Security Engineer - Proactive Threat

Monograph

Dublin

On-site

EUR 112,000 - 168,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Equity
Health benefits
Wellness stipend
Bonus

Job summary

Stripe is seeking an experienced Offensive Security Engineer to simulate adversaries, run hands-on pentests, and lead red team engagements across Stripe's products and cloud environments. You will build custom tooling, collaborate with blue teams, and deliver actionable risk-focused reports.

Based in Dublin, this role requires deep expertise in offensive security, cloud techniques, and MITRE ATT&CK; in-office expectations apply for local collaboration and incident response support.

Qualifications

  • 5+ years in offensive security, pentesting, red teaming, or related fields.
  • Strong programming in Python or Go; able to build tools and automation.
  • Deep knowledge of web security (OWASP Top 10, ASVS) and common vuln classes.
  • Hands-on experience with cloud platforms (AWS/Azure/GCP) and misconfigurations.
  • Proficient with offensive tooling and threat frameworks such as MITRE ATT&CK.
  • Excellent written and verbal communication; able to convey risk clearly.
  • Creative, persistent adversary mindset for risk assessment.

Responsibilities

  • Conduct comprehensive penetration tests across web apps, APIs, cloud, mobile, and internal infra.
  • Plan and execute red team engagements simulating real-world threat actors.
  • Perform assumed-breach assessments to test detection and response capabilities.
  • Collaborate with threat intel, IR, and detection engineering to close gaps.
  • Contribute adversary tradecraft insights to detection rules and hunting hypotheses.
  • Support investigations with offensive expertise and root-cause analysis.
  • Design and maintain custom offensive tools and automation frameworks.
  • Build scalable internal platforms to enable repeatable offensive ops.
  • Contribute to security tooling repos and promote best practices.
  • Automate testing tasks, payload generation, and reporting workflows.
  • Produce clear reports communicating findings and risk.
  • Lead projects end-to-end and mentor junior team members.
  • Stay current with threats and share research internally.

Skills

Offensive security
Penetration testing
Red teaming
Python
Go
Cloud platforms
Threat intelligence
MITRE ATT&CK
Burp Suite
Cobalt Strike
Mythic
Sliver
BloodHound
Splunk
OSCP OSWE OSEP OSED

Tools

Burp Suite
Cobalt Strike
Mythic
Sliver
BloodHound
Splunk
Databricks
PySpark
osquery

Job description

Who we are

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

The Proactive Threat team is responsible for identifying vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure — before adversaries do. We operate as a hybrid offensive function: conducting penetration testing, emulating real-world threat actors through red team operations, and partnering closely with our defensive security teams to validate detection capabilities and improve Stripe's overall security posture.

We are builders first. Our team develops custom tooling, automation frameworks, and internal platforms that scale our offensive capabilities and enable repeatable, high-fidelity assessments. We believe the best offensive security engineers are equal parts hacker and engineer.

The team is distributed across the United States, primarily operating in Eastern and Pacific time zones, and collaborates regularly with security, engineering, and product stakeholders across Stripe — including teams in Europe and Asia.

What you'll do

As an Offensive Security Engineer on the Proactive Threat team, you will simulate the tactics, techniques, and procedures (TTPs) of real-world adversaries to uncover security risks across Stripe's products and infrastructure. You'll conduct hands‑on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities. Your work will directly influence how Stripe builds, ships, and secures financial infrastructure used by millions of businesses worldwide.

Beyond assessments, you'll design and build offensive tooling and automation that amplifies the team's impact. You'll leverage threat intelligence to prioritize testing efforts, contribute to incident investigations when needed, and act as a subject‑matter expert for security initiatives across the company.

Responsibilities
  • Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure
  • Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios
  • Perform assumed‑breach and objective‑based assessments to test detection and response capabilities in coordination with defensive teams
  • Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity
  • Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks
  • Support incident investigations by providing offensive expertise, log analysis, and root cause analysis when required
  • Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverage
  • Build internal platforms and workflows that enable scalable, repeatable offensive operations
  • Contribute to internal security tooling repositories and champion engineering best practices within the team
  • Automate repetitive testing tasks, payload generation, and reporting workflows using modern development practices
  • Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non‑technical stakeholders
  • Act as a subject‑matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and Stripe‑wide security initiatives
  • Lead offensive security projects end‑to‑end, mentor junior team members, and foster a culture of continuous learning and knowledge sharing
  • Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and contribute to the broader security community
Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements
  • 5+ years of experience in offensive security, penetration testing, red teaming, or a related field
  • Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits
  • Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.)
  • Hands‑on experience with cloud platforms (AWS, Azure, or GCP), including cloud‑native attack techniques and misconfigurations
  • Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks
  • Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including TTPs for initial access, privilege escalation, lateral movement, and exfiltration
  • Excellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk‑based recommendations
  • Ability to think like an adversary — creative, persistent, and able to holistically assess risk in complex environments
Preferred qualifications
  • Experience conducting offensive security in fintech, financial services, or other highly regulated environments
  • Background in vulnerability research, exploit development, or CVE discovery
  • Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations)
  • Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support
  • Proficiency with AI/LLM‑assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows
  • Interest or experience in agentic automation — using LLMs or autonomous agents to augment reconnaissance, vulnerability discovery, or exploitation workflows
  • Experience testing AI/ML systems or LLM‑based applications for security weaknesses (prompt injection, training data extraction, model manipulation, etc.)
  • Contributions to open‑source security tools, published research, blog posts, or conference presentations
  • Relevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications
In‑office expectations

Office‑assigned Stripes in most of our locations are currently expected to spend at least 50% of the time in a given month in their local office or with users. This expectation may vary depending on role, team and location. For example, Stripes in Stripe Delivery Center roles in Mexico City, Mexico, Bengaluru, India, and Dublin, Ireland work 100% from the office. Also, some teams have greater in‑office attendance requirements, to appropriately support our users and workflows, which the hiring manager will discuss. This approach helps strike a balance between bringing people together for in‑person collaboration and learning from each other, while supporting flexibility when possible.

Pay and benefits

The annual salary range for this role in the primary location is €112,200 - €168,200. This range may change if you are hired in another location. For sales roles, the range provided is the role’s On Target Earnings (“OTE”) range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role. This salary range may be inclusive of several career levels at Stripe and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and specific location. Applicants interested in this role and who are not located in the primary location may request the annual salary range for their location during the interview process.

Specific benefits and details about what compensation is included in the salary range listed above will vary depending on the applicant’s location and can be discussed in more detail during the interview process. Benefits/additional compensation for this role may include: equity, company bonus or sales commissions/bonuses; retirement plans; health benefits; and wellness stipends.

We look forward to hearing from you.

At Stripe, we're looking for people with passion, grit, and integrity. You're encouraged to apply even if your experience doesn't precisely match the job description. Your skills and passion will stand out—and set you apart—especially if your career has taken some extraordinary twists and turns. At Stripe, we welcome diverse perspectives and people who think rigorously and aren't afraid to challenge assumptions. Join us.

Company

Stripe

Team

Security

Office location

Dublin HQ

Employment type

Full time

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Proactive Threat
Security Engineer - Proactive Threat

Stripe • Dublin

On-site
EUR 112,000 - 168,000
Equity
Health benefits
Wellness stipends
+1
Security Engineer - Proactive Threat
Security Engineer - Proactive Threat

Stripe • Ireland

On-site
EUR 120,000 - 180,000
Incident Response Manager - Security
Incident Response Manager - Security

Stripe • Dublin

Hybrid
EUR 89,000 - 134,000
Equity
Bonuses / commissions
Retirement plans
+2
S Security Engineer - Proactive Threat Stripe via Greenhouse Ireland 8611 security analytics View role
S Security Engineer - Proactive Threat Stripe via Greenhouse Ireland 8611 security analytics View role

Nubeero Limited • Ireland

Hybrid
EUR 90,000 - 150,000
Staff Security Engineer, Abuse Control
Staff Security Engineer, Abuse Control

Stripe • Dublin

On-site
EUR 132,000 - 198,000
Equity
Bonus
Retirement plans
+2
Backend Engineer/API, Payments and Risk
Backend Engineer/API, Payments and Risk

Monograph • Dublin

On-site
EUR 83,000 - 125,000
Equity
Health benefits
Wellness stipends
+1
S Forward Deployed Security Engineer Stripe via Greenhouse Dublin 8611 security analytics View role
S Forward Deployed Security Engineer Stripe via Greenhouse Dublin 8611 security analytics View role

Nubeero Limited • Dublin

On-site
EUR 120,000 - 180,000
Forward Deployed Engineer, Professional Services
Forward Deployed Engineer, Professional Services

Monograph • Dublin

Hybrid
EUR 84,000 - 126,000
Equity
Bonus/Commissions
Retirement plans
+2
Staff Backend Engineer - CI Services
Staff Backend Engineer - CI Services

Stripe • Dublin

On-site
EUR 132,000 - 198,000
Equity
Bonus potential
Retirement plans
+2
Enterprise Support Specialist
Enterprise Support Specialist

Stripe • Dublin

On-site
EUR 64,000 - 96,000