Staff Product Security Engineer
Hands-on staff security engineer building guardrails, tooling, and automations to secure Rippling's web applications. Requires 10+ years in product security, fluency in Python/React/DRF, and experience embedding security into SDLC and CI/CD.
About the job
What You'll Do
- Build guardrails and controls to eliminate full classes of vulnerabilities within the Rippling application
- Build security tooling and automations to help scale the Product Security team’s practices
- Threat-model application designs and solutions and provide security assessments
- Audit source code and perform code review for critical application changes
- Mentor software engineering teams in security best practices
- Provide hands-on remediation guidance to development teams
- Review & establish software development practices that make security an essential part of the development process
- Develop / Integrate security into the Software Development Life Cycle
Qualifications
- 10+ years of experience in a product security role
- Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities
- Deep understanding of securing web applications
- Fluency in Python, React, and Django Rest Framework
- Experience with manual source code review, and embedding security to code in production environments
- Experience with deploying application security tools in the CI/CD pipeline
- Experience with securing software development lifecycle including building programs that eliminate full classes of vulnerabilities
Bonus Points
- Good understanding of SSO, including OAUTH, SAML
- Experience with speaking at meetups or conferences
- Experience running a bug bounty program
Skills
Python, React, Django Rest Framework, CI/CD, Source Code Review, Threat Modeling, Application Security, SSO, OAuth, SAML, Bug Bounty
Similar jobs
Security Engineering jobsBuild and scale container security capabilities that orchestrate Zero Trust Segmentation at the application and pod level. The role requires 8+ years developing distributed systems, proficiency in a higher-level language, and strong Kubernetes, networking, and Linux expertise.
Build and lead application and product security practices across a 145-engineer organization, embedding secure defaults, CI guardrails, threat modeling, and vulnerability mitigation into product development. The role requires 6+ years of hands-on security experience, strong coding ability, and microservices expertise.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Leads security architecture, assessments, automation, and security-by-design practices for the Walrus team and broader ecosystem. The role requires 8+ years of security engineering experience, broad technical expertise, and Staff-level leadership.
Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.