Senior Staff Security Engineer, Ripple Treasury
You will be one of Ripple's most senior technical security practitioners, working across application security, cloud infrastructure security, and secure software delivery. You will partner with Ripple Treasury Product and Engineering teams to drive secure design, threat modeling, vulnerability management, cloud security architecture, compliance, and security engineering maturity.
Responsibilities
- Serve as the dedicated Security Engineering partner for Ripple Treasury, owning the security posture of the Treasury solution and infrastructure environment.
- Lead threat modeling and security architecture reviews across Treasury offerings.
- Own the secure software development lifecycle, including security guardrails, CI/CD integrations, and developer guidance.
- Drive cloud security architecture across Azure and AWS, including IAM, network segmentation, encryption, zero trust, Kubernetes, DDoS, and WAF strategy.
- Partner with GRC to meet SOC 2, ISO 27001, and applicable financial regulatory obligations.
- Own vulnerability discovery through security assessments, penetration testing, and bug bounty programs.
- Build and scale a Security Champions model within Treasury Engineering.
- Influence engineering architecture decisions through design reviews and architectural assessments.
- Mentor and develop Security Engineers through threat model walkthroughs, design discussions, and knowledge sharing.
- Track emerging threats affecting FinTech, crypto, and enterprise treasury systems and translate them into defensive improvements.
Requirements
- 10+ years of Security Engineering experience, including Product Security and Infrastructure Security.
- Expertise in threat modeling, security architecture review, OWASP Top 10, API security, authentication, authorization, and secure SDLC development.
- Deep expertise securing cloud environments across Azure, AWS, and/or GCP, including IAM, network security, secrets management, containers, Kubernetes, and infrastructure as code.
- Hands-on experience building and operating DevSecOps tooling for static analysis, dynamic analysis, software composition analysis, secrets scanning, container scanning, and CI/CD security integration.
- Strong software engineering skills in Python, Go, or equivalent.
- Experience with cryptographic principles and key management, including HSMs, MPC, PKI, and key rotation.
- FinTech, crypto, blockchain, or high-stakes financial environment experience is a strong plus.
- Practitioner's approach with experience writing threat models, reviewing architecture, reading code, and building tooling.
Benefits
- Professional development budget
- Flexible in-office collaboration schedule with a minimum of 10+ days per month
- Bi-weekly all-company meetings with leadership
- Team offsites, team bonding activities, and happy hours
- Competitive bonuses and equity
- Physical and mental healthcare, retirement, family-forming, and family-support benefits
- Employee giving match
- Mobile phone stipend
- R&R days
- Wellness reimbursement and weekly onsite and virtual programming
- Generous vacation policy
- Industry-leading parental leave
- Family planning benefits
- Catered lunches and stocked kitchens