Staff Security Engineer - Detection and Response

Posted 2 Days Ago
Be an Early Applicant
2 Locations
In-Office
205K-256K Annually
Senior level
Software
The Role
Lead architecture and execution of detection and response capabilities across AWS and broader infrastructure. Build AI-augmented detection/triage pipelines, design SIEM/SOAR ingestion and alerting frameworks, drive incident response for high-impact events, close detection gaps, mentor engineers, and set team standards for responsible AI usage.
Summary Generated by Built In
Staff Security Engineer - Detection and Response (L4)

Location: San Ramon, CA; Reno, NV

About Ridgeline

Ridgeline is the industry cloud platform for investment management. It was founded by visionary tech entrepreneur Dave Duffield (co-founder of both PeopleSoft and Workday) to apply his successful formula of solving operational business challenges with bold innovation and human connectivity to the unique needs of the investment management industry.

Ridgeline started with a clean sheet of paper and a deep bench of experts bound by a set of core values and motivated to revolutionize an industry underserved by its current tech offerings. We are building a new, modern platform in the public cloud, purpose-built for the investment management industry and we are prioritizing security, agility, and usability to empower business like never before.

With a growing campus in Reno and offices in New York, Lake Tahoe, and the Bay Area, Ridgeline is proud to have built a fast-growing, people-first company that has been recognized by Fast Company as a "Best Workplace for Innovators," by The Software Report as a "Top 100 Software Company," and by Forbes as one of "America's Best Startup Employers."

The Opportunity

As a member of the Detections and Response Team (DART) at Ridgeline, you will bring your expertise and new ideas to help develop and execute our Detections and Response roadmap. Acting as a significant architect for the systems overseeing our critical infrastructure - both within AWS and across our broader technical landscape - you will apply your expertise to elevate our collective detection coverage and lead the response to our highest-impact security events. Additionally, in this AI-forward role, you will engineer and validate robust, AI-augmented detection and response pipelines while serving as a key point person to ensure our standards for responsible and fluent AI usage remain relevant and effective.

At Ridgeline, the workplace culture is just as important as the products we build. We value ownership, transparency, and a bias toward action - which means we’re always looking for solutions rather than just identifying problems. We’re a team that chooses growth over comfort, owns our setbacks as much as our wins, and thrives on the kind of collaboration that pushes everyone to do their best work. If that’s the environment where you do your best work, we would be interested to meet you.

The impact you will have:

  • Shape the DART roadmap based on business priorities and threat models, proactively identifying detection requirements during the design phase of new features and infrastructure.
  • Eliminate detection gaps by performing variant analysis to close entire classes of vulnerabilities rather than addressing individual findings.
  • Architect AI-powered detection and triage pipelines that maintain accuracy and reduce manual effort, minimizing false positives so every alert warrants a response.
  • Collaborate as a key architect for our SIEM, SOAR, and adjacent security platforms, designing scalable, resilient ingestion, enrichment, and alerting frameworks.
  • Own the technical architecture and maturity of our incident response program, guiding the response to complex high-impact events, interfacing with leadership during major incidents, and driving findings to systemic remediation.
  • Set the technical direction for DART-owned codebases and infrastructure, making sound architectural tradeoffs that balance speed, correctness, and maintainability.
  • Establish team standards for the effective and responsible use of AI in detection and response workflows, including appropriate human-in-the-loop guardrails.
  • Influence security strategy across engineering organizations, building consensus with Staff+ engineers through technical credibility instead of unilateral directives.
  • Elevate the team's technical expertise by mentoring junior and mid-level engineers through code reviews, collaborative problem solving, and knowledge sharing.

What we look for:

  • 8+ years working in detection, security operations, incident response, or software engineering, with a proven track record of leading cross-functional technical initiatives.
  • Advanced proficiency in Python (preferred) or another high-level language like Kotlin or TypeScript.
  • Demonstrated skill engineering AI/LLM-driven systems: it is essential you are capable of building augmented detection, triage, and investigation workflows and rigorously validating their output for correctness and risk.
  • Expertise authoring detections mapped to attacker TTPs (e.g., MITRE ATT&CK).
  • Extensive background building and operating detection-as-code and alerting pipelines, tuned for signal quality and noise reduction.
  • Strong command of the AWS ecosystem, specifically across logging and telemetry (CloudTrail, VPC Flow Logs, GuardDuty, CloudWatch), investigative tools (Athena, IAM analysis), and compute (Lambda, ECS/EKS).
  • Fluency with infrastructure-as-code (e.g., Terraform) and CI/CD practices.
  • Strong written and verbal communication skills, with the ability to explain detection and response decisions clearly to engineers, product partners, and stakeholders.

Bonus:

  • History leading complex, high-impact incidents as a technical lead or incident commander.
  • Hands-on design of AI agents or LLM-based automation in a security operations context.
  • Contributions to open source detection/security tooling or published security research.

Compensation and Benefits 

The typical starting salary range for this role is: $205,000 - $256,000. Final compensation amounts are determined by multiple factors, including candidate experience and expertise, and may vary from the amount listed above. 

As an employee at Ridgeline, you’ll have many opportunities for advancement in your career and can make a true impact on the product. 

In addition to the base salary, Ridgeline employees can participate in our Company Stock Plan subject to the applicable Stock Option Agreement. We also offer rich benefits that reflect the kind of organization we want to be: one in which our employees feel valued and are inspired to bring their best selves to work. These include unlimited vacation, educational and wellness reimbursements, and $0 cost employee insurance plafis. Please check out our Careers page for a more comprehensive overview of our perks and benefits.


Ridgeline is proud to be a community-minded, discrimination-free equal opportunity workplace.

Ridgeline processes the information you submit in connection with your application in accordance with the Ridgeline Candidate Privacy Policy. Please review the Ridgeline Candidate Privacy Policy in full to understand our privacy practices and contact us with any questions.

This posting is for an existing vacancy.


Skills Required

  • 8+ years working in detection, security operations, incident response, or software engineering with proven cross-functional technical leadership
  • Advanced proficiency in Python
  • Proficiency in Kotlin or TypeScript
  • Demonstrated experience engineering AI/LLM-driven detection, triage, and investigation systems and validating their outputs
  • Expertise authoring detections mapped to attacker TTPs (e.g., MITRE ATT&CK)
  • Extensive background building and operating detection-as-code and alerting pipelines tuned for signal quality
  • Strong command of AWS logging, telemetry, investigative tools, and compute (CloudTrail, VPC Flow Logs, GuardDuty, CloudWatch, Athena, IAM analysis, Lambda, ECS/EKS)
  • Fluency with infrastructure-as-code (e.g., Terraform) and CI/CD practices
  • Strong written and verbal communication skills to explain detection and response decisions to stakeholders
  • Proven ability to mentor and elevate junior and mid-level engineers
  • History leading complex, high-impact incidents as a technical lead or incident commander
  • Hands-on design of AI agents or LLM-based automation in a security operations context
  • Contributions to open source detection/security tooling or published security research

Ridgeline Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Ridgeline and has not been reviewed or approved by Ridgeline.

  • Affordable Benefits Employee-only medical, dental, and vision coverage is offered at no cost, lowering out-of-pocket expenses. Wellness and education stipends further enhance the overall value of the package.
  • Equity Value & Accessibility Stock options are provided to all employees, creating broad-based ownership. This makes equity a meaningful pillar of total compensation.
  • Parental & Family Support Paid parental leave for all caregivers alongside fertility coverage indicates strong support for family-building. These benefits reduce logistical and financial strain during major life events.

Ridgeline Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Incline Village, NV
276 Employees
Year Founded: 2018

What We Do

Ridgeline has a simple mission: partner with investment management firms to modernize their software. Founded by software industry entrepreneur Dave Duffield, Ridgeline is headquartered in Incline Village, Nevada.

Similar Jobs

Benchling Logo Benchling

Artificial Intelligence Engineer

Cloud • Healthtech • Social Impact • Software • Biotech
Remote or Hybrid
US
605 Employees
176K-265K Annually

Coursera + Udemy  Logo Coursera + Udemy

Director, FP&A Systems and Transformation

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
United States
1500 Employees
178K-243K Annually

PNC Bank Logo PNC Bank

Technology Solution Center Analyst

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
37K-75K Annually

PNC Bank Logo PNC Bank

Software Engineer

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account