Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Communication @ 7
Data Science @ 3
Databricks @ 4
Fraud @ 8
Pandas @ 3
Payments
Python @ 3
SQL @ 3
Security @ 8
Trino @ 4
scikit-learn @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Who We Are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Stripe's mission is to increase the GDP of the internet.
About the Team
Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multidisciplinary group includes Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists. The team neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. Team members work directly with impacted merchants to resolve incidents and policy abuse rapidly, operating primarily across Eastern, Pacific, and Western European time zones while coordinating with global stakeholders.
Responsibilities
- Respond to live fraud and abuse incidents as a Forward Deployed Security Engineer, investigating high-risk activity, neutralizing active attacks, and mitigating security risks across the ecosystem.
- Investigate, mitigate, and remediate urgent fraud incidents, including account takeover and card testing, using FT3-mapped (Fraud Taxonomy 3.0) detection and signal enrichment to reduce uncertainty and accelerate response.
- Analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.
- Develop, document, and execute incident response strategies, runbooks, and capabilities to continuously improve fraud and abuse detection and prevention.
- Act as a dedicated technical bridge during and after incidents, working directly with impacted merchants and customers to investigate root causes, remediate vulnerabilities, and secure accounts.
- Serve as an operational and technical liaison for legal teams, policy partners, and threat intelligence communities.
- Build and nurture strategic relationships across external threat intelligence communities, peer working groups, and law enforcement agencies.
Requirements
Minimum Requirements
- 10+ years of experience leading security or fraud incident response.
- B.S. or M.S. in Computer Science, or equivalent experience.
- Expert knowledge of Python and SQL, with familiarity with other programming languages.
- Experience with log analysis, including first- or third-party applications, system and data access, and event logs; network security; digital forensics; and incident response investigations.
- Proven ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
- Strong written and verbal communication skills, with a track record of driving cross-functional alignment with minimal oversight.
- Previous experience working with law enforcement.
- Engagement in threat intelligence sharing communities.
Preferred Qualifications
- Broad expertise across fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
- An adversarial mindset and understanding of threat actor goals, behaviors, and tactics, techniques, and procedures (TTPs).
- Experience with engineering, data processing, and analysis tools such as Databricks and Trino.
- Familiarity with open-source frameworks for big data processing and data science, such as PySpark, Pandas, and scikit-learn.
- Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment.
- Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges.
- Experience speaking at or participating in external conferences or similar industry engagements.