Senior Security Engineer - Detection & Response
Listed on 2026-09-14
-
IT/Tech
Cybersecurity
Senior Security Engineer - Detection & Response
Rippling Seattle, Washington, United States
About this position About RipplingRippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and computers. For the first time ever, you can manage and automate every part of the employee lifecycle in a single system.
Take onboarding, for example. With Rippling, you can hire a new employee anywhere in the world and set up their payroll, corporate card, computer, benefits, and even third-party apps like Slack and Microsoft 365—all within 90 seconds.
Based in San Francisco, CA, Rippling has raised $1.4B+ from the world’s top investors—including Kleiner Perkins, Founders Fund, Sequoia, Greenoaks, and Bedrock—and was named one of America's best startup employers by Forbes.
We prioritize candidate safety. Please be aware that all official communication will only be sent from @ addresses.
AboutThe Role
We are looking for a hands‑on Senior Detection and Response Security Engineer to be a critical force in driving Rippling's security program forward. This role offers the opportunity to revolutionize our detection and response strategies through advanced automation, strategic data collection, and innovative detection logic. You will collaborate with our talented security team and broader engineering org to elevate and enhance our security efforts.
WhatYou'll Do
- Innovative Tool Development: Design and implement sophisticated tools to gather security telemetry data from cloud production systems, enhancing our ability to detect and respond to threats.
- Automation and Optimization: Lead the charge in automating workflows, significantly improving the speed and accuracy of security event identification and response.
- Detection Rule Development: Build and refine advanced detection rules to protect against emerging cyber threats.
- Process and Technology Enhancement: Drive continuous improvement of processes, procedures, and technologies used for detection and response.
- Strategic Development: Spearhead advancements in Security Incident and Event Management (SIEM), Case Management, and Automation frameworks.
- Comprehensive Documentation: Develop detailed runbooks and incident playbooks for both new and existing detections.
- Proactive Threat Hunting: Lead threat hunting initiatives, uncovering potential attack vectors and integrating findings into security controls.
- Extensive Expertise: 4+ years of full-time experience as a security engineer, with a focus on security monitoring, incident response, and threat hunting.
- Programming
Skills:
Proficiency in developing tools and automation using common Dev Ops toolsets, with a preference for Python. - Deep Technical Knowledge: Practical understanding of common attacks, adversary tactics, techniques, and procedures (TTPs), and MITRE ATT&CK principles.
- Analytical Proficiency: Hands‑on experience with large-scale data analysis, modeling, and correlation.
- Cross-Platform Forensics: Expertise in operating systems internals and forensics for macOS, Windows, and Linux.
- Platform Management: Experience managing and working with current SIEM and SOAR platforms.
- Log Analysis Expertise: Ability to analyze endpoint, network, and application logs for anomalous events.
Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).