Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Data Science @ 2
Databricks @ 3
Fraud @ 5
Pandas @ 2
Payments
Python @ 2
SQL @ 2
Security @ 5
Trino @ 3
scikit-learn @ 2
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Who We Are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Stripe's mission is to increase the GDP of the internet.
About the Team
Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multidisciplinary group includes Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists. The team neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. Team members work directly with impacted merchants to resolve technical incidents and policy abuse rapidly, coordinating primarily across Eastern, Pacific, and Western European time zones with global stakeholders.
What You'll Do
You will help safeguard Stripe's financial ecosystem by investigating high-risk accounts and identifying complex patterns of fraud during incidents. You will lead incident response for product abuse and fraud events, conduct in-depth analyses to identify root causes, and collaborate cross-functionally to improve fraud detection and prevention strategies at scale. You will also help automate response processes through agentic approaches.
Responsibilities
- Investigate, mitigate, and remediate urgent fraud incidents, such as account takeovers and card testing, using FT3-mapped detection and signal enrichment to reduce uncertainty and accelerate response.
- Analyze high-risk accounts during incidents to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them with Fraud Taxonomy 3.0 (FT3) to standardize threat intelligence.
- Lead incident root-cause analyses to identify gaps in existing systems and strategies, leveraging the FT3 framework and data-driven models to improve processes and address emerging fraud risks.
- Streamline incident response capabilities and ensure that tooling and processes are clear, accurate, and efficient.
- Work cross-functionally with security, fraud, and data science teams to build agentic solutions for responding to abuse incidents at scale.
- Communicate effectively with legal and policy teams to assess and mitigate risks, while demonstrating strong problem-solving skills under pressure.
- Collaborate with teammates, lead projects, mentor others, and develop and champion quality standards within the team.
Requirements
Minimum Requirements
- 3+ years of experience conducting incident response in security, product abuse, or trust domains.
- 3+ years of experience analyzing large datasets to solve problems and/or building models with a behavioral approach to fraud detection.
- B.S. or M.S. in Computer Science or a related field, or equivalent experience.
- Expert knowledge of Python and SQL, with familiarity with other programming languages.
- Experience with log analysis, including first- or third-party applications, system or data access, and event logs; network security; digital forensics; and incident response investigations.
- Ability to communicate results clearly and focus on impact.
- Ability to think creatively and holistically about reducing risk in a complex environment.
Preferred Qualifications
- An adversarial mindset and understanding of threat actor goals, behaviors, and tactics, techniques, and procedures (TTPs).
- Experience with engineering, data processing, and analysis tools such as Databricks and Trino.
- Familiarity with open-source frameworks for big data processing and/or data science, such as PySpark, Pandas, and scikit-learn.
- Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment.
- Ability to challenge the status quo proactively by leveraging data and taking a user-centric approach to complex product integrity challenges.