Problem-solving skills to resolve ambiguous or high-pressure situations effectively and creatively, while maintaining flexibility, professionalism, and integrity.
Understands and anticipates people's needs, skills, and abilities, to coach, motivate, and empower them for success.