Staff Detection and Response Engineer

7 days ago


Dublin, Dublin City, Ireland Rippling Full time
About Rippling
Rippling is the first way for businesses to manage all of their HR & IT—payroll, benefits, computers, apps, and more—in one unified workforce platform.
By connecting every business system to one source of truth for employee data, businesses can automate all of the manual work they normally need to do to make employee changes. Take onboarding, for example. With Rippling, you can just click a button and set up a new employees' payroll, health insurance, work computer, and third-party apps—like Slack, Zoom, and Office 365—all within 90 seconds.
Based in San Francisco, CA, Rippling has raised $1.2B from the world's top investors—including Kleiner Perkins, Founders Fund, Sequoia, Bedrock, and Greenoaks—and was named one of America's best startup employers by Forbes (#12 out of 500). About the role

We are looking for an experienced Security Engineer to join our Detection and Response Team (DART).  You will help us build out a world class incident response function that will navigate challenging security incidents, drive process improvement, develop an open culture where we grow from our mistakes as an organization.   In this role, you will also build the tools and detection infrastructure that we need to scale our detection and response capability across all threats to our Production and Corporate environments.

What you will do

  • Respond to security events, triage, perform investigations, incident analysis, and communicate clearly and efficiently to stakeholders

  • Contribute to improving processes, procedures, and technologies used for detection and response, enabling us to improve after each incident

  • Develop and run tools to gather security telemetry data from cloud production systems 

  • Automate workflows and improve identification and response time for security events

  • Build and optimize detection rules, allowing us to spend our cycles on the alerts that matter

  • Develop runbooks and incident playbooks for new and existing detections

  • Lead Threat hunting practices, suggest product and infrastructure signals to surface attacks and incorporate findings into security controls

What you will need

  • 8+ years of full-time experience as a security engineer, including security monitoring, incident response, and threat hunting in a cloud environment

  • A defensive practitioner who understands offensive security and, the actual scenarios that lead to compromise

  • Prior experience leading complex investigations with a large number of stakeholders

  • Strong communication skills and a proven track record of communicating with internal and external stakeholders at all levels.

  • Expertise on AWS security controls and services. 

  • Experience leveraging coding for automation, alert enrichment and detections. 

  • Knowledge of adversary tactics, techniques, and procedures (TTPs) and MITRE ATT&CK principles

  • Hands-on experience with data analysis, modeling, and correlation at scale

  • Operating systems internals and forensics experience for macOS, Windows & Linux

  • Domain experience managing and working with current SIEM and SOAR platforms

  • Experience developing tools and automation using common DevOps toolsets and programming languages

  • Understanding of malware functionality and persistence mechanisms

  • Ability to analyze endpoint, network, and application logs for anomalous events

Additional Information
Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email   accomodations@rippling.com
Rippling highly values having employees working in-office to foster a collaborative work environment and company culture.  For office-based employees (employees who live within a 40 mile radius of a Rippling office), Rippling considers working in the office, at least three days a week under current policy, to be an essential function of the employee's role.

  • Dublin, Dublin City, Ireland Tbwa ChiatDay Inc Full time

    Security Engineer, Detection and Response TeamDublin, IrelandAbout Us:We're on a mission to make it possible for every person, team, and company to tailor their software to solve any problem and take on any challenge. At Notion, we want to change this with focus, design, and craft.We've been working on this together since 2016, with customers like Pixar,...


  • Dublin, Dublin City, Ireland Tbwa ChiatDay Inc Full time

    Security Engineer, Detection and Response TeamDublin, IrelandAbout Us:We're on a mission to make it possible for every person, team, and company to be able to tailor their software to solve any problem and take on any challenge.Computers may be our most powerful tools, but most of us can't build or modify the software we use on them every day.At Notion, we...


  • Dublin, Dublin City, Ireland Tbwa ChiatDay Inc Full time

    Security Engineer, Detection and Response TeamDublin, IrelandAbout Us:We're on a mission to make it possible for every person, team, and company to tailor their software to solve any problem and take on any challenge. Computers may be our most powerful tools, but most of us can't build or modify the software we use on them every day. At Notion, we want to...


  • Dublin, Dublin City, Ireland Notion Full time

    About Us:We're on a mission to make it possible for every person, team, and company to be able to tailor their software to solve any problem and take on any challenge. Computers may be our most powerful tools, but most of us can't build or modify the software we use on them every day. At Notion, we want to change this with focus, design, and craft.We've been...


  • Dublin, Dublin City, Ireland Google Full time

    Minimum qualifications:Bachelor's degree or equivalent practical experience.3 years of experience in incident response or emergency management.2 years of experience with security assessments or security design reviews or threat modeling.Preferred qualifications:Experience with digital forensics.Experience managing privacy incidents.Familiarity with security...


  • Dublin, Dublin City, Ireland ENGINEERINGUK Full time

    We're looking for a highly skilled Advanced Threat Detection Engineer to join our team. As a member of our team, you'll be responsible for developing and implementing advanced threat detection systems that protect our cloud infrastructure.About the RoleThis role involves working on cutting-edge security technologies and collaborating with cross-functional...


  • Dublin, Dublin City, Ireland Amazon Full time

    As an AWS Threat Detection Engineer, you will play a critical role in protecting Amazon's cloud infrastructure from emerging security threats. Your expertise in threat detection and mitigation will help us stay ahead of the curve in ensuring the security and integrity of our cloud services.**Key Responsibilities**Design and implement threat detection...


  • Dublin, Dublin City, Ireland Amazon Full time

    **Job Description**We're looking for a skilled Threat Detection Engineer to join our security team. In this role, you'll research, identify, and prioritize security problems that can be detected using automation. You'll develop detection prototypes for these security problems to enhance detection capabilities and identify opportunities to prevent security...


  • Dublin, Dublin City, Ireland Google Full time

    Minimum qualifications:Bachelor's degree or equivalent practical experience.3 years of experience in incident response or emergency management.2 years of experience with security assessments or security design reviews or threat modeling.Preferred qualifications:Experience with digital forensics.Experience managing privacy incidents.Familiarity with security...


  • Dublin, Dublin City, Ireland Amazon Full time

    Incident Management Engineer, AWS Incident Detection and ResponseJob ID: 2882806 | Amazon Web Services EMEA SARL (Irish Branch)ABOUT USAmazon has built a reputation for excellence with a mission to be the earth's most customer-centric company. Amazon Web Services (AWS) is carrying on that tradition while leading the world in cloud technologies.The AWS...


  • Dublin, Dublin City, Ireland Google Full time

    corporate_fare Google place Dublin, IrelandMidExperience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area.Applylink Copy linkBachelor's degree or equivalent practical experience.3 years of experience in incident response or emergency management.2 years of experience with...


  • Dublin, Dublin City, Ireland Amazon Full time

    Security Detection Engineer, AWS SecurityJob ID: | Amazon Data Services Ireland LimitedCome and build innovative services that protect our cloud from advanced security threatsAs a Security Engineer on our team, you'll help build and manage services that detect and automate the mitigation of cybersecurity threats across Amazon's infrastructure, including...


  • Dublin, Dublin City, Ireland Amazon Full time

    Security Detection Engineer, AWS Security Come and build innovative services that protect our cloud from advanced security threatsAs a Security Engineer on our team, you'll help build and manage services that detect and automate the mitigation of cybersecurity threats across Amazon's infrastructure, including advanced persistent threats.You'll work with...

  • Senior Detection

    3 weeks ago


    Dublin, Dublin City, Ireland Expel Full time

    Imagine yourself as a SOC analyst and a new alert shoots to the top of the queue. You open the alert and all of the relevant facts are laid out for you. You know the who, the what, and the where of what happened and it's all right there in the alert. You notice the attacker IP immediately and wonder, "Where is that IP located?". Wonder no more because the IP...


  • Dublin, Dublin City, Ireland Sysdig Full time

    In the cloud, every second counts. On the leading edge of security, Sysdig stops attacks in real-time by instantly detecting changes in cloud security risk with runtime insights and open source Falco. Trusted by a large enterprise customer base, we are a well-funded startup, passionate open source enthusiasts at heart, and problem-solvers who are building...


  • Dublin, Dublin City, Ireland Amazon Full time

    Security Detection Engineer, AWS SecurityJob ID: 2886798 | Amazon Data Services Ireland LimitedCome and build innovative services that protect our cloud from advanced security threatsAs a Security Engineer on our team, you'll help build and manage services that detect and automate the mitigation of cybersecurity threats across Amazon's infrastructure,...


  • Dublin, Dublin City, Ireland Google Full time

    Security Engineer, Detection, Security Surveillancecorporate_fare Google place Dublin, IrelandApplyMinimum Qualifications:Bachelor's degree or equivalent practical experience.2 years of experience with security assessments or security design reviews or threat modeling.2 years of experience with security engineering, computer and network security and security...


  • Dublin, Dublin City, Ireland Amazon Full time

    About the RoleWe are seeking a highly skilled and experienced Security Threat Detection Specialist to join our team. As a Security Detection Engineer, you will be responsible for building innovative services that protect our cloud from advanced security threats.Key responsibilities include researching, identifying, and prioritizing security problems that can...


  • Dublin, Dublin City, Ireland Expel Full time

    You know that NOP sleds don't go down snowbanks, and that IR isn't just on the electromagnetic spectrum. In fact, you've owned a few boxes with Metasploit, maybe even tinkered with exploit code. You were really excited the first time you got a reverse shell. Meterpreter might be your payload of choice, maybe even Beacon. You have a lab where you're spending...


  • Dublin, Dublin City, Ireland Amazon Full time

    Incident Management Engineer, AWS Incident Detection and ResponseJob ID: 2882806 | Amazon Web Services EMEA SARL (Irish Branch)ABOUT USAmazon has built a reputation for excellence with a mission to be the earth's most customer-centric company. Amazon Web Services (AWS) is carrying on that tradition while leading the world in cloud technologies.The AWS...