Abuse Research Engineer

Stripe

San Francisco (CA)

Hybrid

USD 144,000 - 217,000

Full time

16 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Equity
401(k) plan
Medical, dental & vision benefits
Wellness stipends

Job summary

Stripe is seeking an Abuse Research Engineer to proactively hunt for advanced threats, dissect fraud vectors, and extract adversary intelligence. You will operate across internal telemetry and external data to uncover fraudulent tools and techniques (TTPs) before they impact Stripe’s platform.

You’ll collaborate with Fraud Ops, Strategy, Risk, Onboarding, and Security to integrate threat intelligence, build agentic simulation workflows, and systematically eliminate vulnerabilities.

Qualifications

  • 5+ years of threat intelligence, threat hunting, or incident response in cyber security or trust domains.
  • 5+ years of analyzing large, complex datasets to identify anomalies and fraud patterns.
  • Bachelor's or Master’s in CS, Cybersecurity, or related field, or equivalent experience.
  • Proficiency in Python and SQL; ability to automate workflows and query big data pipelines.
  • Experience with log analysis, forensics, and cyber investigation methodologies.

Responsibilities

  • Proactive threat hunting & kill chain analysis across Stripe systems and external data.
  • Apply FT3 taxonomy across datasets and incidents to standardize threat intelligence.
  • Integrate threat feeds into engineering workflows with Fraud Ops, Risk, Onboarding, and Security.
  • Translate research findings into actionable advisories and controls for multiple stakeholders.
  • Build agentic testing frameworks to simulate adversary TTPs and validate controls.

Skills

Python
SQL
Threat hunting
Data analytics
Log analysis
Communication

Education

BS in Computer Science or Cybersecurity
MS in Computer Science or Cybersecurity

Tools

Databricks
Trino
PySpark
Pandas
Scikit-Learn

Job description

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

Who we are

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

About The Team

Abuse Research Group (ARG) handles proactive threat hunting and adversary behavior analysis across Stripe products. Rather than reacting to alerts, the team maps end‑to‑end fraud and abuse paths, validates novel attack vectors, and identifies product conditions that enable fraud. Using agentic automated testing and simulation tools, ARG translates research into actionable threat advisories, strategic control recommendations, and regression scenarios to systematically eliminate vulnerabilities.

What you’ll do

As an Abuse Research Engineer in the Abuse Research Group, you will play a critical role in safeguarding Stripe’s financial ecosystem by proactively hunting for advanced threats, dissecting complex fraud vectors, and extracting actionable adversary intelligence. Rather than relying solely on reactive alerts, you will develop and execute hypothesis‑driven threat hunting operations across internal telemetry and external sources to uncover fraudulent tools, tactics, and techniques (TTPs) before they impact Stripe’s platform. Central to this work is FT3 (Fraud Taxonomy 3.0), Stripe’s multi‑layered taxonomy that decomposes monolithic fraud into structured kill chains. Collaborating cross‑functionally with Fraud Ops, Strategy, Risk, Onboarding, and Security, you will integrate threat intelligence, build agentic simulation workflows, and systematically eliminate product vulnerabilities.

Responsibilities
  • Proactive Threat Hunting & Kill Chain Analysis: Formulate hypotheses and conduct iterative threat hunting operations across Stripe systems and external data.
  • FT3 Taxonomy: Apply and enrich the FT3 framework across empirical datasets and incidents, standardizing threat intelligence across kill chain phases and targeted API endpoints.
  • Threat Intelligence & Signal Expansion: Partner with teams like Fraud Intelligence to integrate, curate, and automate threat feeds into engineering workflows.
  • Cross-Functional Advisories & Strategic Controls: Translate raw research and retrospective findings into actionable threat advisories and control recommendations (policy, technical systems, support workflows, and detection mechanisms) for stakeholders across Fraud, Risk, Onboarding, and Security.
  • Agentic Testing & Adversary Simulation: Utilize agentic automated testing frameworks to simulate adversary TTPs, validate whether deployed controls interrupt empirical kill chains, and generate regression scenarios to exercise controls.
Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum Requirements
  • 5+ years of experience conducting threat intelligence, threat hunting, or technical incident response within cyber security, product abuse, or trust domains.
  • 5+ years of experience analyzing large, complex datasets using data analytics tools to identify anomalies, map behavioral trends, and solve complex fraud problems.
  • B.S. or M.S. in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
  • Expert proficiency in Python and SQL, with demonstrated experience using code and scripting to automate workflows, build investigative tools, or query big data pipelines.
  • Hands‑on experience in log analysis (e.g., application logs, API route telemetry, network security events), digital forensics, and cyber investigation methodologies.
  • Strong communication skills with a proven ability to translate complex technical research into clear, actionable recommendations and advisories for cross‑functional partners.
Preferred Qualifications
  • Deep technical understanding of threat actor motivations, infrastructure, and TTPs specific to financial fraud (e.g., ATO, Card Testing, Credential Stuffing).
  • Familiarity with standardized taxonomies such as FT3 or MITRE ATT&CK.
  • Proficiency with engineering, data processing, and analysis platforms such as Databricks, Trino, PySpark, Pandas, or Scikit-Learn.
  • Proven background utilizing Threat Intelligence Platforms (TIPs), tactical threat feeds, OSINT, and breach intelligence.
  • Demonstrated capability building or leveraging agentic LLM tools, automated testing systems, or control validation frameworks to model adversary behavior at scale.
Hybrid work at Stripe

This role is available either in an office or a remote location (35+ miles or 56+ km from a Stripe office).

In-office expectations

Office‑assigned Stripes spend at least 50% of the time in a given month in their local office or with users. This hits a balance between bringing people together for in‑person collaboration and learning from each other, while supporting flexibility about how to do this in a way that makes sense for individuals and their teams.

Working remotely at Stripe

A remote location is defined as being 35 miles (56 kilometers) or more from one of our offices. While you would be welcome to come into the office for team/business meetings, on‑sites, meet‑ups, and events, our expectation is you would regularly work from home rather than a Stripe office. Stripe does not cover the cost of relocating to a remote location. We encourage you to apply for roles that match the location where you currently live or plan to live.

Pay and benefits

The annual US base salary range for this role is $144,300 - $216,500. For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role. This salary range may be inclusive of several career levels at Stripe and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location. Applicants interested in this role and who are not located in the US may request the annual salary range for their location during the interview process.

Additional benefits for this role may include: equity, company bonus or sales commissions/bonuses; 401(k) plan; medical, dental, and vision benefits; and wellness stipends.

Culture and values

At Stripe, we're looking for people with passion, grit, and integrity. Your skills and passion will stand out—and set you apart—especially if your career has taken some extraordinary twists and turns.

At Stripe, we welcome diverse perspectives and people who think rigorously and aren't afraid to challenge assumptions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Abuse Investigator
Abuse Investigator

Stripe • Atlanta (GA)

Hybrid
USD 188,000 - 283,000
Equity
401(k) plan
Medical/Dental/Vision
Abuse Investigator
Abuse Investigator

Stripe • San Francisco (CA)

Hybrid
USD 188,000 - 283,000
Equity
Company bonus
401(k) plan
+1
Security Incident Response Manager, Abuse Operations
Security Incident Response Manager, Abuse Operations

Stripe • San Francisco (CA)

Hybrid
USD 188,000 - 283,000
Equity
Bonus or sales commissions/bonuses
401(k)
+2
Abuse Research Engineer
Abuse Research Engineer

Stripe • Atlanta (GA)

On-site
USD 140,000 - 210,000
Security Incident Response Manager, Abuse Operations
Security Incident Response Manager, Abuse Operations

Stripe • Atlanta (GA)

Hybrid
USD 188,000 - 283,000
Equity
Company bonus
401(k) plan
+2
Abuse Research Engineer
Abuse Research Engineer

Socket.dev • United States

On-site
USD 180,000 - 240,000
Abuse Investigator
Abuse Investigator

Visa Hunt • California (MO), Seattle (WA), San Francisco (CA)

On-site
USD 180,000 - 240,000
Abuse Investigator
Abuse Investigator

Socket.dev • Seattle (WA), New York (NY)

On-site
USD 180,000 - 240,000
Abuse Investigator
Abuse Investigator

Stripe • Northern (KY)

Hybrid
USD 180,000 - 250,000
ARG Engineering Manager
ARG Engineering Manager

Stripe • South San Francisco (CA)

On-site
USD 350,000 - 520,000