Security Engineer - Detection & Response Organization

CO-RIPPLING LLC
Seattle, WA, United States
6 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$168,000.0 - $280,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Data Analysis Apple Mac Systems Big Data Cloud Computing Cyber Security Computer Programming Linux DevOps Internet Security Python (Programming Language) Log Analysis
+7 more
Microsoft Software Security Information and Event Management Scripting Mitre Att&ck Slack Cybercrime Multiplatform

Job description

We are looking for a hands-on Senior Detection and Response Security Engineer to be a critical force in driving Ripplings security program forward. This role offers the opportunity to revolutionize our detection and response strategies through advanced automation, strategic data collection, and innovative detection logic. You will collaborate with our talented security team and broader engineering org to elevate and enhance our security efforts.

What Youll Do

  • Innovative Tool Development: Design and implement sophisticated tools to gather security telemetry data from cloud production systems, enhancing our ability to detect and respond to threats.
  • Automation and Optimization: Lead the charge in automating workflows, significantly improving the speed and accuracy of security event identification and response.
  • Detection Rule Development: Build and refine advanced detection rules to protect against emerging cyber threats.
  • Process and Technology Enhancement: Drive continuous improvement of processes, procedures, and technologies used for detection and response.
  • Strategic Development: Spearhead advancements in Security Incident and Event Management (SIEM), Case Management, and Automation frameworks.
  • Comprehensive Documentation: Develop detailed runbooks and incident playbooks for both new and existing detections.
  • Proactive Threat Hunting: Lead threat hunting initiatives, uncovering potential attack vectors and integrating findings into security controls.

Requirements

  • Extensive Expertise: 4+ years of full-time experience as a security engineer, with a focus on security monitoring, incident response, and threat hunting.
  • Programming Skills: Proficiency in developing tools and automation using common DevOps toolsets, with a preference for Python.
  • Deep Technical Knowledge: Practical understanding of common attacks, adversary tactics, techniques, and procedures (TTPs), and MITRE ATT&CK principles.
  • Analytical Proficiency: Hands-on experience with large-scale data analysis, modeling, and correlation.
  • Cross-Platform Forensics: Expertise in operating systems internals and forensics for macOS, Windows, and Linux.
  • Platform Management: Experience managing and working with current SIEM and SOAR platforms.
  • Log Analysis Expertise: Ability to analyze endpoint, network, and application logs for anomalous events., Analysis Skills, Automation, Case Management, Cloud Computing, Computer Programming, Computer Security, Continuous Improvement, Data Analysis, Data Collection, Data Modeling, DevOps, Establish Priorities, Finance, Forensic Science, Hunting, Incident Response, Internet Security, Linux Operating System, Mac Operating System, Medical Genetics, Microsoft Product Family, Microsoft Windows Operating System, Military, Multiplatform/Cross-Platform, Network Performance/Analysis, Onboarding, Operating Systems, Procedure Development, Process Improvement, Production Systems, Python Programming/Scripting Language, Security Attacks, Security Information and Event Management (SIEM), Security Monitoring, Slack, Strategic Planning, System Lifecycle, Systems/Internals Programming, Telemetry

Benefits & conditions

This role will receive a competitive salary + benefits + equity. The salary for US-based employees will be aligned with one of the ranges below based on location; see which tier applies to your location here.

A variety of factors are considered when determining someone’s compensation-including a candidate’s professional background, experience, and location. Final offer amounts may vary from the amounts listed below.

The pay range for this role is:

168,000 - 280,000 USD per year (US Tier 1)

151,200 - 252,000 USD per year (US Tier 2)

About the company

Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and computers. For the first time ever, you can manage and automate every part of the employee lifecycle in a single system.

Take onboarding, for example. With Rippling, you can hire a new employee anywhere in the world and set up their payroll, corporate card, computer, benefits, and even third-party apps like Slack and Microsoft 365-all within 90 seconds.

Based in San Francisco, CA, Rippling has raised $1.4B+ from the world’s top investors-including Kleiner Perkins, Founders Fund, Sequoia, Greenoaks, and Bedrock-and was named one of Americas best startup employers by Forbes., Rippling highly values in-office collaboration. Employees living within 30 miles of an office are expected to work onsite three days a week with those living 30-49.9 miles away expected to be in the office one day a week. Employees living over 50 miles away are required to relocate within 30 miles of an office. To enhance team cohesiveness, new employees are asked to work onsite three days a week for their first six months.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:14 min

Automating user bug triage and resolutions using Slack agents

Brian Lovin Brian Lovin · World Congress 2026 Europe

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

5:36 min

Integrating agentic coding models into Slack

Chris Heilmann Chris Heilmann +2 · LIVE

Videos

See all

Related articles

See all