Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI @ 4
API @ 4
Automated Testing @ 4
Communication @ 7
Databricks @ 4
Fraud @ 4
Go @ 7
Java @ 7
Payments
Python @ 7
SQL @ 6
Security @ 8
Software Development @ 7
Trino @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Who We Are
Stripe is a financial infrastructure platform used by businesses worldwide to accept payments, grow revenue, and accelerate new business opportunities.
Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. The team uses attacker telemetry to prototype, test, and deploy software safeguards against emerging abuse vectors. ACE partners with Fraud, Risk, Abuse Research, and Product Engineering to evaluate risk mitigation while minimizing impact on legitimate users and conversion. The team also builds automated regression suites and transfers mature controls to long-term product owners.
As an Abuse Control Engineer, you will design, prototype, and incubate technical defenses that protect Stripe’s financial ecosystem against complex, cross-cutting abuse vectors. You will translate threat intelligence and Stripe’s Fraud Taxonomy 3.0 framework into technical control requirements, run experiments to evaluate risk reduction, manage controls through an incubation lifecycle, and partner with product engineering teams to deploy long-term defenses.
Responsibilities
- Design, prototype, and deploy technical controls across API, protocol, and product boundaries to address high-impact abuse vectors.
- Translate attacker evidence and threat research from Abuse Research, Fraud, and Security teams into precise technical abuse requirements and control specifications.
- Collaborate across Stripe to design resilient, secure controls for payments, onboarding, identity, and Connect surfaces.
- Run experiments and A/B tests to measure risk reduction against the impact on legitimate user conversion.
- Build comprehensive regression test suites and automated attack simulations with Abuse Research.
- Define handoff criteria, operational documentation, timelines, and target dates for transferring successful controls to product teams.
Requirements
- 10+ years of experience in security engineering, software engineering, application security, or anti-abuse engineering in a high-scale production environment.
- A bachelor’s or master’s degree in computer science, cybersecurity, software engineering, or a related technical field, or equivalent practical experience.
- Strong software development experience with Python, Go, Java, or a similar production programming language.
- Advanced SQL skills for analyzing system telemetry.
- Experience using frontier AI models for software development, learning, and analysis.
- Hands-on experience building API-level safeguards, rate-limiting frameworks, authentication or authorization checks, or input-validation controls.
- Experience with automated testing frameworks, including unit, integration, and regression testing for critical backend software.
- Strong cross-functional collaboration and communication skills.
Preferred Qualifications
- Experience designing and executing A/B tests, evaluating control efficacy, and balancing security safeguards against user-conversion friction.
- Expertise in threat modeling, secure systems architecture, and modern application-security design principles.
- Familiarity with threat frameworks such as FT3 or MITRE ATT&CK, including adversary kill-chain analysis.
- Knowledge of financial fraud vectors and threat-actor tactics, techniques, and procedures, including account takeover, card testing, and credential stuffing.
- Experience with large-scale data-processing platforms such as Databricks, Trino, or PySpark.
- Experience incubating software features, establishing operational handoff criteria, and transitioning ownership to partner engineering teams.