Point your AI agent at freehire and let it find you a job.

Get the CLI →

Rippling

NewBe an early applicant

Principal Security Engineer

Posted Updated
Discussion

Summary

Hands-on principal-level security engineer at Rippling who reports to the CSO and leads cross-team security initiatives from San Francisco — replacing RBAC with JIT, agentic-AI-driven access control, designing inter-service isolation and AuthN/Z, and staying in the code while setting security architecture.

About the role


Rippling is looking for a Principal Security Engineer to tackle some of the most complex, cross-cutting security challenges across our technical ecosystem. Reporting directly to the CSO, you will lead high-impact initiatives that span security, AI, infrastructure, identity, developer experience, internal tooling, and third-party SaaS systems.

This is a deeply technical, hands-on role for an engineer who can move between architecture and implementation. You will take ambiguous security problems that cross organizational and technical boundaries, develop a cohesive technical strategy, and work alongside engineering teams to build and ship the solution.

"We’re looking for someone who has designed and delivered large-scale systems, can influence technical direction across multiple teams, and still wants to build. You’ll help redefine and implement parts of Rippling’s security program to take advantage of AI and agentic systems, applying these technologies to security controls, automation, and decision-making in ways that weren’t previously possible."

  • Replace RBAC for internal system access with a minimal privilege, JIT system using real-time agentic inspection of raw data from the employee graph, system alerts, incidents, customer requests, and support tickets
  • Integrate this JIT access control system into all third-party tools (e.g. SAAS applications) used by Rippling, and working with the product team to enable this for Rippling customers as well
  • Design and build robust inter-service isolation and sandboxing, as well as AuthN/Z to manage product attack surface, 0-day blast radius, and limit lateral movement


This role is based in San Francisco.


About the Team


Security at Rippling is responsible for protecting a platform that sits at the center of how companies manage their workforce, systems, and data. Our work touches nearly every part of Rippling's technical environment and requires close partnership with teams across Engineering, Infrastructure, Developer Experience, IT, and Product.


As a Principal Security Engineer, you will operate horizontally across these organizations rather than within a narrow security domain. You will identify systemic problems, bring together stakeholders with different requirements and priorities, and drive technical programs from initial architecture through implementation.


The team values engineers who combine strong technical judgment with urgency, ownership, and a bias toward action.


What you will do

  • Lead the architecture and implementation of complex security initiatives spanning multiple engineering teams and technical domains.
  • Incorporate the use of agentic AI technologies into security capabilities within both product and infrastructure technologies
  • Help business leaders understand and navigate risk tradeoffs to ensure Rippling is making well informed security decisions.
  • Design scalable security systems across areas such as identity and access management, cloud infrastructure, internal tooling, developer infrastructure, and third-party SaaS.
  • Translate ambiguous or fragmented security problems into clear technical architectures, roadmaps, and executable engineering plans.
  • Rationalize requirements and technical roadmaps across three or more teams into cohesive systems and long-term solutions.
  • Partner with senior engineers and engineering leaders across Security, Infrastructure, Developer Experience, IT, and Product to drive alignment on critical technical decisions.
  • Build prototypes, write production code, and remain hands-on throughout the lifecycle of the systems you design.
  • Identify architectural weaknesses and systemic security risks before they become incidents, then drive durable engineering solutions.
  • Establish technical patterns and frameworks that improve security while allowing engineering teams to continue moving quickly.
  • Raise the technical bar across the security organization through design reviews, mentorship, and influence across engineering.

What you will need

  • Significant experience designing, building, and operating complex systems in large-scale cloud or enterprise environments.
  • A track record of leading technically complex initiatives involving multiple engineering teams, competing requirements, and cross-functional stakeholders.
  • Deep expertise in one or more security domains, with identity and access management (IAM), authentication, authorization, or identity architecture experience particularly relevant.
  • Strong understanding of modern cloud and enterprise architecture, including security boundaries, workload isolation, service-to-service communication, and access-control systems.
  • Recent hands-on engineering experience and the ability to prototype, write code, and work directly with modern development tooling.
  • Experience building defensive agentic systems and integrating them with dynamic software development and operations.
  • Ability to move fluidly between high-level system architecture and detailed implementation decisions.
  • Strong technical judgment and the ability to make pragmatic tradeoffs between security, scalability, developer experience, and business needs.
  • Demonstrated ability to influence senior technical stakeholders without relying on organizational authority.
  • High degree of ownership, urgency, and bias toward action in ambiguous environments.
  • Experience and trajectory matter more to us than a specific number of years, but candidates will have 10+ years experience solving complex engineering and security problems.

Additional Information

Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email accommodations@rippling.com


Rippling highly values having employees working in-office to foster a collaborative work environment and company culture. For office-based employees (employees who live within a defined radius of a Rippling office), Rippling considers working in the office, at least three days a week under current policy, to be an essential function of the employee's role.

This role will receive a competitive salary + benefits + equity. The salary for US-based employees will be aligned with one of the ranges below based on location; see which tier applies to your location here.


A variety of factors are considered when determining someone’s compensation–including a candidate’s professional background, experience, and location. Final offer amounts may vary from the amounts listed below.

Skills

What Principal Security jobs ask for — and how much of it you have →

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available