Staff Detection and Response Engineer

4 weeks ago


San Francisco, United States Rippling Full time
Dublin, Ireland; London, United Kingdom; Remote (Poland)RipplingRippling eliminates the friction from running a business, combining HR, IT, and Finance apps on a unified data platform.

Rippling is the first way for businesses to manage all of their HR & IT—payroll, benefits, computers, apps, and more—in one unified workforce platform.

By connecting every business system to one source of truth for employee data, businesses can automate all of the manual work they normally need to do to make employee changes. Take onboarding, for example. With Rippling, you can just click a button and set up a new employees’ payroll, health insurance, work computer, and third-party apps—like Slack, Zoom, and Office 365—all within 90 seconds.

Based in San Francisco, CA, Rippling has raised $1.2B from the world’s top investors—including Kleiner Perkins, Founders Fund, Sequoia, Greenoaks, and Bedrock—and was named one of America's best startup employers by Forbes.

We prioritize candidate safety. Please be aware that official communication will only be sent from @Rippling.com addresses.

About the role

We are looking for an experienced Security Engineer to join our Detection and Response Team (DART). You will help us build out a world-class incident response function that will navigate challenging security incidents, drive process improvement, and develop an open culture where we grow from our mistakes as an organization. In this role, you will also build the tools and detection infrastructure that we need to scale our detection and response capability across all threats to our Production and Corporate environments.

What you will do

  • Respond to security events, triage, perform investigations, incident analysis, and communicate clearly and efficiently to stakeholders.
  • Contribute to improving processes, procedures, and technologies used for detection and response, enabling us to improve after each incident.
  • Develop and run tools to gather security telemetry data from cloud production systems.
  • Automate workflows and improve identification and response time for security events.
  • Build and optimize detection rules, allowing us to spend our cycles on the alerts that matter.
  • Develop runbooks and incident playbooks for new and existing detections.
  • Lead Threat hunting practices, suggest product and infrastructure signals to surface attacks and incorporate findings into security controls.

What you will need

  • 8+ years of full-time experience as a security engineer, including security monitoring, incident response, and threat hunting in a cloud environment.
  • A defensive practitioner who understands offensive security and the actual scenarios that lead to compromise.
  • Prior experience leading complex investigations with a large number of stakeholders.
  • Strong communication skills and a proven track record of communicating with internal and external stakeholders at all levels.
  • Expertise on AWS security controls and services.
  • Experience leveraging coding for automation, alert enrichment, and detections.
  • Knowledge of adversary tactics, techniques, and procedures (TTPs) and MITRE ATT&CK principles.
  • Hands-on experience with data analysis, modeling, and correlation at scale.
  • Operating systems internals and forensics experience for macOS, Windows & Linux.
  • Domain experience managing and working with current SIEM and SOAR platforms.
  • Experience developing tools and automation using common DevOps toolsets and programming languages.
  • Understanding of malware functionality and persistence mechanisms.
  • Ability to analyze endpoint, network, and application logs for anomalous events.

Additional Information

Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics. Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email accomodations@rippling.com.

Rippling highly values having employees working in-office to foster a collaborative work environment and company culture. For office-based employees (employees who live within a 40 mile radius of a Rippling office), Rippling considers working in the office, at least three days a week under current policy, to be an essential function of the employee's role.

#J-18808-Ljbffr

  • San Francisco, United States OpenAI Full time

    OpenAI Introducing Sora: Creating video from text Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all...


  • San Francisco, United States Openai Full time

    OpenAI Introducing Sora: Creating video from text Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all...


  • San Francisco, United States Grammarly Full time

    Grammarly Grammarly makes AI writing convenient. Work smarter with personalized AI guidance and text generation on any app or website. Grammarly offers a dynamic hybrid working model for this role. This flexible approach gives team members the best of both worlds: plenty of focus time along with in-person collaboration that helps foster trust, innovation,...


  • San Francisco, United States OpenAI Full time

    OpenAI Introducing Sora: Creating video from text Security is at the foundation of OpenAIs mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAIs technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all...


  • San Francisco, United States Grammarly Full time

    GrammarlyGrammarly makes AI writing convenient. Work smarter with personalized AI guidance and text generation on any app or website.Grammarly offers a dynamic hybrid working model for this role. This flexible approach gives team members the best of both worlds: plenty of focus time along with in-person collaboration that helps foster trust, innovation, and...


  • San Francisco, United States Postman Full time

    Senior Security Engineer, Detection & Response Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly...


  • San Francisco, United States Postman Full time

    Senior Security Engineer, Detection & Response Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly...


  • San Francisco, United States Postman Full time

    Senior Security Engineer, Detection & ResponsePostman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly...


  • San Francisco, United States Postman Full time

    Who Are We? Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs-faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to strive humbly towards our mission of 100 million...


  • San Francisco, United States NexHealth Full time

    About NexHealth Our healthcare system is frustratingly analog. When you live in a world of one-tap car rides, meal delivery, and unlimited streaming, why do you have to call to schedule an appointment with a doctor and are still handed a clipboard to fill in a form? NexHealth's mission is to accelerate innovation in healthcare. We're doing this by connecting...


  • San Francisco, United States NexHealth Full time

    About NexHealth Our healthcare system is frustratingly analog. When you live in a world of one-tap car rides, meal delivery, and unlimited streaming, why do you have to call to schedule an appointment with a doctor and are still handed a clipboard to fill in a form? NexHealth's mission is to accelerate innovation in healthcare. We're doing this by connecting...


  • San Jose, United States Sony Corporation of America Full time

    Sony Corporation of America, located in New York, NY, is the U.S. headquarters of Sony Group Corporation, based in Tokyo, Japan. Sony's principal U.S. businesses include Sony Electronics Inc., Sony Interactive Entertainment LLC, Sony Music Entertainment, Sony Music Publishing and Sony Pictures Entertainment Inc. With some 900 million Sony devices in hands...


  • San Francisco, United States Tbwa ChiatDay Inc Full time

    Senior Security Engineer, Detection & ResponseWho Are We?Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs–faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to...


  • San Bruno, California, United States Verily Full time

    Cyber Security Engineer (Threat Detection and Response)About the Role:Verily is seeking a highly motivated and skilled Cybersecurity Detection and Response Engineer to join our Security Operations team. The ideal candidate will have a strong understanding of cybersecurity principles, a passion for threat hunting, and experience with various security tools...


  • San Francisco, United States Tbwa ChiatDay Inc Full time

    Senior Security Engineer, Detection & ResponseWho Are We?Postman is the world's leading collaboration platform for API development. Postman's features simplify each step of building an API & streamline collaboration to help create better APIs—faster. More than 30 million developers & 500,000 organizations worldwide use Postman today, and we continue to...


  • San Francisco, CA, United States ADVANCED ENGINEERING GROUP PC Full time

    Anthropic is an AI safety and research company that’s working to build reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our customers and for society as a whole. Our interdisciplinary team has experience across ML, physics, policy, business and product. Responsibilities: Lead a team of engineers building systems...


  • San Francisco, California, United States Cloudflare, Inc. Full time

    Cloudflare, Inc.Cyber Security Expert in Threat DetectionAbout the JobWe are seeking a highly skilled Cyber Security Expert in Threat Detection to join our team at Cloudflare, Inc. Based in London, this is an exciting opportunity for a Senior Staff or Principal Engineer with a strong background in threat detection and experience leading engineering teams.The...


  • San Francisco, California, United States Postman Full time

    About UsAt Postman, we're pushing the boundaries of API development and collaboration. As a leading platform for APIs, our mission is to empower 100 million connected developers and support innovative companies in an API-first world.The OpportunityWe're seeking an experienced Senior Security Engineer, Detection & Response to join our dynamic security team....


  • San Francisco, California, United States Rippling Full time

    About the RoleRippling is seeking a seasoned Security Incident Response Engineer to join our Detection and Response Team (DART) in Dublin, Ireland; London, United Kingdom; Remote (Poland). As a key member of our security team, you will play a vital role in building out a world-class incident response function that navigates challenging security incidents,...


  • San Diego, United States PEAK Technical Staffing USA Full time

    We are hiring for a Nuclear Engineer or Radiation Detection Engineer in San Diego, CA. This is an onsite role due to cleared facility. An essential qualification for this position is successfully obtaining a Secret security clearance issued by the Federal Government, which may require successful completion of a background check. JOB SUMMARY We are looking...