Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AWS @ 2
Communication @ 5
Data Analysis
GCP @ 2
OWASP @ 2
Payments
Python @ 5
Ruby @ 5
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Who We Are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Stripe’s mission is to increase the GDP of the internet.
About the Team
You’ll join Stripe’s Vulnerability Management team, whose mission is to surface vulnerabilities at scale across Stripe. The team’s vision is to create a culture of continuous excellence in managing vulnerabilities. The bug bounty program is an important pillar of this mission and a critical line of defense in Stripe’s security immune system.
Responsibilities
- Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
- Communicate clearly and effectively with security researchers to follow up on unclear reports, improve report clarity, and increase engagement with top hackers.
- Understand the root cause of security vulnerabilities to help product and engineering teams fix them and advise on appropriate mitigation strategies.
- Drive submissions through their full lifecycle to resolution, coordinating with product and engineering stakeholders.
- Act as the security bridge between external researchers and internal teams to facilitate rapid and effective remediation.
- Conduct in-depth data analysis on bug reports and vulnerability patterns to identify systemic risks and inform new security initiatives.
- Provide tactical support for vulnerability management triage processes as needed.
- Prepare and implement improvements to the overall bug bounty program, including researcher campaigns and scoring transparency.
- Provide feedback and requirements for tool development to enhance triage and security workflows, leveraging opportunities for automation.
- Develop a deep understanding of Stripe and acquired company products, assets, and configurations to effectively assess and prioritize vulnerabilities.
Requirements
Minimum Requirements
- Proven ability to follow bug reports and accurately triage security vulnerabilities.
- Familiarity with web security issues and exploit methodologies, including OWASP Top 10 and CWEs.
- Competence with offensive security tools, such as Burp Suite and custom scripting.
- Ability to think like an attacker to understand the impact of vulnerabilities.
- Proficiency in clear communication and conveying technical concepts to various stakeholders.
- Experience in bug bounty programs, triaging security vulnerability reports, knowledge of Stripe products, or general security expertise.
Preferred Qualifications
- Experience in technical support, operations, or similar roles involving technical systems.
- Prior participation in or experience with bug bounty programs.
- Experience analyzing source code for security vulnerabilities.
- Proficiency in scripting languages such as Python or Ruby for automation.
- Familiarity with cloud-based services such as AWS or GCP.
- Certifications such as OSWA or BSCP.
More jobs at Stripe
Solutions Architect, Enterprise (French Speaking)
Stripe · Toronto, Canada
CAD 208,100-312,100 per year
Strategy & Operations Program Manager
Stripe · United States
USD 157,800-236,800 per year
IT Support Engineer
Stripe · Dublin, Ireland
EUR 62,400-93,600 per year
Software Engineer - Infrastructure
Stripe · Seattle, United States
USD 156,800-235,200 per year
Specialist Solutions Architect - Money Management (APAC and Greater China)
Stripe · Sydney, Australia, Melbourne, Australia, Singapore, Singapore
SGD 298,300-447,500 per year
Similar jobs
Security Engineer, Privy
Stripe · New York City, United States
USD 196,900-295,300 per year
Software Engineer, Secrets Infrastructure
Stripe · United States
USD 173,000-259,600 per year
AI Engineer
Stripe · Chicago, United States
USD 126,600-235,300 per year
Senior Product Security Engineer
Collibra · United States
USD 168,000-210,000 per year
Senior Product Security Engineer
Collibra · Raleigh, United States
USD 168,000-210,000 per year
Application Security Engineer
SpaceXAI · Palo Alto, United States
USD 100,000-258,000 per year
Security Engineer - Offensive Security
Stripe · Dublin, Ireland, Spain, Ireland
EUR 112,200-168,200 per year
Senior Software Engineer II
Confluent · Boston, United States, Dallas, United States, Chicago, United States, United States, Portland, United States
USD 176,000-230,000 per year