Security Incident Response Engineer

at Stripe
USD 144,300-216,500 per year
MIDDLE SENIOR
✅ Remote ✅ On-site

Tech Stack

Data Engineering @ 2 Data Science @ 2 Databricks @ 3 Observability @ 2 Pandas @ 2 Payments Python @ 2 SQL @ 2 Security @ 3 Splunk @ 2 Trino @ 3 scikit-learn @ 2

Details

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Stripe’s mission is to increase the GDP of the internet.

About the Team

The Security Incident Response team analyzes, investigates, and responds to threats before they impact Stripe’s business or users. The team handles external attacks and insider threats, responds with speed and precision, remediates incidents, and supports the incident postmortem process. The team is distributed across multiple AMER time zones and regularly coordinates with stakeholders in EMEA and APAC.

Responsibilities

  • Analyze and investigate a broad range of threats or activities occurring on client devices.
  • Develop requirements for detection models and enhancements to existing systems.
  • Collect, transform, and ingest raw data from disparate sources into threat detection pipelines.
  • Streamline incident response capabilities and ensure that tooling and processes are clear.
  • Work cross-functionally with security engineering and data science teams to build solutions for analyzing security event data at scale and protecting Stripe networks, systems, and data from threats.
  • Provide actionable insights to identify, prevent, detect, and respond to anomalous or potentially malicious user and entity activity.
  • Act as the subject-matter expert and primary contact for stakeholder teams involved in Security Analytics and Detection programs and Stripe-wide security initiatives.
  • Collaborate with teammates, lead projects, mentor others, and develop and champion quality standards within the team.
  • Leverage security engineering experience to improve incident response capabilities, with an emphasis on user and entity behavior analytics and endpoint hardening.
  • Use threat intelligence and collected telemetry to build Stripe-specific signal-enrichment logic and scalable incident response solutions.
  • Apply analytic capabilities during security incidents to reduce uncertainty, uncover root causes, and inform prevention and detection mechanisms.

Requirements

Minimum Requirements

  • 3+ years of experience analyzing large data sets to solve problems and/or building models with a behavioral approach to security.
  • B.S. or M.S. in Computer Science or a related field, or equivalent experience.
  • Expert knowledge of Python and SQL, and familiarity with other programming languages.
  • Experience with log analysis, including first- or third-party applications, system and data access, and event logs; network security; digital forensics; and incident response investigations.
  • Proficiency developing and using novel analytical methods to build, automate, and improve detection and response systems.
  • Ability to communicate results clearly and focus on impact.
  • Ability to think creatively and holistically about reducing risk in a complex environment.

Preferred Qualifications

  • An adversarial mindset and understanding of threat actor goals, behaviors, and tactics, techniques, and procedures (TTPs).
  • Experience with software engineering, data processing, and analysis tools such as Databricks, Jupyter, and Trino.
  • Familiarity with open-source frameworks for big data processing and/or data science, such as PySpark, Pandas, and scikit-learn.
  • Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment.
  • Familiarity with network observability, security software, or data engineering solutions such as osquery and Splunk/LogScale.
  • Experience in one or more of the following areas: user and entity behavior analytics (UEBA), security information and event management (SIEM), security orchestration, automation and response (SOAR), or data loss prevention (DLP).

More jobs at Stripe

Similar jobs