Senior Staff Security Engineer, Ripple Treasury
Job description
.
About the role
You will serve as the dedicated security engineering partner for Ripple Treasury, owning the technical direction and security posture of the Treasury solution and its infrastructure environment from assessment through remediation and ongoing maturity improvement. You will lead threat modeling and security architecture reviews across all Treasury offerings, ensuring security considerations are embedded in every design decision. This role requires you to define secure guardrails, CI/CD integrations, and developer guidance that make secure by default a practical reality for the engineering teams you partner with. You will drive the cloud security architecture for Treasury across Azure and AWS, including IAM, network segmentation, encryption, zero trust controls, Kubernetes traffic policies, and DDoS and WAF strategy. You will own vulnerability discovery via security assessments, penetration testing and bug bounty, driving findings through triage, prioritization, remediation, and validation with a bias toward automation and developer self-service. You will mentor and develop Security Engineers and build a Security Champions model within Treasury Engineering to extend the Security team's reach at scale.
Key facts
What you'll do
- Serve as the dedicated Security Engineering partner for Ripple Treasury BU, owning the security posture of the Treasury solution and infrastructure environment from assessment through remediation and ongoing maturity improvement.
- Lead threat modeling and security architecture reviews across Treasury offerings to identify risks early and ensure robust security foundations.
- Own the secure software development lifecycle for your product surface area, defining security guardrails, CI/CD integrations, and developer guidance that make secure by default a practical reality.
- Drive the cloud security architecture for Treasury across Azure and AWS, including IAM, network segmentation, encryption, zero trust controls, Kubernetes traffic policies, and DDoS and WAF strategy, ensuring full alignment with Ripple's infrastructure standards as Treasury integrates.
- Partner with GRC to ensure Treasury meets its compliance obligations across SOC 2, ISO 27001, and applicable financial regulatory frameworks as the BU integrates into Ripple's governance program.
- Own vulnerability discovery via security assessments, penetration testing and bug bounty, driving findings through triage, prioritization, remediation, and validation with a bias toward automation and developer self-service.
- Build and scale a Security Champions model within Treasury Engineering, embedding security advocates who extend the Security Engineering team's reach at scale.
- Influence engineering architecture decisions at the senior level, participating in design reviews and architectural assessments with the standing to raise security concerns that get acted on.
- Mentor and develop Security Engineers, raising the technical bar through threat model walkthroughs, design discussions, and structured knowledge sharing.
- Stay ahead of the threat landscape for FinTech, crypto, and enterprise treasury systems, translating emerging attack techniques into concrete defensive improvements across platforms and systems.
Requirements
- 10+ years of Security Engineering experience, including hands-on work in Product Security and Infrastructure Security.
- Expert-level product security skills including threat modeling using STRIDE or equivalent, security architecture review, OWASP Top 10 and beyond, API security, authentication and authorization design, and secure SDLC development.
- Deep expertise in securing cloud environments across Azure, AWS, and/or GCP, covering IAM architecture, network security, secrets management, container and Kubernetes security, and infrastructure as code security.
- Hands-on experience building and operating DevSecOps tooling, including static analysis, dynamic analysis, software composition analysis, secrets scanning, container scanning, and CI/CD pipeline security integration.
- Strong software engineering skills in Python, Go, or equivalent languages that enable you to build security tooling, automate analysis, and integrate security into developer workflows.
- Demonstrated experience working with financial services, crypto, or regulated environments, understanding the unique risks and compliance demands of these sectors.
- Proven ability to operate independently at a senior level, exercising sound judgment and influencing without authority in a matrixed organization.
- Experience with security frameworks, risk assessment methodologies, and compliance mapping to standards such as SOC 2, ISO 27001, and relevant financial regulations.
- Strong written and verbal communication skills to articulate complex technical risks to both technical and non-technical stakeholders and to drive remediation efforts.
Practical notes
-
Location: New York, NY, United States
- Travel: SOURCE does not specify travel requirements
- Visa: SOURCE does not specify visa sponsorship details
- Deadline: SOURCE does not specify application deadlines
The role is situated within the Ripple Treasury organization, where you will work closely with product managers, engineers, and cross-functional stakeholders to embed security into the full lifecycle of digital asset treasury solutions. You will be expected to operate with a high degree of autonomy, balancing strategic security initiatives with tactical execution against emerging vulnerabilities and compliance needs. Your work will directly impact the security of financial infrastructure used by institutions and developers building on Ripple's platform. This position requires a deep commitment to security excellence, continuous learning, and collaboration across distributed teams. You will contribute to internal security programs, including incident response, security training, and architecture reviews, ensuring that security remains a core competency as Ripple scales its treasury offerings. The ideal candidate is comfortable in fast-paced environments, capable of managing multiple priorities, and passionate about leveraging security to enable business innovation rather than restrict it. You will have opportunities to grow your skills in cloud security, application security, and DevSecOps while mentoring others and shaping security practices across the engineering organization. This is a senior-level position that expects mastery of current security tools and techniques, along with the ability to anticipate and defend against evolving threats in the cryptocurrency and financial infrastructure space. You will be evaluated on your ability to execute against security objectives, improve the security posture of the organization, and partner effectively with product and engineering teams.