Staff Product Security Engineer

Rippling

San Francisco (CA)

On-site

USD 189,000 - 315,000

Full time

28 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Rippling is seeking a hands-on staff security engineer to help build and lead Rippling's Product Security program. You’ll own critical security initiatives, mentor engineers, and shape security practices across the development lifecycle.

The role focuses on securing Rippling’s applications, integrating security into SDLC, and collaborating with Engineering to defend our vast ecosystem. A strong security mindset and hands-on execution are essential.

Qualifications

  • 10+ years of experience in a product security role.
  • Experience leading architectural changes or cross-team efforts to mitigate security vulnerabilities.
  • Deep understanding of securing web applications.
  • Fluency in Python, React, and Django Rest Framework.
  • Experience with manual source code review, and embedding security to code in production environments.
  • Experience with deploying application security tools in the CI/CD pipeline.
  • Experience with securing software development lifecycle including building programs that eliminate full classes of vulnerabilities.

Responsibilities

  • Build guardrails and controls to eliminate full classes of vulnerabilities within the Rippling application.
  • Build security tooling and automations to help scale the Product Security team’s practices.
  • Threat-model application designs and solutions and provide security assessments.
  • Audit source code and perform code review for critical application changes.
  • Mentor software engineering teams in security best practices.
  • Provide hands-on remediation guidance to development teams.
  • Review & establish software development practices that make security an essential part of the development process.
  • Develop / Integrate security into the Software Development Life Cycle.

Skills

Security engineering
Architectural changes
Web security
Python
React
Django REST Framework
Code review

Job description

About Rippling

Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and computers. For the first time ever, you can manage and automate every part of the employee lifecycle in a single system.

Take onboarding, for example. With Rippling, you can hire a new employee anywhere in the world and set up their payroll, corporate card, computer, benefits, and even third-party apps like Slack and Microsoft 365- all within 90 seconds.

Based in San Francisco, CA, Rippling has raised $1.4B+ from the world’s top investors—including Kleiner Perkins, Founders Fund, Sequoia, Greenoaks, and Bedrock—and was named one of America's best startup employers by Forbes.

We prioritize candidate safety. Please be aware that all official communication will only be sent from @ Rippling.com addresses.

About The Role

We're looking for a hands-on staff security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of security challenges, but our management is especially supportive of security and compliance as a central function of the business. As an early member of Rippling's security team, you'll have a meaningful impact on the security program’s priorities and direction.

About The Team

We are a diverse team of skilled security engineers that are passionate about pushing the boundaries of security practices. We look to collaborate with our Engineering partners to find the right solution for our interesting challenges. Our team thrives on re-imagining approaches to traditional security to secure our vast ecosystem.

Our achievements are shared through our blogs and at conferences and meetups.

  • Build guardrails and controls to eliminate full classes of vulnerabilities within the Rippling application
  • Build security tooling and automations to help scale the Product Security team’s practices
  • Threat-model application designs and solutions and provide security assessments.
  • Audit source code and perform code review for critical application changes
  • Mentor software engineering teams in security best practices
  • Provide hands-on remediation guidance to development teams
  • Review & establish software development practices that make security an essential part of the development process
  • Develop / Integrate security into the Software Development Life Cycle
Qualifications
  • 10+ years of experience in an product security role
  • Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities
  • Deep understanding of securing web applications
  • Fluency in Python, React, and Django Rest Framework
  • Experience with manual source code review, and embedding security to code in production environments.
  • Experience with deploying application security tools in the CI/CD pipeline
  • Experience with securing software development lifecycle including building programs that eliminate full classes of vulnerabilities
Bonus Points
  • Good understanding of SSO, including OAUTH, SAML
  • Experience with speaking at meetups or conferences
  • Experience running a bug bounty program

Additional Information

Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email accommodations@rippling.com .

Rippling highly values in-office collaboration. Employees living within 30 miles of an office are expected to work onsite three days a week with those living 30-49.9 miles away expected to be in the office one day a week. Employees living over 50 miles away are required to relocate within 30 miles of an office. To enhance team cohesiveness, new employees are asked to work onsite three days a week for their first six months.

This role will receive a competitive salary + benefits + equity. The salary for US-based employees will be aligned with one of the ranges below based on location; see which tier applies to your location

A variety of factors are considered when determining someone’s compensation--including a candidate’s professional background, experience, and location. Final offer amounts may vary from the amounts listed below.

About Rippling

Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and computers. For the first time ever, you can manage and automate every part of the employee lifecycle in a single system.

Take onboarding, for example. With Rippling, you can hire a new employee anywhere in the world and set up their payroll, corporate card, computer, benefits, and even third-party apps like Slack and Microsoft 365- all within 90 seconds.

Based in San Francisco, CA, Rippling has raised $1.4B+ from the world’s top investors—including Kleiner Perkins, Founders Fund, Sequoia, Greenoaks, and Bedrock—and was named one of America's best startup employers by Forbes.

We prioritize candidate safety. Please be aware that all official communication will only be sent from @ Rippling.com addresses.

About The Role

We're looking for a hands-on staff security engineer to play a key role in building Rippling's Product Security program. Rippling's product’s scope provides a unique set of security challenges, but our management is especially supportive of security and compliance as a central function of the business. As an early member of Rippling's security team, you'll have a meaningful impact on the security program’s priorities and direction.

About The Team

We are a diverse team of skilled security engineers that are passionate about pushing the boundaries of security practices. We look to collaborate with our Engineering partners to find the right solution for our interesting challenges. Our team thrives on re-imagining approaches to traditional security to secure our vast ecosystem.

Our achievements are shared through our blogs and at conferences and meetups.

A little more about our team:

  • Our Infrastructure Security team shared a blog about how they streamlined AWS access
  • We spoke at BSides SF about attacking and defending infrastructure with terraform
  • Our Product Security lead talked about the Future Application Security Engineers
  • Our Security Engineering lead talk about an innovative way to reduce vulnerabilities in your organization

What You'll Do

  • Build guardrails and controls to eliminate full classes of vulnerabilities within the Rippling application
  • Build security tooling and automations to help scale the Product Security team’s practices
  • Threat-model application designs and solutions and provide security assessments.
  • Audit source code and perform code review for critical application changes
  • Mentor software engineering teams in security best practices
  • Provide hands-on remediation guidance to development teams
  • Review & establish software development practices that make security an essential part of the development process
  • Develop / Integrate security into the Software Development Life Cycle
Qualifications
  • 10+ years of experience in an product security role
  • Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities
  • Deep understanding of securing web applications
  • Fluency in Python, React, and Django Rest Framework
  • Experience with manual source code review, and embedding security to code in production environments.
  • Experience with deploying application security tools in the CI/CD pipeline
  • Experience with securing software development lifecycle including building programs that eliminate full classes of vulnerabilities
Bonus Points
  • Good understanding of SSO, including OAUTH, SAML
  • Experience with speaking at meetups or conferences
  • Experience running a bug bounty program

Additional Information

Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email accommodations@rippling.com .

Rippling highly values in-office collaboration. Employees living within 30 miles of an office are expected to work onsite three days a week with those living 30-49.9 miles away expected to be in the office one day a week. Employees living over 50 miles away are required to relocate within 30 miles of an office. To enhance team cohesiveness, new employees are asked to work onsite three days a week for their first six months.

This role will receive a competitive salary + benefits + equity. The salary for US-based employees will be aligned with one of the ranges below based on location; see which tier applies to your location

A variety of factors are considered when determining someone’s compensation--including a candidate’s professional background, experience, and location. Final offer amounts may vary from the amounts listed below.

The pay range for this role is:
189,000 - 315,000 USD per year(US Tier 1)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Product Security Engineer
Staff Product Security Engineer

Rippling • Seattle (WA)

On-site
USD 189,000 - 315,000
Senior Security Engineer
Senior Security Engineer

Rippling • Seattle (WA)

On-site
USD 168,000 - 280,000
Staff Product Security Engineer
Staff Product Security Engineer

Rippling • New York (NY)

On-site
USD 180,000 - 260,000
Equity
Senior Product Security Engineer — Build Secure, Scalable Apps
Senior Product Security Engineer — Build Secure, Scalable Apps

Rippling • Seattle (WA)

On-site
USD 168,000 - 280,000
Senior Security Engineer
Senior Security Engineer

Rippling • New York (NY)

On-site
USD 140,000 - 210,000
Equity
Senior Software Engineer, Backend - HR Product
Senior Software Engineer, Backend - HR Product

Rippling • Seattle (WA)

On-site
USD 180,000 - 280,000
Senior Engineering Manager, Platform
Senior Engineering Manager, Platform

Rippling • Seattle (WA)

On-site
USD 207,000 - 345,000
Senior Security Engineer
Senior Security Engineer

Rippling • New York (NY)

On-site
USD 168,000 - 280,000
Principal Security Engineer
Principal Security Engineer

Rippling • San Francisco (CA)

On-site
USD 207,000 - 345,000
Senior Software Engineer, Backend-Fintech Platform
Senior Software Engineer, Backend-Fintech Platform

Rippling • San Francisco (CA)

On-site
USD 168,000 - 280,000