> Markdown version of [/jobs/ext/726730-staff-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/726730-staff-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Product Security Engineer - **Company:** CO-RIPPLING LLC - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $189,000.0 - $315,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Code Review, Encodings, Continuous Integration, Django Web Framework, Python (Programming Language), OAuth, Security Assertion Markup Language (SAML), Web Application Security, Software Engineering, Web Applications, ReactJS, Software Security, Terraform - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4c9178e2639d229f ## About the Role Do you have experience in Web Application Security Testing?, * 10+ years of experience in an product security role * Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities * Deep understanding of securing web applications * Fluency in Python, React, and Django Rest Framework * Experience with manual source code review, and embedding security to code in production environments. * Experience with deploying application security tools in the CI/CD pipeline * Experience with securing software development lifecycle including building programs that eliminate full classes of vulnerabilities, * Good understanding of SSO, including OAUTH, SAML * Experience with speaking at meetups or conferences * Experience running a bug bounty program ## Description We're looking for a hands-on staff security engineer to play a key role in building Rippling's Product Security program. Rippling's product's scope provides a unique set of security challenges, but our management is especially supportive of security and compliance as a central function of the business. As an early member of Rippling's security team, you'll have a meaningful impact on the security program's priorities and direction., We are a diverse team of skilled security engineers that are passionate about pushing the boundaries of security practices. We look to collaborate with our Engineering partners to find the right solution for our interesting challenges. Our team thrives on re-imagining approaches to traditional security to secure our vast ecosystem. Our achievements are shared through our blogs and at conferences and meetups. A little more about our team: * Our Infrastructure Security team shared a blog about how they streamlined AWS access * We spoke at BSides SF about attacking and defending infrastructure with terraform * Our Product Security lead talked about the Future Application Security Engineers * Our Security Engineering lead talk about an innovative way to reduce vulnerabilities in your organization What You'll Do * Build guardrails and controls to eliminate full classes of vulnerabilities within the Rippling application * Build security tooling and automations to help scale the Product Security team's practices * Threat-model application designs and solutions and provide security assessments. * Audit source code and perform code review for critical application changes * Mentor software engineering teams in security best practices * Provide hands-on remediation guidance to development teams * Review & establish software development practices that make security an essential part of the development process * Develop / Integrate security into the Software Development Life Cycle ## Related Videos - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [A Brief History of Data Storage](https://www.wearedevelopers.com/videos/974-a-brief-history-of-data-storage) - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JSON and Beyond](https://www.wearedevelopers.com/videos/968-json-and-beyond) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)