Senior Security Engineer - Detection & Response

Rippling

San Francisco (CA)

On-site

USD 170,000 - 210,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Equity
Benefits

Job summary

Rippling in San Francisco seeks a hands-on Senior Detection and Response Security Engineer to advance our security program through automation, data collection, and detection logic. You will build tools, automate workflows, develop detection rules, and improve SIEM/SOAR capabilities while documenting runbooks and incident playbooks.

You will lead threat hunting initiatives, analyze telemetry from cloud production systems, and collaborate with the security and engineering teams to strengthen

Qualifications

  • 4+ years of full-time security engineering, focusing on monitoring, incident response, and threat hunting.
  • Proficiency in developing automation using Python and DevOps toolchains.
  • Strong knowledge of MITRE ATT&CK and adversary TTPs.
  • Experience with large-scale data analysis, modeling, and correlation.
  • Forensics expertise across macOS, Windows, Linux.

Responsibilities

  • Design and implement tools to gather security telemetry from cloud systems.
  • Automate security workflows to speed detection and response.
  • Develop and refine detection rules for emerging threats.
  • Improve SIEM, SOAR, and related detection technologies.
  • Create runbooks and incident playbooks for detections.
  • Lead proactive threat hunting initiatives.
  • Collaborate with security and engineering teams.

Skills

Threat hunting
Security monitoring
Incident response
Python scripting
Data analysis

Tools

SIEM
SOAR
MITRE ATT&CK
Cloud telemetry tooling

Job description

About The Role

We are looking for a hands-on Senior Detection and Response Security Engineer to be a critical force in driving Rippling’s security program forward. This role offers the opportunity to revolutionize our detection and response strategies through advanced automation, strategic data collection, and innovative detection logic. You will collaborate with our talented security team and broader engineering org to elevate and enhance our security efforts.

What You’ll Do
  • Innovative Tool Development: Design and implement sophisticated tools to gather security telemetry data from cloud production systems, enhancing our ability to detect and respond to threats.
  • Automation and Optimization: Lead the charge in automating workflows, significantly improving the speed and accuracy of security event identification and response.
  • Detection Rule Development: Build and refine advanced detection rules to protect against emerging cyber threats.
  • Process and Technology Enhancement: Drive continuous improvement of processes, procedures, and technologies used for detection and response.
  • Strategic Development: Spearhead advancements in Security Incident and Event Management (SIEM), Case Management, and Automation frameworks.
  • Comprehensive Documentation: Develop detailed runbooks and incident playbooks for both new and existing detections.
  • Proactive Threat Hunting: Lead threat hunting initiatives, uncovering potential attack vectors and integrating findings into security controls.
Qualifications
  • Extensive Expertise: 4+ years of full-time experience as a security engineer, with a focus on security monitoring, incident response, and threat hunting.
  • Programming Skills: Proficiency in developing tools and automation using common DevOps toolsets, with a preference for Python.
  • Deep Technical Knowledge: Practical understanding of common attacks, adversary tactics, techniques, and procedures (TTPs), and MITRE ATT&CK principles.
  • Analytical Proficiency: Hands-on experience with large-scale data analysis, modeling, and correlation.
  • Cross-Platform Forensics: Expertise in operating systems internals and forensics for macOS, Windows, and Linux.
  • Platform Management: Experience managing and working with current SIEM and SOAR platforms.
  • Log Analysis Expertise: Ability to analyze endpoint, network, and application logs for anomalous events.
Additional Information

Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email accommodations@rippling.com.

Rippling highly values in-office collaboration. Employees living within 30 miles of an office are expected to work onsite three days a week with those living 30-49.9 miles away expected to be in the office one day a week. Employees living over 50 miles away are required to relocate within 30 miles of an office. To enhance team cohesiveness, new employees are asked to work onsite three days a week for their first six months.

This role will receive a competitive salary + benefits + equity. The salary for US-based employees will be aligned with one of the ranges below based on location; see which tier applies to your location here.

A variety of factors are considered when determining someone’s compensation–including a candidate’s professional background, experience, and location. Final offer amounts may vary from the amounts listed below.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Detection & Response
Senior Security Engineer - Detection & Response

Rippling • Seattle (WA)

On-site
USD 151,000 - 280,000
Senior Security Engineer - Detection & Response
Senior Security Engineer - Detection & Response

Rippling • Austin (TX)

On-site
USD 151,000 - 280,000
Senior Security Engineer - Detection & Response
Senior Security Engineer - Detection & Response

Rippling • New York (NY)

On-site
USD 170,000 - 250,000
Senior Security Engineer - Detection & Response
Senior Security Engineer - Detection & Response

Cedarparktexasedc • Austin (TX)

On-site
USD 140,000 - 190,000
Senior Security Engineer
Senior Security Engineer

Rippling • New York (NY)

On-site
USD 140,000 - 210,000
Equity
Senior Security Engineer
Senior Security Engineer

Rippling • Seattle (WA)

On-site
USD 168,000 - 280,000
Senior Security Engineer
Senior Security Engineer

Rippling • San Francisco (CA)

On-site
USD 168,000 - 280,000
Senior Security Engineer
Senior Security Engineer

Rippling • New York (NY)

Hybrid
USD 168,000 - 280,000
Staff Product Security Engineer
Staff Product Security Engineer

Rippling • New York (NY)

On-site
USD 180,000 - 260,000
Equity
Principal Security Engineer
Principal Security Engineer

Socket.dev • San Francisco (CA)

On-site
USD 210,000 - 320,000