Tech Stack

API @ 4 Automated Testing @ 4 Communication @ 7 Data Pipelines @ 6 Databricks @ 6 Fraud @ 6 LLM @ 4 Pandas @ 6 Payments Python @ 6 SQL @ 6 Security @ 4 Trino @ 6 scikit-learn @ 6

Details

Who We Are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Stripe’s mission is to increase the GDP of the internet.

About the Team

The Abuse Research Group (ARG) handles proactive threat hunting and adversary behavior analysis across Stripe products. Rather than reacting to alerts, the team maps end-to-end fraud and abuse paths, validates novel attack vectors, and identifies product conditions that enable fraud. Using agentic automated testing and simulation tools, ARG translates research into actionable threat advisories, strategic control recommendations, and regression scenarios to systematically eliminate vulnerabilities.

Responsibilities

  • Formulate hypotheses and conduct iterative threat hunting operations across Stripe systems and external data.
  • Apply and enrich the FT3 (Fraud Taxonomy 3.0) framework across empirical datasets and incidents, standardizing threat intelligence across kill chain phases and targeted API endpoints.
  • Partner with teams such as Fraud Intelligence to integrate, curate, and automate threat feeds into engineering workflows.
  • Translate raw research and retrospective findings into actionable threat advisories and control recommendations covering policies, technical systems, support workflows, and detection mechanisms for stakeholders across Fraud, Risk, Onboarding, and Security.
  • Use agentic automated testing frameworks to simulate adversary tactics, techniques, and procedures (TTPs), validate whether deployed controls interrupt empirical kill chains, and generate regression scenarios to exercise controls.

Requirements

Minimum Qualifications

  • 5+ years of experience conducting threat intelligence, threat hunting, or technical incident response within cybersecurity, product abuse, or trust domains.
  • 5+ years of experience analyzing large, complex datasets using data analytics tools to identify anomalies, map behavioral trends, and solve complex fraud problems.
  • B.S. or M.S. in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
  • Expert proficiency in Python and SQL, with demonstrated experience using code and scripting to automate workflows, build investigative tools, or query big data pipelines.
  • Hands-on experience with log analysis, including application logs, API route telemetry, and network security events; digital forensics; and cyber investigation methodologies.
  • Strong communication skills and the ability to translate complex technical research into clear, actionable recommendations and advisories for cross-functional partners.

Preferred Qualifications

  • Deep technical understanding of threat actor motivations, infrastructure, and TTPs specific to financial fraud, including account takeover, card testing, and credential stuffing.
  • Familiarity with standardized taxonomies such as FT3 or MITRE ATT&CK.
  • Proficiency with engineering, data processing, and analysis platforms such as Databricks, Trino, PySpark, Pandas, or Scikit-Learn.
  • Experience using Threat Intelligence Platforms (TIPs), tactical threat feeds, OSINT, and breach intelligence.
  • Experience building or leveraging agentic LLM tools, automated testing systems, or control validation frameworks to model adversary behavior at scale.

More jobs at Stripe

Similar jobs