SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Rippling is seeking a hands-on Senior Detection and Response Security Engineer to drive the company's security program forward. You will be a critical force in revolutionizing detection and response strategies through advanced automation, strategic data collection, and innovative detection logic, collaborating with Rippling's security team and broader engineering organization.
Key Responsibilities:
- Design and implement sophisticated tools to gather security telemetry data from cloud production systems, enhancing threat detection and response capabilities
- Lead automation and optimization initiatives to improve the speed and accuracy of security event identification and response
- Build and refine advanced detection rules to protect against emerging cyber threats
- Drive continuous improvement of processes, procedures, and technologies used for detection and response
- Spearhead advancements in Security Incident and Event Management (SIEM), Case Management, and Automation frameworks
- Develop detailed runbooks and incident playbooks for both new and existing detections
- Lead threat hunting initiatives to uncover potential attack vectors and integrate findings into security controls
About Rippling:
Rippling provides an integrated platform for HR, IT, and Finance, consolidating workforce systems including payroll, expenses, benefits, and device management. The company has raised $1.4B+ from top-tier investors including Kleiner Perkins, Founders Fund, and Sequoia, and was named one of America's best startup employers by Forbes.
Work Arrangement:
Rippling values in-office collaboration. Employees within 30 miles of an office are expected to work onsite three days per week; those 30-49.9 miles away, one day per week; those over 50 miles away must relocate within 30 miles. New employees work onsite three days per week for their first six months.
Requirements:
- 4+ years of full-time experience as a security engineer, with focus on security monitoring, incident response, and threat hunting
- Proficiency in developing tools and automation using common DevOps toolsets, with preference for Python
- Practical understanding of common attacks, adversary tactics, techniques, and procedures (TTPs), and MITRE ATT&CK principles
- Hands-on experience with large-scale data analysis, modeling, and correlation
- Expertise in operating systems internals and forensics for macOS, Windows, and Linux
- Experience managing and working with current SIEM and SOAR platforms
- Ability to analyze endpoint, network, and application logs for anomalous events