SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Ripple is seeking a Staff Security Engineer to join the Security Operations team in London. In this role, you will be a technical leader responsible for detecting, investigating, and responding to security threats across the organization's environment. You'll operate independently on sophisticated investigations and serve as a technical reference point for junior engineers.
Key responsibilities include designing and tuning detections across Google Security Operations to identify and mitigate threats; leading incident response for complex, high-severity investigations from triage through remediation; building and maintaining security automation workflows in Tines to reduce manual work; owning SIEM and data pipeline health including log source coverage and alert quality; and developing cross-functional relationships to drive security initiatives. You'll maintain awareness of the evolving threat landscape and translate that into concrete improvements to detection coverage and response playbooks. The role emphasizes using AI tools strategically for detection engineering and automation while maintaining critical judgment about tool appropriateness and output verification.
You'll participate in design reviews, providing and receiving constructive feedback to keep projects on track, and breaking down complex detection challenges into simple, maintainable systems that other engineers can build upon.
Required qualifications include 7+ years in security operations, detection engineering, or incident response with a track record of owning end-to-end incident response and detection work. You need advanced knowledge of blue teaming security principles and tools, with advanced proficiency in at least one scripting language for automation and REST API work. Experience with SIEM platforms and security data pipelines (particularly Google SecOps) is essential, including hands-on understanding of log onboarding, parsing, and alert tuning. You should have hands-on experience with EDR, identity, email security, and network security tooling at a level where you can extend and tune tools. Strong technical communication skills, ability to write clear specs, identify project risks, and reason about trade-offs are critical. You should excel at breaking down complex projects into repeatable processes and seeking constructive feedback. Problem-solving skills for ambiguous, high-pressure situations with flexibility and integrity are essential, along with the ability to coach, motivate, and empower team members.