Staff Security Engineer

Ripple
London, Dublin
Workplace: OnsiteFull timeFunction: CybersecuritySkills: ["Incident response","Detection engineering","Security automation","Cross-functional collaboration","Technical specification writing"]

Build and improve security detections across Ripple’s security stack (including Google Security Operations), tuning alert quality and SIEM/data pipeline health. Lead incident response for the most complex, high-severity investigations and drive root cause remediation. Create security automation workflows (e.g., in Tines) to reduce manual toil, and translate the evolving threat landscape into better detection coverage and response playbooks. Serve as a technical reference for engineers and support design reviews.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Ripple
Ripple
1 day ago

Staff Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 23 hours agoStatus: Live

Job Summary

Build and improve security detections across Ripple’s security stack (including Google Security Operations), tuning alert quality and SIEM/data pipeline health. Lead incident response for the most complex, high-severity investigations and drive root cause remediation. Create security automation workflows (e.g., in Tines) to reduce manual toil, and translate the evolving threat landscape into better detection coverage and response playbooks. Serve as a technical reference for engineers and support design reviews.
Location: London, Dublin
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Design, build, and tune detections across the security stack to identify and mitigate threats.
  • •Lead incident response for the most complex and high-severity investigations, from triage through root cause and remediation.
  • •Build and maintain security automation workflows (e.g., in Tines) to reduce manual toil across detection, triage, and response.
  • •Own and improve SIEM/data pipeline health, including log source coverage, parsing/normalization, and alert quality.
  • •Influence security initiatives through cross-functional relationships and improve detection coverage and response playbooks as threats evolve.

Pay and Benefits

Perks:Health InsuranceRetirementParental LeaveLearning BudgetMobile Stipend

Key Requirements

  • •7+ years of experience in security operations, detection engineering, or incident response, owning work end-to-end.
  • •Advanced knowledge of security principles and blue team operations, including proficiency in at least one scripting language and REST API automation.
  • •Hands-on experience with SIEM platforms and security data pipelines (e.g., Google SecOps), including log source onboarding, parsing, and alert tuning.
  • •Hands-on experience with EDR, identity, email security, and network security tooling, with ability to extend and tune tooling.
  • •Ability to write clear technical specs, manage risk and trade-offs, and break complex problems into repeatable systems.
Skills:Incident responseDetection engineeringSecurity automationCross-functional collaborationTechnical specification writing
Languages:English
Tech Stack:Google Security OperationsSIEMSIEM/data pipelinesTinesREST APIsEDRClaude CodeOpenAI Codex

Company Brief

Ripple
Builds blockchain-based payment and liquidity infrastructure for financial institutions and enterprises. Its products support cross-border payments, crypto liquidity, and digital asset settlement.
Industry: Fintech Infrastructure
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Headquarters: San Francisco, United States
Founded: 2012
WebsiteLinkedIn