Staff Security Engineer London, UK

Ripple

Greater London

Hybrid

GBP 120,000 - 180,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive salary
Equity
Learning budget
In-office collaboration

Job summary

Ripple in London is seeking a Staff Security Engineer to join the Security Operations team. You will detect, investigate, and respond to threats across the environment, partnering with detection engineering, incident response, and security automation.

You’ll design detections, lead high-severity investigations, build automation with tools like Tines, and own SIEM/data pipelines. You’ll mentor engineers and translate threat intel into concrete improvements.

Qualifications

  • 7+ years in security operations, detection engineering, or incident response.
  • Advanced knowledge of blue team security principles and at least one scripting language.
  • Experience with SIEM and security data pipelines.
  • Hands-on with EDR, identity, email, and network security tooling.
  • Ability to write technical specs and assess risks.
  • Strong ability to break down complex projects into repeatable processes.
  • Strong interpersonal skills and coaching/mentoring.

Responsibilities

  • Design, build, and tune detections across our security stack to improve threat identification and mitigation.
  • Lead incident response for complex, high-severity investigations from triage to remediation.
  • Build and maintain security automation workflows (e.g., in Tines) to reduce manual toil.
  • Own and improve SIEM/data pipeline health, including log onboarding, parsing, and alerting.
  • Develop cross-functional relationships to influence security initiatives and tool adoption.
  • Translate evolving threat landscape into concrete improvements to detection coverage and playbooks.
  • Participate in design reviews and provide constructive feedback to simplify systems.

Skills

Security operations
Detection engineering
Incident response
Scripting (Python/JS)
REST API automation
SIEM platforms
EDR
Identity security
Network security tooling
Threat detection

Tools

Google SecOps
Tines
SIEM tooling

Job description

Please note this is for London, UK. You only need toapply to one location if there are multiple listed for the job.

At Ripple, we’re building a world where value moves like information does today. It’s big, it’s bold, and we’re already doing it. Through our crypto solutions for financial institutions, businesses, governments and developers, we are improving the global financial system and creating greater economic fairness and opportunity for more people, in more places around the world. And we get to do the best work of our career and grow our skills surrounded by colleagues who have our backs.

If you’re ready to see your impact and unlock incredible career growth opportunities, join us, and build real world value.

THE WORK:

As a Staff Security Engineer on the Security Operations team, you will help Ripple detect, investigate, and respond to security threats across our environment. You’ll work across detection and data engineering, incident response, and security automation — building the tooling and detection logic that lets the team scale. You’ll operate independently on sophisticated investigations and detection initiatives, and you’ll be a technical reference point for less senior engineers on the team.

WHAT YOU’LL DO:
  • Design, build, and tune detections across our security stack (Google Security Operations) to improve our ability to identify and mitigate threats.
  • Lead incident response for the most complex and high-severity investigations, from initial triage through root cause and remediation.
  • Build and maintain security automation workflows (e.g., in Tines) that reduce manual toil in detection, triage, and response.
  • Own and improve SIEM/data pipeline health, including log source coverage, parsing/normalization, and alert quality.
  • Develop cross-functional relationships to influence security initiatives and drive adoption of security tooling.
  • Maintain awareness of the evolving threat landscape and translate that awareness into concrete improvements to our detection coverage and response playbooks.
  • Use AI tools as more than a chatbot — agentic coding tools like Claude Code or OpenAI Codex for detection engineering and automation work — while knowing when a given tool is (and isn’t) the right fit, and verifying output before it ships.
  • Participate in the design review process, giving and receiving constructive feedback to keep detection and automation projects on track — and break complex detection challenges into simple systems and repeatable processes other engineers can build and maintain.
WHAT YOU'LL BRING:
  • 7+ years of experience in security operations, detection engineering, or incident response, with a track record of owning incident response and detection work end-to-end.
  • Advanced knowledge of security principles, tools, and practices used in blue teaming operations, with advanced proficiency in at least one scripting language for tasks like response automation and using REST APIs to automate security operations work.
  • Experience with SIEM platforms and security data pipelines (e.g., Google SecOps) — you understand log source onboarding, parsing, and alert tuning, not just querying.
  • Hands‑on experience with EDR, identity, email security, and network security tooling at a level where you can extend and tune the tooling, not just operate it.
  • Ability to write clean technical specs, identify risks before starting major projects, and reason clearly about trade‑offs between alternative approaches.
  • Ability to break down complex projects into simple systems and repeatable processes that other engineers can build and maintain, and to seek and give constructive feedback in design review.
  • Problem‑solving skills to resolve ambiguous or high‑pressure situations effectively and creatively, while maintaining flexibility, professionalism, and integrity.
  • Understands and anticipates people’s needs, skills, and abilities, to coach, motivate, and empower them for success.
WHO WE ARE:

Do Your Best Work

  • The opportunity to build in a fast‑paced start‑up environment with experienced industry leaders
  • A learning environment where you can dive deep into the latest technologies and make an impact. A professional development budget to support other modes of learning.
  • Thrive in an environment where no matter what race, ethnicity, gender, origin, or culture they identify with, every employee is a respected, valued, and empowered part of the team.
  • In‑office collaboration for moments that matter is important to our culture, and we give managers and teams the flexibility to decide which 10+ days a month they come in.
  • Bi‑weekly all‑company meeting - business updates and ask me anything style discussion with our Leadership Team
  • We come together for moments that matter which include team offsites, team bonding activities, happy hours and more!
Take Control of Your Finances
  • Competitive salary, bonuses, and equity
  • Competitive benefits that cover physical and mental healthcare, retirement, family forming, and family support
  • Employee giving match
Take Care of Yourself
  • R&R days so you can rest and recharge
  • Generous wellness reimbursement and weekly onsite & virtual programming
  • Generous vacation policy - work with your manager to take time off when you need it
  • Industry‑leading parental leave policies. Family planning benefits.
  • Catered lunches, fully‑stocked kitchens with premium snacks&beverages, and plenty of fun events

Benefits listed above are for full‑time employees.

Ripple is an Equal Opportunity Employer. We’re committed to building a diverse and inclusive team. We do not discriminate against qualified employees or applicants because of race, color, religion, gender identity, sex, sexual identity, pregnancy, national origin, ancestry, citizenship, age, marital status, physical disability, mental disability, medical condition, military status, or any other characteristic protected by local law or ordinance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer
Staff Security Engineer

Ripple • Greater London

On-site
GBP 120,000 - 180,000
Staff Security Engineer
Staff Security Engineer

Hidden Road • Greater London

Hybrid
GBP 110,000 - 170,000
Bonuses
Equity
Professional development budget
Staff Software Engineer, C++
Staff Software Engineer, C++

Ripple • London

On-site
GBP 60,000 - 120,000
Competitive salary
Bonuses and equity
Generous wellness reimbursement
+7
Staff Software Engineer - Authentication & Authorization London, UK
Staff Software Engineer - Authentication & Authorization London, UK

Ripple • Greater London

On-site
GBP 70,000 - 90,000
Competitive salary
Bonuses and equity
Generous vacation policy
+2
Senior Staff Security Engineer, AI Security
Senior Staff Security Engineer, AI Security

Hidden Road • Greater London

On-site
GBP 120,000 - 190,000
Competitive salary
Equity
Healthcare
Staff Partner Engineer
Staff Partner Engineer

Ripple • Greater London

On-site
GBP 120,000 - 180,000
Equity
Professional development budget
Healthcare coverage
+1
Staff Software Engineer, Frontend
Staff Software Engineer, Frontend

Ripple • Greater London

On-site
GBP 90,000 - 130,000
Competitive salary
Bonuses and equity
In-office collaboration
+2
Senior Software Engineer, Banking Connectivity
Senior Software Engineer, Banking Connectivity

Ripple • Greater London

On-site
GBP 60,000 - 80,000
Competitive salary
Bonuses
Equity
+2
Senior Software Engineer, Risk
Senior Software Engineer, Risk

Hidden Road • Greater London

Hybrid
GBP 90,000 - 120,000
Remote work options
Great benefits
Professional development budget
Privacy Senior Manager New London, UK
Privacy Senior Manager New London, UK

Ripple • Greater London

Hybrid
GBP 120,000 - 180,000
Competitive salary
Bonuses and equity
Healthcare benefits