SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Ripple is seeking a Senior Staff Security Engineer to serve as the dedicated security partner for Ripple Treasury, a financial infrastructure product. This is a senior technical security role operating at the intersection of application security, cloud infrastructure security, and secure software delivery.
You will own the security posture of the Treasury solution and infrastructure environment, leading threat modeling and security architecture reviews across Treasury offerings. Key responsibilities include:
- Serve as the dedicated Security Engineering partner for Treasury, owning security posture from assessment through remediation and ongoing maturity improvement
- Lead threat modeling and security architecture reviews using STRIDE or equivalent methodologies
- Own the secure software development lifecycle, defining security guardrails, CI/CD integrations, and developer guidance
- Drive cloud security architecture across Azure and AWS, including IAM, network segmentation, encryption, zero trust controls, Kubernetes policies, and DDoS/WAF strategy
- Partner with GRC to ensure compliance with SOC 2, ISO 27001, and financial regulatory frameworks
- Own vulnerability discovery via security assessments, penetration testing, and bug bounty programs
- Build and scale a Security Champions model within Treasury Engineering
- Influence senior-level engineering architecture decisions and participate in design reviews
- Mentor and develop Security Engineers, raising technical standards
- Stay ahead of threat landscape for FinTech, crypto, and enterprise treasury systems
Required qualifications: 10+ years of Security Engineering experience with hands-on product and infrastructure security work. Expert-level product security skills including threat modeling, security architecture review, OWASP Top 10, API security, and secure SDLC. Deep expertise securing cloud environments (Azure, AWS, GCP) covering IAM, network security, secrets management, container/Kubernetes security, and IaC security. Hands-on experience building DevSecOps tooling including SAST, DAST, SCA, secrets scanning, and CI/CD integration. Strong software engineering skills in Python, Go, or equivalent. Experience with cryptographic principles, key management, HSMs, MPC, and PKI. Background in FinTech, crypto, blockchain, or high-stakes financial environments is a strong plus. Practitioner's approach—most effective when close to the work, writing threat models, reviewing architecture, reading code, and building tooling.