Rippling

Senior Security Engineer - Detection & Response

Rippling$168K — $280K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years as a security engineer focused on monitoring, incident response, and threat hunting.
  • Proficiency in developing automation tools, preferably using Python.
  • Strong understanding of attack tactics, techniques, and procedures (TTPs) including MITRE ATT&CK.
  • Experience in large-scale data analysis and modeling.
  • Expertise in macOS, Windows, and Linux forensics.
  • Familiarity with current SIEM and SOAR platforms.
  • Ability to analyze endpoint, network, and application logs for anomalies.

Responsibilities

  • Design and implement tools for gathering security telemetry data.
  • Automate workflows to improve speed and accuracy in event identification.
  • Develop and refine detection rules against emerging cyber threats.
  • Drive continuous improvement in detection and response technologies.
  • Lead development in SIEM, Case Management, and Automation frameworks.
  • Create detailed documentation for runbooks and incident playbooks.
  • Conduct proactive threat hunting to identify potential attack vectors.

Benefits

  • In-office collaboration with specified onsite work expectations based on distance to office.
  • Access to a competitive salary, benefits, and equity package.
Full Job Description
About The Role

We are looking for a hands-on Senior Detection and Response Security Engineer to be a critical force in driving Rippling's security program forward. This role offers the opportunity to revolutionize our detection and response strategies through advanced automation, strategic data collection, and innovative detection logic. You will collaborate with our talented security team and broader engineering org to elevate and enhance our security efforts.

What You'll Do

  • Innovative Tool Development: Design and implement sophisticated tools to gather security telemetry data from cloud production systems, enhancing our ability to detect and respond to threats.
  • Automation and Optimization: Lead the charge in automating workflows, significantly improving the speed and accuracy of security event identification and response.
  • Detection Rule Development: Build and refine advanced detection rules to protect against emerging cyber threats.
  • Process and Technology Enhancement: Drive continuous improvement of processes, procedures, and technologies used for detection and response.
  • Strategic Development: Spearhead advancements in Security Incident and Event Management (SIEM), Case Management, and Automation frameworks.
  • Comprehensive Documentation: Develop detailed runbooks and incident playbooks for both new and existing detections.
  • Proactive Threat Hunting: Lead threat hunting initiatives, uncovering potential attack vectors and integrating findings into security controls.

Qualifications

  • Extensive Expertise: 4+ years of full-time experience as a security engineer, with a focus on security monitoring, incident response, and threat hunting.
  • Programming Skills: Proficiency in developing tools and automation using common DevOps toolsets, with a preference for Python.
  • Deep Technical Knowledge: Practical understanding of common attacks, adversary tactics, techniques, and procedures (TTPs), and MITRE ATT&CK principles.
  • Analytical Proficiency: Hands-on experience with large-scale data analysis, modeling, and correlation.
  • Cross-Platform Forensics: Expertise in operating systems internals and forensics for macOS, Windows, and Linux.
  • Platform Management: Experience managing and working with current SIEM and SOAR platforms.
  • Log Analysis Expertise: Ability to analyze endpoint, network, and application logs for anomalous events.


Additional Information

Rippling highly values in-office collaboration. Employees living within 30 miles of an office are expected to work onsite three days a week with those living 30-49.9 miles away expected to be in the office one day a week. Employees living over 50 miles away are required to relocate within 30 miles of an office. To enhance team cohesiveness, new employees are asked to work onsite three days a week for their first six months.

This role will receive a competitive salary + benefits + equity. The salary for US-based employees will be aligned with one of the ranges below based on location; see which tier applies to your location here.

A variety of factors are considered when determining someone's compensation-including a candidate's professional background, experience, and location. Final offer amounts may vary from the amounts listed below.

The pay range for this role is:

168,000 - 280,000 USD per year (US Tier 1)

151,200 - 252,000 USD per year (US Tier 2)

About Rippling

Rippling is a technology company that provides a platform for managing human resources. The company's platform includes tools for onboarding new employees, managing payroll and benefits, and tracking time off. Rippling was founded in 2017 by Parker Conrad, who previously founded Zenefits. The company is headquartered in San Francisco, California.
Learn more about Rippling
Size
200 employees
Industry
Founded
2017

Similar Jobs

More Jobs at Rippling

More Information Technology Jobs

Find similar Senior Security Engineer - Detection & Response jobs: