Staff Product Security Engineer

4 weeks ago


Bengaluru, India Rippling Full time
About RipplingRippling is the first way for businesses to manage all of their HR & IT—payroll, benefits, computers, apps, and more—in one unified workforce platform.By connecting every business system to one source of truth for employee data, businesses can automate all of the manual work they normally need to do to make employee changes. Take onboarding, for example. With Rippling, you can just click a button and set up a new employees’ payroll, health insurance, work computer, and third-party apps—like Slack, Zoom, and Office 365—all within 90 seconds.Based in San Francisco, CA, Rippling has raised $1.2B from the world’s top investors—including Kleiner Perkins, Founders Fund, Sequoia, Greenoaks, and Bedrock—and was named one of America's best startup employers by Forbes.We prioritize candidate safety. Please be aware that all official communication will only be sent from @ Rippling.com

addresses.About The Role

We're looking for a hands-on staff security engineer to play a key role in building Rippling's security program. Rippling's product’s scope provides a unique set of security challenges, but our management is especially supportive of security and compliance as a central function of the business. As an early member of Rippling's security team, you'll have a meaningful impact on the security program’s priorities and direction.About the team

We are a diverse team of skilled security engineers that are passionate about pushing the boundaries of

security practices. We look to collaborate with our Engineering partners to find the right solution for our interesting challenges. Our team thrives on re-imagining approaches to traditional security to secure our vast ecosystem.

Our achievements are shared through our blogs and at conferences and meetups.

A little more about our team:Our Infrastructure Security team shared a blog about how they

streamlined AWS access

We spoke at BSides SF about

attacking and defending infrastructure with terraform

Our Product Security lead talked about the

Future Application Security Engineers

Our Security Engineering lead talk about an

innovative way to reduce vulnerabilities in your organization

What You'll Do

Build security tooling and automations to help scale the Product Security team’s practices

Threat-model application designs and solutions and provide security assessments.

Audit source code and perform code review for critical application changes

Mentor software engineering teams in security best practices

Provide hands-on remediation guidance to development teams

Review & establish software development practices that make security an essential part of the development process

Develop / Integrate security into the Software Development Life Cycle

Qualifications

8+ years of experience in an product security role

Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities

Deep understanding of securing web applications

Fluency in Python, React, and Django Rest Framework

Experience with manual source code review, and embedding security to code in production environments.

Experience with deploying application security tools in the CI/CD pipeline

Experience with securing software development lifecycle including building programs that eliminate full classes of vulnerabilities

Bonus Points

Good understanding of SSO, including OAUTH, SAMLExperience with speaking at meetups or conferencesExperience running a bug bounty program

Additional InformationRippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email



  • Bengaluru, Karnataka, India Harness Full time

    As a Staff Security Engineer, you will lead efforts to extend visibility into Harness' security posture, integrate and automate core security technologies, and drive continuous improvement across our technical estate. You'll use your knowledge to test, design, and secure solutions that enable Harness' business goals, and collaborate directly with engineering...


  • Bengaluru, Karnataka, India Insight Global Full time

    Our client searching for a Staff Information Security Engineer in India. This position is hybrid friendly (WFH several days a week). We're looking for problem solvers, innovators, and dreamers who are searching for anything but business as usual. Like us, you're a high performer who's an expert at your craft, constantly challenging the status quo. You value...


  • Bengaluru, India Insight Global Full time

    Our client searching for a Staff Information Security Engineer in India. This position is hybrid friendly (WFH several days a week). We’re looking for problem solvers, innovators, and dreamers who are searching for anything but business as usual. Like us, you’re a high performer who’s an expert at your craft, constantly challenging the status quo. You...


  • Bengaluru, India RSA Security Full time

    Responsibilities • Work on any number of security and identity related areas and products • Build systems for detecting anomalous activities within the product • Develops and administers software engineering procedures and training for vulnerability scans and static code analysis • Analyse vulnerability report of various SCA and SAST scan tools...


  • Bengaluru, Karnataka, India Rippling Full time

    About RipplingRippling is the first way for businesses to manage all of their HR & IT—payroll, benefits, computers, apps, and more—in one unified workforce platform.By connecting every business system to one source of truth for employee data, businesses can automate all of the manual work they normally need to do to make employee changes. Take...


  • Bengaluru, Karnataka, India RSA Security Full time

    Responsibilities Work on any number of security and identity related areas and products Build systems for detecting anomalous activities within the product Develops and administers software engineering procedures and training for vulnerability scans and static code analysis Analyse vulnerability report of various SCA and SAST scan tools like, Black Duck,...


  • Bengaluru, Karnataka, India Rippling Full time

    About Rippling Rippling is the first way for businesses to manage all of their HR & IT—payroll, benefits, computers, apps, and more—in one unified workforce platform. By connecting every business system to one source of truth for employee data, businesses can automate all of the manual work they normally need to do to make employee changes. Take...


  • Bengaluru, India Rippling Full time

    About Rippling Rippling is the first way for businesses to manage all of their HR & IT—payroll, benefits, computers, apps, and more—in one unified workforce platform. By connecting every business system to one source of truth for employee data, businesses can automate all of the manual work they normally need to do to make employee changes. Take...


  • Bengaluru, Karnataka, India Guidewire Full time

    Responsibilities:Proactively partner with teams across the organization (infrastructure, application engineering, data analytics, etc.) to define, promote and implement security best practices that improve the security posture of our infrastructure.Working closely with business units, product teams, DevOps engineers and/or SRE's to embed security...


  • Bengaluru, India Guidewire Full time

    Responsibilities:Proactively partner with teams across the organization (infrastructure, application engineering, data analytics, etc.) to define, promote and implement security best practices that improve the security posture of our infrastructure.Working closely with business units, product teams, DevOps engineers and/or SRE's to embed security...


  • Bengaluru, India Guidewire Full time

    Responsibilities:Proactively partner with teams across the organization (infrastructure, application engineering, data analytics, etc.) to define, promote and implement security best practices that improve the security posture of our infrastructure. Working closely with business units, product teams, DevOps engineers and/or SRE's to embed security...


  • Bengaluru, Karnataka, India Menlo Security Full time

    Menlo Security's mission is enabling the world to connect, communicate and collaborate securely without compromise. COVID-19 has made our mission all the more real. We support customers across various enterprises including Fortune 500 companies, 9/10 of the largest global banks and the Department of Defense.Menlo is well-funded for growth and our investors...


  • Bengaluru, India Harness.io Full time

    As a Staff Security Engineer, you will lead efforts to extend visibility into Harness' security posture, integrate and automate core security technologies, and drive continuous improvement across our technical estate. You'll use your knowledge to test, design, and secure solutions that enable Harness' business goals, and collaborate directly...


  • Bengaluru, Karnataka, India Menlo Security Full time

    Menlo Security's mission is enabling the world to connect, communicate and collaborate securely without compromise. COVID-19 has made our mission all the more real. We support customers across various enterprises including Fortune 500 companies, 9/10 of the largest global banks and the Department of Defense. Menlo is well-funded for growth and our investors...


  • Bengaluru, India Insight Global Full time

    Our client searching for a Staff Information Security Engineer in India. This position is hybrid friendly (WFH several days a week). We’re looking for problem solvers, innovators, and dreamers who are searching for anything but business as usual. Like us, you’re a high performer who’s an expert at your craft, constantly challenging the status quo. You...


  • Bengaluru, Karnataka, India Andromeda Security Full time

    Member of Technical Staff - Distributed SystemsWe are a stealth startup, top-tier Silicon Valley VC-funded multinational startup building a team in Bengaluru, India. Over the last year we have grown quite rapidly and built a solid team the Bay Area and Bangalore. We are continuing to expand the core engineering team that will build the foundation of this...


  • Bengaluru, Karnataka, India Andromeda Security Full time

    Member of Technical Staff - Distributed Systems We are a stealth startup, top-tier Silicon Valley VC-funded multinational startup building a team in Bengaluru, India. Over the last year we have grown quite rapidly and built a solid team the Bay Area and Bangalore. We are continuing to expand the core engineering team that will build the foundation of this...


  • Bengaluru, Karnataka, India GE HEALTHCARE Full time

    **Job Description Summary**: Responsible for hunting, detecting and responding to digital security threats. Demonstrates technical leadership abilities and strong comprehension of malware, emerging threats and calculating risk. GE HealthCare is a leading global medical technology and digital solutions innovator. Our purpose is to create a world where...


  • Bengaluru, India RSA Security Full time

    RSA - Application Security Engineer Location: Remote India RSA offers mission-driven security solutions that provide organizations with a unified approach to managing digital risk that hinges on integrated visibility, automated insights and coordinated actions. RSA solutions are designed to effectively detect and respond to advanced attacks; manage...


  • Bengaluru, India RSA Security Full time

    RSA - Application Security Engineer Location: Remote India RSA offers mission-driven security solutions that provide organizations with a unified approach to managing digital risk that hinges on integrated visibility, automated insights and coordinated actions. RSA solutions are designed to effectively detect and respond to advanced attacks; manage...