Security Engineer @Stripe
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 3wks ago

[Hiring] Security Engineer @Stripe

3wks ago - Stripe is hiring a remote Security Engineer. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

As an Abuse Control Engineer on the Abuse Control Engineering (ACE) team, you will design, prototype, and incubate technical defenses that safeguard Stripe’s financial ecosystem against complex, cross-cutting abuse vectors.

  • Rapidly build and experiment with technical safeguards where emerging threat patterns identify Stripe product weaknesses.
  • Translate threat intelligence into hard technical control requirements (e.g., API rate-limiting, step-up challenges, parameter validation, pre-debit holds).
  • Balance security and product velocity, running experiments to evaluate risk reduction against user conversion impact.
  • Manage controls through a strict incubation lifecycle, building automated regression suites to prevent recurrence.
  • Partner with native product teams to hand off mature, long-term defenses.

Responsibilities

  • Design, prototype, and deploy technical controls across API, protocol, and product boundaries to immediately close high-impact abuse vectors.
  • Translate empirical attacker evidence and FT3 threat research into precise technical abuse requirements and control specifications.
  • Collaborate closely with teams across Stripe to co-design resilient, secure controls across payment, onboarding, identity, and Connect surfaces.
  • Run rigorous experiments and A/B tests to measure risk reduction against legitimate user conversion impact, optimizing controls to minimize friction while neutralizing threats.
  • Build comprehensive regression testing suites and automated attack simulations with Abuse Research to ensure mitigated abuse vectors do not recur.
  • Execute ACE’s incubation model by defining handoff criteria, operational documentation, and target dates to transfer successful controls to product teams.

Qualifications

  • 3+ years of experience in Security Engineering, Software Engineering, Application Security, or Anti-Abuse Engineering in a high-scale production environment.
  • B.S. or M.S. in Computer Science, Cybersecurity, Software Engineering, or a related technical field, or equivalent practical experience.
  • Strong software development background with expert proficiency in Python, Go, Java, or similar production languages, alongside expert SQL skills for analyzing system telemetry.
  • Hands-on engineering experience building API-level safeguards, rate-limiting frameworks, authentication/authorization checks, or input validation controls.
  • Demonstrated experience with automated testing frameworks, including writing unit, integration, and regression tests for critical backend software.
  • Strong cross-functional collaboration and communication skills, with a track record of partnering across security, product, and platform teams to drive technical outcomes.

Preferred Qualifications

  • Proven track record of designing and executing A/B tests, evaluating control efficacy, and balancing security safeguards against user conversion friction.
  • Deep expertise in threat modeling, secure system architecture, and modern application security design principles.
  • Familiarity with established threat frameworks (e.g., FT3, MITRE ATT&CK) and applying adversary kill chain analysis to build resilient defenses.
  • Strong domain knowledge of financial fraud vectors, threat actor TTPs, and attacker infrastructure (e.g., Account Takeover, Card Testing, Credential Stuffing).
  • Hands-on experience with large-scale data processing platforms (e.g., Databricks, Trino, PySpark) to monitor and measure control performance across distributed systems.
  • Demonstrated capability in incubating software features, establishing clear operational handoff criteria, and seamlessly transitioning ownership to partner engineering teams.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Security Engineer @Stripe
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 3wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,845+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later