Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 5
API
AWS @ 3
Azure @ 3
Claude Code @ 5
Communication @ 3
Databricks @ 2
FinTech @ 3
GCP @ 3
GitHub @ 5
Go @ 6
LLM @ 5
Machine Learning
OWASP @ 6
Python @ 6
Security @ 5
Splunk @ 2
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Stripe's Proactive Threat team identifies vulnerabilities and security weaknesses across the company's systems, applications, networks, and cloud infrastructure before adversaries do. The team conducts penetration testing, emulates real-world threat actors through red team operations, validates detection capabilities, and builds custom tooling, automation frameworks, and internal platforms for scalable offensive security assessments.
The team is distributed across the United States and collaborates with security, engineering, and product stakeholders across Stripe, including teams in Europe and Asia.
Responsibilities
- Conduct penetration tests across web applications, APIs, AWS, GCP, and Azure cloud environments, mobile applications, and internal infrastructure.
- Plan and execute red team engagements that emulate cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration.
- Perform assumed-breach and objective-based assessments to test detection and response capabilities with defensive teams.
- Partner with detection engineering, threat intelligence, and incident response teams to validate controls, identify coverage gaps, and improve detection fidelity.
- Contribute adversary tradecraft insights to detection rules, threat-hunting hypotheses, and incident-response playbooks.
- Support incident investigations through offensive expertise, log analysis, and root-cause analysis.
- Design, develop, and maintain offensive tools, scripts, automation frameworks, internal platforms, and workflows.
- Automate testing tasks, payload generation, and reporting workflows using modern development practices.
- Contribute to internal security-tooling repositories and promote engineering best practices.
- Produce actionable reports explaining technical findings, business risk, and remediation guidance to technical and non-technical stakeholders.
- Serve as a subject-matter expert for offensive security programs and company-wide security initiatives.
- Lead offensive security projects, mentor junior team members, and support continuous learning.
- Stay current with emerging threats, vulnerabilities, and attack techniques, and share research internally and with the broader security community.
Requirements
Minimum Requirements
- 5+ years of experience in offensive security, penetration testing, red teaming, or a related field.
- Strong programming skills in Python, Go, or similar languages, with experience building tools, automation, or custom exploits.
- Deep knowledge of web application security, including OWASP Top 10, ASVS, injection, authentication flaws, and business-logic vulnerabilities.
- Hands-on experience with AWS, Azure, or GCP, including cloud-native attack techniques and misconfigurations.
- Proficiency with offensive-security tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks.
- Familiarity with MITRE ATT&CK and adversary tactics, techniques, and procedures for initial access, privilege escalation, lateral movement, and exfiltration.
- Excellent written and verbal communication skills, including the ability to translate complex technical findings into clear, risk-based recommendations.
- Ability to think like an adversary and assess risk holistically in complex environments.
Preferred Qualifications
- Experience conducting offensive security in fintech, financial services, or other highly regulated environments.
- Background in vulnerability research, exploit development, or CVE discovery.
- Experience collaborating with threat intelligence, detection engineering, or incident response teams in purple-team operations.
- Familiarity with Splunk, Databricks, PySpark, osquery, or similar tools for threat hunting and investigative support.
- Proficiency with AI/LLM-assisted development tools such as Claude Code, Cursor, or GitHub Copilot.
- Experience using LLMs or autonomous agents for reconnaissance, vulnerability discovery, or exploitation workflows.
- Experience testing AI/ML systems or LLM-based applications for prompt injection, training-data extraction, model manipulation, and related security weaknesses.
- Contributions to open-source security tools, published research, blog posts, or conference presentations.
- Relevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud-security certifications.
More jobs at Stripe
Full Stack Engineer, Developer & End User Experience Platform
Stripe · Toronto, Canada
CAD 135,200-202,800 per year
Head of Enterprise Solutions Architecture Platforms
Stripe · South San Francisco, United States
USD 299,800-449,600 per year
Technical Solutions Engineer
Stripe · United States
USD 134,600-201,800 per year
Strategic Programs Lead, New Markets
Stripe · Singapore, Singapore
SGD 159,200-238,800 per year
Financial Connections TechOps Manager
Stripe · Toronto, Canada
CAD 149,200-223,800 per year
Similar jobs
Forward Deployed Engineer - Physical AI Cloud Platform
Nebius · United States, Austin, United States
USD 179,500-224,300 per year
Member of Technical Staff (Offensive Security Engineer)
Perplexity AI · Serbia, New York City, United States, United States, San Francisco, United States, London, United Kingdom
USD 220,000-405,000 per year
Senior Systems Software Engineer, Developer Productivity and Cloud Automation - GeForce NOW
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year
Resident Solutions Architect
Glean · United States
USD 170,000-240,000 per year
Principal Software Engineer - DGX Cloud
Nvidia · Santa Clara, United States
USD 272,000-431,200 per year
Senior Full-Stack Lead Engineer
Nvidia · Santa Clara, United States
USD 224,000-356,500 per year
Senior Software Engineer
SentinelOne · United States
USD 132,000-182,000 per year
Application Security Engineer
SpaceXAI · Palo Alto, United States
USD 100,000-258,000 per year