SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Rippling is seeking a Principal Security Engineer to lead high-impact security initiatives across the company's technical ecosystem. Reporting directly to the Chief Security Officer, you will tackle complex, cross-cutting security challenges spanning security architecture, AI/ML integration, infrastructure, identity, developer experience, internal tooling, and third-party SaaS systems.
This is a deeply technical, hands-on role for an engineer who can move fluidly between system architecture and implementation. You will take ambiguous security problems that cross organizational and technical boundaries, develop cohesive technical strategies, and work alongside engineering teams to build and ship solutions.
Key responsibilities include:
- Lead the architecture and implementation of complex security initiatives spanning multiple engineering teams and technical domains
- Incorporate agentic AI technologies into security capabilities within both product and infrastructure
- Replace traditional RBAC for internal system access with a minimal-privilege, just-in-time (JIT) system using real-time agentic inspection of employee graph data, system alerts, incidents, customer requests, and support tickets
- Integrate the JIT access control system into all third-party tools (e.g., SaaS applications) used by Rippling, and work with the product team to enable this for Rippling customers
- Design and build robust inter-service isolation, sandboxing, and AuthN/Z to manage product attack surface, 0-day blast radius, and limit lateral movement
- Help business leaders understand and navigate risk tradeoffs to ensure well-informed security decisions
- Design scalable security systems across identity and access management, cloud infrastructure, internal tooling, developer infrastructure, and third-party SaaS
- Translate ambiguous security problems into clear technical architectures, roadmaps, and executable engineering plans
- Rationalize requirements and technical roadmaps across multiple teams into cohesive systems
- Partner with senior engineers and leaders across Security, Infrastructure, Developer Experience, IT, and Product to drive alignment on critical technical decisions
- Build prototypes, write production code, and remain hands-on throughout the lifecycle of systems you design
- Identify architectural weaknesses and systemic security risks before they become incidents
- Establish technical patterns and frameworks that improve security while allowing engineering teams to move quickly
- Raise the technical bar across the security organization through design reviews, mentorship, and influence
About Rippling: Rippling provides a unified platform for HR, IT, and Finance, bringing together workforce systems like payroll, expenses, benefits, and computer management. The company has raised $1.4B+ from top investors including Kleiner Perkins, Founders Fund, Sequoia, Greenoaks, and Bedrock, and was named one of America's best startup employers by Forbes.
The Security team is responsible for protecting a platform that sits at the center of how companies manage their workforce, systems, and data. Work touches nearly every part of Rippling's technical environment and requires close partnership across Engineering, Infrastructure, Developer Experience, IT, and Product. As a Principal Security Engineer, you will operate horizontally across these organizations rather than within a narrow security domain.
Rippling values engineers who combine strong technical judgment with urgency, ownership, and a bias toward action.
REQUIREMENTS:
- Significant experience designing, building, and operating complex systems in large-scale cloud or enterprise environments
- Track record of leading technically complex initiatives involving multiple engineering teams, competing requirements, and cross-functional stakeholders
- Deep expertise in one or more security domains, with identity and access management (IAM), authentication, authorization, or identity architecture experience particularly relevant
- Strong understanding of modern cloud and enterprise architecture, including security boundaries, workload isolation, service-to-service communication, and access-control systems
- Recent hands-on engineering experience and ability to prototype, write code, and work directly with modern development tooling
- Experience building defensive agentic systems and integrating them with dynamic software development and operations
- Ability to move fluidly between high-level system architecture and detailed implementation decisions
- Strong technical judgment and ability to make pragmatic tradeoffs between security, scalability, developer experience, and business needs
- Demonstrated ability to influence senior technical stakeholders without relying on organizational authority
- High degree of ownership, urgency, and bias toward action in ambiguous environments
- 10+ years of experience solving complex engineering and security problems (experience and trajectory matter more than specific years)