Security Engineer - Offensive Security

at Stripe
📍 Spain
📍 Ireland
📍 Dublin, Ireland
EUR 112,200-168,200 per year
MIDDLE
✅ Remote ✅ On-site

Tech Stack

AI @ 5 API AWS @ 3 Azure @ 3 Claude Code @ 5 Communication @ 3 Databricks @ 2 FinTech @ 3 GCP @ 3 GitHub @ 5 Go @ 6 LLM @ 5 Machine Learning OWASP @ 6 Python @ 6 Security @ 5 Splunk @ 2

Details

Stripe's Proactive Threat team identifies vulnerabilities and security weaknesses across the company's systems, applications, networks, and cloud infrastructure before adversaries do. The team conducts penetration testing, emulates real-world threat actors through red team operations, validates detection capabilities, and builds custom tooling, automation frameworks, and internal platforms for scalable offensive security assessments.

The team is distributed across the United States and collaborates with security, engineering, and product stakeholders across Stripe, including teams in Europe and Asia.

Responsibilities

  • Conduct penetration tests across web applications, APIs, AWS, GCP, and Azure cloud environments, mobile applications, and internal infrastructure.
  • Plan and execute red team engagements that emulate cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration.
  • Perform assumed-breach and objective-based assessments to test detection and response capabilities with defensive teams.
  • Partner with detection engineering, threat intelligence, and incident response teams to validate controls, identify coverage gaps, and improve detection fidelity.
  • Contribute adversary tradecraft insights to detection rules, threat-hunting hypotheses, and incident-response playbooks.
  • Support incident investigations through offensive expertise, log analysis, and root-cause analysis.
  • Design, develop, and maintain offensive tools, scripts, automation frameworks, internal platforms, and workflows.
  • Automate testing tasks, payload generation, and reporting workflows using modern development practices.
  • Contribute to internal security-tooling repositories and promote engineering best practices.
  • Produce actionable reports explaining technical findings, business risk, and remediation guidance to technical and non-technical stakeholders.
  • Serve as a subject-matter expert for offensive security programs and company-wide security initiatives.
  • Lead offensive security projects, mentor junior team members, and support continuous learning.
  • Stay current with emerging threats, vulnerabilities, and attack techniques, and share research internally and with the broader security community.

Requirements

Minimum Requirements

  • 5+ years of experience in offensive security, penetration testing, red teaming, or a related field.
  • Strong programming skills in Python, Go, or similar languages, with experience building tools, automation, or custom exploits.
  • Deep knowledge of web application security, including OWASP Top 10, ASVS, injection, authentication flaws, and business-logic vulnerabilities.
  • Hands-on experience with AWS, Azure, or GCP, including cloud-native attack techniques and misconfigurations.
  • Proficiency with offensive-security tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks.
  • Familiarity with MITRE ATT&CK and adversary tactics, techniques, and procedures for initial access, privilege escalation, lateral movement, and exfiltration.
  • Excellent written and verbal communication skills, including the ability to translate complex technical findings into clear, risk-based recommendations.
  • Ability to think like an adversary and assess risk holistically in complex environments.

Preferred Qualifications

  • Experience conducting offensive security in fintech, financial services, or other highly regulated environments.
  • Background in vulnerability research, exploit development, or CVE discovery.
  • Experience collaborating with threat intelligence, detection engineering, or incident response teams in purple-team operations.
  • Familiarity with Splunk, Databricks, PySpark, osquery, or similar tools for threat hunting and investigative support.
  • Proficiency with AI/LLM-assisted development tools such as Claude Code, Cursor, or GitHub Copilot.
  • Experience using LLMs or autonomous agents for reconnaissance, vulnerability discovery, or exploitation workflows.
  • Experience testing AI/ML systems or LLM-based applications for prompt injection, training-data extraction, model manipulation, and related security weaknesses.
  • Contributions to open-source security tools, published research, blog posts, or conference presentations.
  • Relevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud-security certifications.

More jobs at Stripe

Similar jobs