Abuse Investigator

Stripe

Northern (KY)

Hybrid

USD 180,000 - 250,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Stripe's Abuse Operations team is seeking an experienced security professional to lead high-stakes incident response and fraud investigations. You will drive deep-dive analyses, identify root causes, and implement scalable, data-driven improvements across detection and prevention systems.

You’ll collaborate across security, fraud, and data science to automate responses and reduce risk for merchants and customers globally.

Qualifications

  • Minimum 10+ years in incident response, security, or trust domains.
  • Strong experience analyzing large data sets and building fraud detection models.
  • Proficiency in Python and SQL; familiarity with other languages is a plus.
  • Ability to communicate results clearly and drive risk-reduction actions.

Responsibilities

  • Investigate, mitigate, and remediate urgent fraud incidents (ATO, card testing).
  • Analyze high-risk accounts to identify fraudulent merchants and vectors.
  • Lead root-cause analyses to improve systems using FT3 framework and data-driven insights.
  • Streamline incident response tooling and processes for speed and accuracy.
  • Collaborate with security, fraud, and data science teams to scale agentic solutions.
  • Communicate with legal and policy teams to assess and mitigate risk.
  • Mentor teammates and champion quality standards within the team.

Skills

Incident response
Fraud detection
Data analysis
Python
SQL
Cross-functional
Mentoring
Problem solving

Education

CS degree or related field

Tools

Databricks
Trino
PySpark
Pandas
Sci-kit Learn

Job description

Who we are
About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world's largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve technical incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.

What you’ll do

You’ll play a critical role in safeguarding our financial ecosystem by investigating high-risk accounts and identifying complex patterns of fraud during incidents. You will lead incident response for product abuse and fraud events, conducting deep-dive analyses to identify root causes. By collaborating cross-functionally, you will drive improvements that enhance our fraud detection and prevention strategies at scale. Your expertise will be essential in automating response processes through agentic approaches, allowing us to safeguard merchants and neutralize threats with speed and precision.

Responsibilities
  • Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped detection and signals enrichment to reduce uncertainty and accelerate response.
  • As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 (Fraud Taxonomy 3.0) to standardize threat intelligence.
  • Lead incident root cause analyses to identify gaps in current systems and strategies, leveraging the FT3 framework, data-driven model to drive enhancements and process improvements for emerging fraud risks.
  • Streamline incident response capabilities, ensuring the tooling and processes are clear, accurate and efficient
  • Work cross-functionally with security, fraud and data science teams to build agentic solutions for responding to abuse incidents at scale
  • Effectively communicate cross-functionally with legal and policy teams to assess and mitigate risks, while demonstrating strong problem-solving under pressure.
  • Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team
Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements
  • 10+ years of experience conducting incident response in security, product abuse or trust domains
  • 10+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to fraud detection
  • B.S. or M.S. Computer Science or related field, or equivalent experience
  • Expert knowledge of Python and SQL, and familiarity with other programming languages
  • Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
  • Ability to communicate results clearly and focus on impact
  • Ability to think creatively and holistically about reducing risk in a complex environment
Preferred qualifications
  • An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
  • Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
  • Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
  • Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
  • Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Abuse Investigator
Abuse Investigator

Free resume • Seattle (WA)

On-site
USD 180,000 - 240,000
Abuse Investigator
Abuse Investigator

Socket.dev • Seattle (WA), New York (NY)

On-site
USD 180,000 - 240,000
Investigator
Investigator

Jackalope Digital LLC • Northern (KY)

Hybrid
USD 110,000 - 170,000
Abuse Research Engineer
Abuse Research Engineer

Socket.dev • United States

On-site
USD 180,000 - 240,000
ARG Engineering Manager
ARG Engineering Manager

EngineersOfAI • Northern (KY)

Hybrid
USD 180,000 - 240,000
S Fraud Patterns Analyst Stripe via Greenhouse US-Remote 4896 fraud operations View role
S Fraud Patterns Analyst Stripe via Greenhouse US-Remote 4896 fraud operations View role

Nubeero Limited • Northern (KY)

Hybrid
USD 90,000 - 135,000
Security Incident Response Engineer
Security Incident Response Engineer

EngineersOfAI • Northern (KY)

Hybrid
USD 120,000 - 150,000
Fraud Strategist
Fraud Strategist

Stripe • United States

On-site
USD 140,000 - 190,000
ARG Engineering Manager
ARG Engineering Manager

Stripe • South San Francisco (CA)

On-site
USD 350,000 - 520,000
ARG Engineering Manager
ARG Engineering Manager

Stripe • San Francisco (CA)

Hybrid
USD 203,000 - 304,000
Equity
401(k) plan
Medical, dental, and vision benefits
+1