Staff Product Security Engineer

2 Weeks ago • 10 Years + • Product Management

Job Summary

Job Description

Rippling is seeking a hands-on Staff Product Security Engineer to be a key player in developing its security program. The role offers a unique set of security challenges within Rippling's product scope, with strong management support for security and compliance. As an early member of the security team, you will significantly influence the program's priorities and direction. The security team is collaborative and passionate about innovative security practices, often sharing achievements through blogs and at conferences. Responsibilities include developing security architecture strategies, evaluating security technologies, providing full SDLC support for new features through threat modeling and code reviews, conducting vulnerability analyses, and building automations to scale security efforts.
Must have:
  • Develop security architecture strategy
  • Provide full SDLC support
  • Conduct system security analyses
  • Build security automations
  • 10+ years in product security
  • Lead architectural changes
  • Familiar with security frameworks/regulations
  • Deep understanding of web app security
  • Fluency in Python, React, Django Rest Framework
  • Experience with manual code review
  • Deploy security tools in CI/CD
  • Secure software development lifecycle
Good to have:
  • Good understanding of SSO (OAUTH, SAML)
  • Experience speaking at meetups/conferences
  • Experience running bug bounty programs

Job Details

About Rippling

Rippling is the first way for businesses to manage all of their HR & IT—payroll, benefits, computers, apps, and more—in one unified workforce platform.


By connecting every business system to one source of truth for employee data, businesses can automate all of the manual work they normally need to do to make employee changes. Take onboarding, for example. With Rippling, you can just click a button and set up a new employees’ payroll, health insurance, work computer, and third-party apps—like Slack, Zoom, and Office 365—all within 90 seconds.


Based in San Francisco, CA, Rippling has raised $1.2B from the world’s top investors—including Kleiner Perkins, Founders Fund, Sequoia, Greenoaks, and Bedrock—and was named one of America's best startup employers by Forbes.


We prioritize candidate safety. Please be aware that all official communication will only be sent from @Rippling.com addresses.


About The Role

We're looking for a hands-on staff security engineer to play a key role in building Rippling's security program. Rippling's product’s scope provides a unique set of security challenges, but our management is especially supportive of security and compliance as a central function of the business. As an early member of Rippling's security team, you'll have a meaningful impact on the security program’s priorities and direction.

About the team

We are a diverse team of skilled security engineers that are passionate about pushing the boundaries of  security practices. We look to collaborate with our Engineering partners to find the right solution for our interesting challenges. Our team thrives on re-imagining approaches to traditional security to secure our vast ecosystem.


Our achievements are shared through our blogs and at conferences and meetups. 


A little more about our team:

What You'll Do


  • Develop and maintain a security architecture strategy, evaluate security technologies, and ensure compliance through design and architecture reviews.
  • Provide full SDLC support for new product features developed by engineering and non-engineering teams, including threat modeling, design reviews, manual code reviews, and exploit writing.
  • Conduct system security and vulnerability analyses, provide risk mitigation recommendations, and mentor team members in security best practices.
  • Build automations or secure paved paths to make it easier for Product Security to scale with the business.

Qualifications

  • 10+ years of experience in an product security role
  • Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities
  • Familiar with security frameworks (e.g., NIST SSDF) and regulations (e.g., GDPR, HIPAA).
  • Deep understanding of securing web applications
  • Fluency in Python, React, and Django Rest Framework
  • Experience with manual source code review, and embedding security to code in production environments.
  • Experience with deploying application security tools in the CI/CD pipeline
  • Experience with securing software development lifecycle including building programs that eliminate full classes of vulnerabilities

Bonus Points

  • Good understanding of SSO, including OAUTH, SAML
  • Experience with speaking at meetups or conferences
  • Experience running a bug bounty program


Additional Information


Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email accomodations@rippling.com


Similar Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Skill Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Jobs in Bengaluru, Karnataka, India

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Product Management Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

London, England, United Kingdom (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (Hybrid)

United States (Remote)

Austin, Texas, United States (On-Site)

San Francisco, California, United States (On-Site)

San Francisco, California, United States (On-Site)

New York, United States (Hybrid)

Dublin, County Dublin, Ireland (Hybrid)

Sydney, New South Wales, Australia (Hybrid)

View All Jobs

Get notified when new jobs are added by Rippling

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug