6 hours ago

Senior Product Security Engineer

Rippling

On Site
Full Time
$200,000
Bengaluru, Karnataka, India

Job Overview

Job TitleSenior Product Security Engineer
Job TypeFull Time
Offered Salary$200,000
LocationBengaluru, Karnataka, India

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

About Rippling

Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and computers. For the first time ever, you can manage and automate every part of the employee lifecycle in a single system.

Take onboarding, for example. With Rippling, you can hire a new employee anywhere in the world and set up their payroll, corporate card, computer, benefits, and even third-party apps like Slack and Microsoft 365—all within 90 seconds.

Based in San Francisco, CA, Rippling has raised $1.8B+ from the world’s top investors—including Kleiner Perkins, Founders Fund, Sequoia, Greenoaks, and Bedrock—and was named one of America's best startup employers by Forbes.

We prioritize candidate safety. Please be aware that all official communication will only be sent from @Rippling.com addresses.

About The Role

We're looking for a hands-on Senior Product Security Engineer to play a key role in building Rippling's security program. Rippling's product’s scope provides a unique set of security challenges, but our management is especially supportive of security and compliance as a central function of the business. As an early member of Rippling's security team, you'll have a meaningful impact on the security program’s priorities and direction.

About The Team

We are a diverse team of skilled security engineers that are passionate about pushing the boundaries of security practices. We look to collaborate with our Engineering partners to find the right solution for our interesting challenges. Our team thrives on re-imagining approaches to traditional security to secure our vast ecosystem.

Our achievements are shared through our blogs and at conferences and meetups.

A little more about our team:

  • Our Infrastructure Security team shared a blog about how they streamlined AWS access
  • We spoke at BSides SF about attacking and defending infrastructure with terraform
  • Our Product Security lead talked about the Future Application Security Engineers
  • Our Security Engineering lead talk about an innovative way to reduce vulnerabilities in your organization

What You'll Do

  • Develop and maintain a security architecture strategy, evaluate security technologies, and ensure compliance through design and architecture reviews.
  • Provide full SDLC support for new product features developed by engineering and non-engineering teams, including threat modeling, design reviews, manual code reviews, and exploit writing.
  • Conduct system security and vulnerability analyses, provide risk mitigation recommendations, and mentor team members in security best practices.
  • Build automations or secure paved paths to make it easier for Product Security to scale with the business.

Qualifications

  • 8+ years of experience in an product security role
  • Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities
  • Familiar with security frameworks (e.g., NIST SSDF) and regulations (e.g., GDPR, HIPAA).
  • Deep understanding of securing web applications
  • Fluency in Python, React, and Django Rest Framework
  • Experience with manual source code review, and embedding security to code in production environments.
  • Experience with deploying application security tools in the CI/CD pipeline
  • Experience with securing software development lifecycle including building programs that eliminate full classes of vulnerabilities

Bonus Points

  • Good understanding of SSO, including OAUTH, SAML
  • Experience with speaking at meetups or conferences
  • Experience running a bug bounty program

Key skills/competency

  • Product Security
  • Security Architecture
  • Threat Modeling
  • Design Reviews
  • Vulnerability Analysis
  • Python
  • React
  • Django
  • CI/CD Security
  • SDLC Security

Tags:

Senior Product Security Engineer
Product security
Security architecture
Threat modeling
Design reviews
Vulnerability analysis
Code review
SDLC security
Risk mitigation
Security automation
Mentorship
Python
React
Django
CI/CD
AWS
Terraform
OAUTH
SAML
Web application security

Share Job:

How to Get Hired at Rippling

  • Research Rippling's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor.
  • Tailor your resume: Highlight product security experience, SDLC integration, and relevant tech stacks like Python and Django.
  • Showcase security leadership: Emphasize architectural changes, cross-team collaboration, and vulnerability mitigation achievements.
  • Prepare for technical deep-dives: Expect questions on web application security, threat modeling, and secure coding practices.
  • Demonstrate passion for innovation: Be ready to discuss re-imagining traditional security approaches and contributing to the security community.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background