Engineering Manager, Abuse Control Engineering

at Stripe
USD 236,000-354,000 per year
SENIOR
✅ Remote ✅ On-site

Tech Stack

A/B Testing @ 4 API @ 3 Experimentation @ 4 Fraud @ 4 Hiring @ 4 Payments Security @ 4

Details

Who We Are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Stripe’s mission is to increase the GDP of the internet.

About the Team

Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE uses real attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale. The team partners closely with Fraud, Risk, and Product Engineering to run rigorous experiments, balancing aggressive risk mitigation against legitimate user conversion.

ACE operates as both a strike team and an incubator. It builds automated regression suites in partnership with Abuse Research to permanently block threat recurrence and transfers mature controls to long-term product owners across Stripe.

As the Engineering Manager for Abuse Control Engineering, you will lead a team responsible for closing urgent, cross-product defense gaps and incubating controls until they are ready for long-term ownership. You will be accountable for the team’s technical direction, people leadership, hiring, coaching, and cross-functional execution.

You will help the team turn attacker evidence into clear technical priorities, guide the design and evaluation of safeguards, and ensure that decisions account for both risk reduction and the experience of legitimate users. You will also establish disciplined incubation and handoff practices so that successful controls move to the appropriate product teams with clear ownership, documentation, criteria, and timelines.

Responsibilities

  • Define and communicate the team’s technical strategy and priorities for identifying cross-product abuse gaps, incubating controls, and preventing the recurrence of mitigated threats.
  • Hire, manage, coach, and support engineers; provide clear expectations and feedback; and create opportunities for engineers to expand their technical judgment, leadership, and impact.
  • Ensure that attacker evidence, product context, and measurable outcomes inform technical abuse requirements, control designs, and investment decisions.
  • Partner with Application Security and product engineering teams to develop safeguards that are resilient, appropriately scoped, and compatible with the systems in which they operate.
  • Guide experiments that assess risk reduction and the effect of controls on legitimate user conversion.
  • Ensure the team develops regression tests and other mechanisms that can detect whether previously mitigated abuse patterns recur.
  • Establish success measures, operational expectations, documentation, destination owners, handoff criteria, and target dates for incubated controls.
  • Hold the team and its partners accountable for transferring successful controls to the product teams that permanently own the relevant surfaces, except where a control is intentionally maintained as a durable capability serving multiple products.
  • Align security, product, engineering, and other partners around priorities, tradeoffs, responsibilities, and delivery plans, including situations requiring urgent coordination.

Requirements

Minimum Requirements

  • Experience managing an engineering team, including setting direction, prioritizing work, and being accountable for delivery and technical outcomes.
  • A relevant technical foundation in software engineering, security engineering, application security, anti-abuse engineering, or a closely related field, developed through professional experience, education, or an equivalent path.
  • Experience hiring, coaching, and developing engineers with different levels of experience, including providing actionable feedback and supporting career growth.
  • Experience leading cross-functional technical work involving teams with different goals, areas of expertise, or ownership boundaries.
  • Ability to evaluate technical designs, ask effective questions, and guide engineering decisions involving reliability, security, risk, and product tradeoffs.
  • Experience communicating technical strategy, priorities, risks, and decisions clearly to engineering teams and cross-functional stakeholders.
  • Ability to create clarity in ambiguous or urgent situations and translate broad risk problems into actionable plans, ownership, and measurable outcomes.

Preferred Qualifications

  • Experience guiding experimentation or A/B testing, including evaluating control effectiveness and balancing risk reduction against effects on legitimate user conversion.
  • Knowledge of threat modeling, secure systems design, or modern application security practices.
  • Familiarity with API safeguards and abuse controls such as rate limits, authorization checks, input validation, step-up challenges, or related protective mechanisms.
  • Knowledge of financial-fraud patterns, attacker behavior, attack methods, or the infrastructure used to conduct abuse.
  • Experience using or overseeing work involving large-scale data platforms to analyze system activity, identify patterns, or measure control performance.
  • Experience incubating technical capabilities and transferring them to long-term owners through explicit success criteria, documentation, operational readiness, and target dates.
  • Experience leading a distributed team or coordinating execution across teams in multiple locations or time zones.

More jobs at Stripe

Similar jobs