Skip to content
RipplingRippling

Senior Product Security Engineer

Hands-on security engineer building product security guardrails, tooling, and SDLC integrations for a multi-product HR/IT/Finance platform. Requires 5+ years in product security, fluency in Python/React/DRF, and experience leading cross-team vulnerability remediation.

About the job

What You'll Do

  • Build guardrails and controls to eliminate full classes of vulnerabilities within the Rippling application
  • Build security tooling and automations to help scale the Product Security team’s practices
  • Threat-model application designs and solutions and provide security assessments
  • Audit source code and perform code review for critical application changes
  • Mentor software engineering teams in security best practices
  • Provide hands-on remediation guidance to development teams
  • Review & establish software development practices that make security an essential part of the development process
  • Develop / Integrate security into the Software Development Life Cycle

Qualifications

  • 5+ years of experience in a product security role
  • Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities
  • Deep understanding of securing web applications
  • Fluency in Python, React, and Django Rest Framework
  • Experience with manual source code review, and embedding security to code in production environments
  • Experience with deploying application security tools in the CI/CD pipeline
  • Experience with securing software development lifecycle including building programs that eliminate full classes of vulnerabilities

Bonus Points

  • Good understanding of SSO, including OAUTH, SAML
  • Experience with speaking at meetups or conferences
  • Experience running a bug bounty program

Skills

Python, React, Django Rest Framework, CI/CD, Application Security, Threat Modeling, Code Review, SSO, OAuth, SAML, Bug Bounty

Juicebox

Juicebox

San Francisco, CA

GRC Lead
$150k+/yrOn-site3+ YOESecurity Engineering

Build and own Juicebox’s governance, risk, compliance, and customer trust function, leading audits, enterprise security reviews, policies, and AI governance initiatives. Requires 3+ years in GRC or security compliance and experience with SOC 2, ISO 27001, and customer security questionnaires.

Alex

Alex

San Francisco, CA

Security & Trust Lead
$150k+/yrOn-siteSecurity Engineering

Own Alex’s information security, compliance, AI governance, and enterprise trust program as its first dedicated Security & Trust hire. The role combines security reviews and customer-facing assurance with audits, regulatory readiness, risk management, and technical control development.

Plaid

Plaid

New York, NY

Fraud Intelligence Lead
$149k+/yrHybrid5+ YOESecurity Engineering

Leads a high-leverage fraud intelligence team while personally investigating complex attacks across identities, devices, accounts, and payments. The role combines people leadership, incident response, threat intelligence, and partnerships with product and ML teams to improve fraud detection and prevention.

Pinterest

Pinterest

United States

Senior Security Software Engineer, Security Operations
$156k+/yrRemote5+ YOESecurity Engineering

Provides technical leadership for Security Operations by building cloud security platforms, automated controls, vulnerability-management workflows, and developer-facing security capabilities. Requires senior-level production systems experience, AWS security architecture, Terraform, and strong cross-functional technical ownership.

Twilio

Twilio

United States

Senior Security Engineer, Incident Response
$142k+/yrRemote5+ YOESecurity Engineering

Lead technical response to security incidents across Twilio's global cloud infrastructure, including triage, containment, remediation, documentation, and post-incident improvements. Requires 5+ years incident response experience, expertise with SIEM/SOAR, cloud platforms, and AI-driven security tools.