Staff Security Engineer

Ripple
London, Dublin
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 7+ yearsSkills: ["Problem-solving","Coaching","Collaboration","Communication","Risk awareness"]

Build and tune security detections across Ripple’s security stack (Google Security Operations), improving identification and mitigation of threats. Lead incident response for the most complex, high-severity cases and translate threat intelligence into stronger detection coverage and response playbooks. Create security automation workflows (e.g., in Tines) to reduce manual toil and own SIEM/data pipeline health, including log onboarding, parsing/normalization, and alert quality. Serve as a technical reference for engineers.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Ripple
Ripple
1 day ago

Staff Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 23 hours agoStatus: Live

Job Summary

Build and tune security detections across Ripple’s security stack (Google Security Operations), improving identification and mitigation of threats. Lead incident response for the most complex, high-severity cases and translate threat intelligence into stronger detection coverage and response playbooks. Create security automation workflows (e.g., in Tines) to reduce manual toil and own SIEM/data pipeline health, including log onboarding, parsing/normalization, and alert quality. Serve as a technical reference for engineers.
Location: London, Dublin
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Design, build, and tune detections across Ripple’s security stack to improve threat identification and mitigation.
  • •Lead incident response for the most complex and high-severity investigations, from triage through remediation.
  • •Build and maintain security automation workflows (e.g., in Tines) to reduce manual toil in detection, triage, and response.
  • •Own and improve SIEM/data pipeline health, including log source coverage, parsing/normalization, and alert quality.
  • •Maintain threat-landscape awareness and translate it into concrete improvements to detection coverage and response playbooks.

Pay and Benefits

Perks:RetirementParental LeaveMobile PhoneWellness Stipend

Key Requirements

  • •7+ years in security operations, detection engineering, or incident response, owning detection and incident response end-to-end.
  • •Advanced security operations knowledge, including blue teaming practices, and strong scripting skills for response automation and REST API use.
  • •Experience with SIEM platforms and security data pipelines (e.g., Google SecOps), including log source onboarding, parsing, and alert tuning.
  • •Hands-on experience with EDR, identity, email security, and network security tooling with the ability to extend and tune it.
  • •Ability to write clear technical specs, identify risks, reason about trade-offs, and break down complex problems into repeatable systems.
Experience:7+ yearsSecurity operationsDetection engineeringIncident responseBlue teaming
Skills:Problem-solvingCoachingCollaborationCommunicationRisk awareness
Languages:English
Tech Stack:Google Security OperationsSIEMSIEM/data pipelinesTinesREST APIsClaude CodeOpenAI CodexEDRIdentity securityEmail securityNetwork security

Company Brief

Ripple
Builds blockchain-based payment and liquidity infrastructure for financial institutions and enterprises. Its products support cross-border payments, crypto liquidity, and digital asset settlement.
Industry: Fintech Infrastructure
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Headquarters: San Francisco, United States
Founded: 2012
WebsiteLinkedIn