SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Engineer

Ripple - San Francisco, CA, United States - Hybrid - posted 2026-09-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 172,000 - 215,000 / annual

Ripple is building infrastructure for global financial value movement through crypto solutions for institutions, businesses, governments, and developers. As a Senior Security Engineer on the Security Operations team, you will be a key technical contributor responsible for detecting, investigating, and responding to security threats across the company's environment. You will operate independently on sophisticated investigations and detection initiatives while serving as a technical reference point for less senior engineers. Your work spans detection and data engineering, incident response, and security automation—building the tooling and detection logic that enables the team to scale. Key responsibilities include: - Design, build, and tune detections across the security stack (Google Security Operations) to identify and mitigate threats - Lead incident response for sophisticated and high-severity investigations from initial triage through root cause analysis and remediation - Build and maintain security automation workflows (e.g., in Tines) to reduce manual toil in detection, triage, and response - Own and improve SIEM/data pipeline health, including log source coverage, parsing/normalization, and alert quality - Develop cross-functional relationships with IT, engineering, and other teams to influence security initiatives and drive tooling adoption - Maintain awareness of the evolving threat landscape and translate it into concrete improvements to detection coverage and response playbooks - Leverage AI tools (agentic coding tools like Claude Code or OpenAI Codex) for detection engineering and automation while verifying output quality - Mentor and provide technical guidance to less experienced engineers The role offers hybrid flexibility with 10+ in-office days per month at the San Francisco office, allowing teams to decide when collaboration matters most. REQUIREMENTS: - 5+ years of experience in security operations, detection engineering, or incident response, with a track record of owning incident response and detection work end-to-end - Advanced knowledge of security principles, tools, and practices used in detection and response operations - Strong scripting/automation skills (Python or SOAR); comfortable building and maintaining automation for response workflows and working with REST APIs to connect security tools - Experience with SIEM platforms and security data pipelines (e.g., Google SecOps); understanding of log source onboarding, parsing, and alert tuning, not just querying - Hands-on experience with EDR, identity, email security, and network security tooling at a level where you can extend and tune the tooling, not just operate it - Ability to write clean technical specs, identify risks before starting major projects, and reason clearly about trade-offs between alternative approaches - Problem-solving skills to resolve ambiguous or high-pressure situations effectively and creatively while maintaining flexibility, professionalism, and integrity - Ability to understand and anticipate people's needs, skills, and abilities to coach, motivate, and empower them for success

Similar roles