Rippling

Staff Product Security Engineer

Rippling$189K — $315K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in product security roles
  • Proven experience leading architectural security changes
  • In-depth knowledge of web application security
  • Fluency in Python, React, and Django Rest Framework
  • Skilled in manual source code reviews and securing production code
  • Experience deploying application security tools in CI/CD pipelines
  • Expertise in embedding security within the software development lifecycle

Responsibilities

  • Establish guardrails and controls to eliminate vulnerabilities in Rippling's application
  • Create security tools and automations for scaling security practices
  • Conduct threat modeling for application designs and deliver security assessments
  • Audit source code and review critical application changes
  • Guide software engineering teams on security best practices
  • Provide remediation guidance to development teams
  • Ensure security integration within software development processes
  • Develop security measures throughout the Software Development Life Cycle

Benefits

  • Competitive salary
  • Equity options
  • Required in-office collaboration for employees within specific distance
  • Focus on team cohesiveness and collaboration for new employees
  • Support for relocation for remote employees engaging in onsite work
Full Job Description
About The Role

We're looking for a hands-on staff security engineer to play a key role in building Rippling's Product Security program. Rippling's product's scope provides a unique set of security challenges, but our management is especially supportive of security and compliance as a central function of the business. As an early member of Rippling's security team, you'll have a meaningful impact on the security program's priorities and direction.

About The Team

We are a diverse team of skilled security engineers that are passionate about pushing the boundaries of security practices. We look to collaborate with our Engineering partners to find the right solution for our interesting challenges. Our team thrives on re-imagining approaches to traditional security to secure our vast ecosystem.

Our achievements are shared through our blogs and at conferences and meetups.

A little more about our team:

  • Our Infrastructure Security team shared a blog about how they streamlined AWS access
  • We spoke at BSides SF about attacking and defending infrastructure with terraform
  • Our Product Security lead talked about the Future Application Security Engineers
  • Our Security Engineering lead talk about an innovative way to reduce vulnerabilities in your organization

What You'll Do

  • Build guardrails and controls to eliminate full classes of vulnerabilities within the Rippling application
  • Build security tooling and automations to help scale the Product Security team's practices
  • Threat-model application designs and solutions and provide security assessments.
  • Audit source code and perform code review for critical application changes
  • Mentor software engineering teams in security best practices
  • Provide hands-on remediation guidance to development teams
  • Review & establish software development practices that make security an essential part of the development process
  • Develop / Integrate security into the Software Development Life Cycle

Qualifications

  • 10+ years of experience in an product security role
  • Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities
  • Deep understanding of securing web applications
  • Fluency in Python, React, and Django Rest Framework
  • Experience with manual source code review, and embedding security to code in production environments.
  • Experience with deploying application security tools in the CI/CD pipeline
  • Experience with securing software development lifecycle including building programs that eliminate full classes of vulnerabilities

Bonus Points

  • Good understanding of SSO, including OAUTH, SAML
  • Experience with speaking at meetups or conferences
  • Experience running a bug bounty program


Additional Information

Rippling highly values in-office collaboration. Employees living within 30 miles of an office are expected to work onsite three days a week with those living 30-49.9 miles away expected to be in the office one day a week. Employees living over 50 miles away are required to relocate within 30 miles of an office. To enhance team cohesiveness, new employees are asked to work onsite three days a week for their first six months.

This role will receive a competitive salary + benefits + equity. The salary for US-based employees will be aligned with one of the ranges below based on location; see which tier applies to your location here.

A variety of factors are considered when determining someone's compensation-including a candidate's professional background, experience, and location. Final offer amounts may vary from the amounts listed below.

The pay range for this role is:

189,000 - 315,000 USD per year (US Tier 1)

About Rippling

Rippling is a technology company that provides a platform for managing human resources. The company's platform includes tools for onboarding new employees, managing payroll and benefits, and tracking time off. Rippling was founded in 2017 by Parker Conrad, who previously founded Zenefits. The company is headquartered in San Francisco, California.
Learn more about Rippling
Size
200 employees
Industry
Founded
2017

Similar Jobs

More Jobs at Rippling

More Information Technology Jobs

Find similar Staff Product Security Engineer jobs: