Offensive Security Engineer

at Stripe
USD 170,400-255,700 per year
SENIOR
✅ Remote

Tech Stack

AI @ 6 API AWS @ 4 Azure @ 4 Claude Code @ 6 Communication @ 6 Databricks @ 3 FinTech @ 4 GCP @ 4 GitHub @ 6 Go @ 7 LLM @ 6 Machine Learning OWASP @ 7 Payments Python @ 7 Security @ 4 Splunk @ 3

Details

Who We Are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Stripe’s mission is to increase the GDP of the internet.

About the Team

The Proactive Threat team identifies vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure before adversaries do. The team conducts penetration testing, emulates real-world threat actors through red team operations, and partners with defensive security teams to validate detection capabilities and improve Stripe's security posture.

The team develops custom tooling, automation frameworks, and internal platforms to scale offensive capabilities and enable repeatable, high-fidelity assessments. The team is distributed across the United States, primarily operating in Eastern and Pacific time zones, and collaborates with stakeholders in Europe and Asia.

Responsibilities

  • Conduct comprehensive penetration tests across web applications, APIs, cloud environments such as AWS, GCP, and Azure, mobile applications, and internal infrastructure.
  • Plan and execute red team engagements that emulate cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios.
  • Perform assumed-breach and objective-based assessments to test detection and response capabilities with defensive teams.
  • Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity.
  • Contribute adversary tradecraft insights to detection rule development, threat-hunting hypotheses, and incident response playbooks.
  • Support incident investigations through offensive expertise, log analysis, and root cause analysis.
  • Design, develop, and maintain custom offensive tools, scripts, and automation frameworks.
  • Build internal platforms and workflows for scalable, repeatable offensive operations.
  • Contribute to internal security tooling repositories and promote engineering best practices.
  • Automate testing tasks, payload generation, and reporting workflows using modern development practices.
  • Produce clear reports communicating technical findings, business risks, and remediation guidance to technical and non-technical stakeholders.
  • Serve as a subject-matter expert and primary point of contact for stakeholder teams involved in offensive security programs and company-wide security initiatives.
  • Lead offensive security projects end-to-end, mentor junior team members, and promote continuous learning and knowledge sharing.
  • Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and with the broader security community.

Requirements

Minimum Requirements

  • At least 5 years of experience in offensive security, penetration testing, red teaming, or a related field.
  • Strong programming skills in Python, Go, or similar languages, with experience building tools, automation, or custom exploits.
  • Deep knowledge of web application security, including OWASP Top 10, ASVS, injection, authentication flaws, and business logic vulnerabilities.
  • Hands-on experience with AWS, Azure, or GCP, including cloud-native attack techniques and misconfigurations.
  • Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks.
  • Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including techniques for initial access, privilege escalation, lateral movement, and exfiltration.
  • Excellent written and verbal communication skills, including the ability to translate complex technical findings into clear, risk-based recommendations.
  • Ability to think like an adversary and assess risk holistically in complex environments.

Preferred Qualifications

  • Experience conducting offensive security in fintech, financial services, or other highly regulated environments.
  • Background in vulnerability research, exploit development, or CVE discovery.
  • Experience collaborating with threat intelligence, detection engineering, or incident response teams in purple team operations.
  • Familiarity with Splunk, Databricks, PySpark, osquery, or similar tools for threat hunting or investigative support.
  • Proficiency with AI/LLM-assisted development tools such as Claude Code, Cursor, and GitHub Copilot.
  • Experience with agentic automation using LLMs or autonomous agents for reconnaissance, vulnerability discovery, or exploitation workflows.
  • Experience testing AI/ML systems or LLM-based applications for prompt injection, training data extraction, model manipulation, or other security weaknesses.
  • Contributions to open-source security tools, published research, blog posts, or conference presentations.
  • Relevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications.

Location

This role is remote within the United States. Employees may visit Stripe offices for team meetings, on-sites, and events, but are expected to regularly work from home. The team primarily coordinates across Eastern and Pacific time zones and collaborates with stakeholders in Europe and Asia.

Compensation & Benefits

The annual US base salary range is $170,400–$255,700. The range may span multiple career levels and will be refined during the interview process based on experience, qualifications, and location.

Additional benefits include:

  • Equity participation in Stripe's growth.
  • 401(k) plan with matching contributions from day one.
  • Comprehensive medical, dental, and vision coverage.
  • Wellness stipends.
  • Annual budget for training, certifications, and conference attendance.

More jobs at Stripe

Similar jobs