Demo

Staff Security Engineer- Detection and Response

Rippling
Seattle, WA Full Time
POSTED ON 3/30/2026
AVAILABLE BEFORE 4/27/2026
About Rippling

Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and computers. For the first time ever, you can manage and automate every part of the employee lifecycle in a single system.

Take onboarding, for example. With Rippling, you can hire a new employee anywhere in the world and set up their payroll, corporate card, computer, benefits, and even third-party apps like Slack and Microsoft 365—all within 90 seconds.

Based in San Francisco, CA, Rippling has raised $1.4B from the world’s top investors—including Kleiner Perkins, Founders Fund, Sequoia, Greenoaks, and Bedrock—and was named one of America's best startup employers by Forbes.

We prioritize candidate safety. Please be aware that all official communication will only be sent from @Rippling.com addresses.

About The Role

We are seeking a Staff Security Engineer to join our Detection and Response team (DART). This role is for a security engineer with deep threat hunting instincts and the engineering skills to build AI-driven solutions that transform how security operations work.

The ideal candidate lives at the intersection of adversary expertise and engineering. You know how to hunt for threats across cloud infrastructure, identity systems, and SaaS platforms - and when you find gaps or inefficiencies in how the team detects and responds, you build technical solutions to close them. You see AI as a tool in your engineering toolkit and you've already started applying it to security problems.

You'll work across detection engineering, incident response, and threat hunting - with the expectation that you're constantly improving the systems and tooling that power all three.

What You’ll Do:

  • Hunt Threats Across the Enterprise: Apply deep adversary knowledge to proactively find security threats across our cloud, identity, endpoint, and SaaS environments. Develop hypotheses from threat intelligence, telemetry gaps, and adversary TTPs, and execute them across 140 log sources. Turn findings into durable detections and improved response workflows.
  • Build AI-Driven Security Solutions: Design and build LLM-powered systems that solve real security operations problems — automated alert triage, investigation acceleration, detection generation, and more. We already run an AI agent that triages every alert. You'll identify the next high-impact opportunities and build them.
  • Engineer Detections at Scale: Write high-fidelity detection logic and build the frameworks, shared libraries, and tooling that raise the quality bar for every detection the team produces. Ensure detection coverage keeps pace with a rapidly evolving threat landscape.
  • Automate Response Workflows: Replace manual, repetitive security workflows with code. Build enrichment pipelines, correlation tools, investigation automation, and response orchestration that make the team faster and more consistent.
  • Investigate Complex Incidents: Serve as a senior responder for security incidents, driving investigations from initial signal through root cause and remediation. Bring deep expertise in cloud-native attack paths, particularly in AWS and SaaS environments.
  • Elevate the Team: Raise engineering standards through better tooling, reusable patterns, and technical mentorship. Influence the team's technical direction by prototyping new approaches and evaluating emerging techniques.

What We’re Looking For:

  • Deep Security Experience: 8 years in hands-on security engineering with significant depth across detection engineering, threat hunting, and incident response. Staff-level judgment in ambiguous, high-stakes situations.
  • Threat Hunting Expertise: You have deep experience hunting for threats and security issues across complex environments. You think in adversary TTPs, develop hypotheses, and know how to work through large-scale security data to find what others miss.
  • Builder Who Ships: You default to building. When you see a repetitive workflow, you automate it. When you see a gap, you write the tool. Strong proficiency in Python and SQL, with experience building production-grade tooling not just scripts.
  • AI Applied to Security: Hands-on experience building AI-driven solutions for security problems — whether agents, automated triage pipelines, LLM-assisted investigation, or detection-as-code generation. You understand both the potential and the limitations, and you've shipped something real.
  • Cloud-Native Security Depth: Extensive experience investigating threats in AWS and SaaS environments. Deep understanding of cloud attack paths, identity-based threats, and modern adversary techniques mapped to MITRE ATT&CK.
  • Data Fluency: Comfort working with large-scale security data in SQL-based environments. You enrich, correlate, and query across disparate sources to build a complete picture - not just react to individual alerts.
  • Technical Leadership: Ability to set technical direction and elevate a team without formal authority. Strong communication skills for conveying complex findings to both technical and non-technical audiences.

Additional Information

Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email accommodations@rippling.com.

Rippling highly values having employees working in-office to foster a collaborative work environment and company culture. For office-based employees (employees who live within a defined radius of a Rippling office), Rippling considers working in the office, at least three days a week under current policy, to be an essential function of the employee's role.

This role will receive a competitive salary benefits equity. The salary for US-based employees will be aligned with one of the ranges below based on location; see which tier applies to your location here.

A variety of factors are considered when determining someone’s compensation–including a candidate’s professional background, experience, and location. Final offer amounts may vary from the amounts listed below.

The pay range for this role is:

189,000 - 330,750 USD per year(US Tier 1)

170,100 - 297,675 USD per year(US Tier 2)

Salary.com Estimation for Staff Security Engineer- Detection and Response in Seattle, WA
$96,088 to $116,190
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Staff Security Engineer- Detection and Response?

Sign up to receive alerts about other jobs on the Staff Security Engineer- Detection and Response career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Rippling

  • Rippling Seattle, WA
  • About Rippling Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered ... more
  • 10 Days Ago

  • Rippling York, NY
  • About Rippling Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered ... more
  • 10 Days Ago

  • Rippling Austin, TX
  • About Rippling Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered ... more
  • 10 Days Ago

  • Rippling Austin, TX
  • About Rippling Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered ... more
  • 10 Days Ago


Not the job you're looking for? Here are some other Staff Security Engineer- Detection and Response jobs in the Seattle, WA area that may be a better fit.

  • Scale AI Seattle, WA
  • We are seeking a Senior Security Engineer with a specialty in Detection and Incident Response to join our Security Engineering team. This role sits at the ... more
  • 2 Days Ago

  • Anthropic Seattle, WA
  • About Anthropic Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and ... more
  • 1 Month Ago

AI Assistant is available now!

Feel free to start your new journey!