Staff Security Engineer, Abuse Control

at Stripe
EUR 132,000-198,000 per year
SENIOR
✅ On-site

Tech Stack

AI @ 4 API @ 4 Automated Testing @ 4 Communication @ 7 Databricks @ 4 Fraud @ 4 Go @ 7 Java @ 7 Payments Python @ 7 SQL @ 6 Security @ 8 Software Development @ 7 Trino @ 4

Details

Who We Are

Stripe is a financial infrastructure platform used by businesses worldwide to accept payments, grow revenue, and accelerate new business opportunities.

Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. The team uses attacker telemetry to prototype, test, and deploy software safeguards against emerging abuse vectors. ACE partners with Fraud, Risk, Abuse Research, and Product Engineering to evaluate risk mitigation while minimizing impact on legitimate users and conversion. The team also builds automated regression suites and transfers mature controls to long-term product owners.

As an Abuse Control Engineer, you will design, prototype, and incubate technical defenses that protect Stripe’s financial ecosystem against complex, cross-cutting abuse vectors. You will translate threat intelligence and Stripe’s Fraud Taxonomy 3.0 framework into technical control requirements, run experiments to evaluate risk reduction, manage controls through an incubation lifecycle, and partner with product engineering teams to deploy long-term defenses.

Responsibilities

  • Design, prototype, and deploy technical controls across API, protocol, and product boundaries to address high-impact abuse vectors.
  • Translate attacker evidence and threat research from Abuse Research, Fraud, and Security teams into precise technical abuse requirements and control specifications.
  • Collaborate across Stripe to design resilient, secure controls for payments, onboarding, identity, and Connect surfaces.
  • Run experiments and A/B tests to measure risk reduction against the impact on legitimate user conversion.
  • Build comprehensive regression test suites and automated attack simulations with Abuse Research.
  • Define handoff criteria, operational documentation, timelines, and target dates for transferring successful controls to product teams.

Requirements

  • 10+ years of experience in security engineering, software engineering, application security, or anti-abuse engineering in a high-scale production environment.
  • A bachelor’s or master’s degree in computer science, cybersecurity, software engineering, or a related technical field, or equivalent practical experience.
  • Strong software development experience with Python, Go, Java, or a similar production programming language.
  • Advanced SQL skills for analyzing system telemetry.
  • Experience using frontier AI models for software development, learning, and analysis.
  • Hands-on experience building API-level safeguards, rate-limiting frameworks, authentication or authorization checks, or input-validation controls.
  • Experience with automated testing frameworks, including unit, integration, and regression testing for critical backend software.
  • Strong cross-functional collaboration and communication skills.

Preferred Qualifications

  • Experience designing and executing A/B tests, evaluating control efficacy, and balancing security safeguards against user-conversion friction.
  • Expertise in threat modeling, secure systems architecture, and modern application-security design principles.
  • Familiarity with threat frameworks such as FT3 or MITRE ATT&CK, including adversary kill-chain analysis.
  • Knowledge of financial fraud vectors and threat-actor tactics, techniques, and procedures, including account takeover, card testing, and credential stuffing.
  • Experience with large-scale data-processing platforms such as Databricks, Trino, or PySpark.
  • Experience incubating software features, establishing operational handoff criteria, and transitioning ownership to partner engineering teams.

More jobs at Stripe

Similar jobs