Abuse Research Engineer

Stripe

United States

On-site

USD 150,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Stripe is seeking an Abuse Research Engineer to safeguard its financial ecosystem by proactively hunting threats, dissecting fraud vectors, and extracting adversary intelligence. You will run hypothesis-driven threat hunts across internal telemetry and external data, applying FT3 taxonomy to decompose fraud into structured kill chains.

Collaborating with Fraud Ops, Strategy, Risk, Onboarding, and Security, you will integrate threat intelligence, build agentic simulation workflows, and eliminate

Qualifications

  • 5+ years of threat intelligence, hunting, or incident response in cyber security, product abuse, or trust domains.
  • 5+ years of experience analyzing large datasets to identify anomalies and fraud trends.
  • BS or MS in Computer Science, Cybersecurity, or related field, or equivalent practical experience.
  • Expert proficiency in Python and SQL.

Responsibilities

  • Proactive Threat Hunting & Kill Chain Analysis across Stripe systems and external data.
  • FT3 Taxonomy: apply and enrich the FT3 framework across datasets and incidents.
  • Threat Intelligence & Signal Expansion: integrate threat feeds into engineering workflows.
  • Cross-Functional Advisories & Strategic Controls: translate findings into actionable advisories and controls for stakeholders across Fraud, Risk, Onboarding, and Security.
  • Agentic Testing & Adversary Simulation: simulate adversary TTPs and validate deployed controls.

Skills

Python
SQL

Education

BS or MS in CS/Cybersecurity/related field

Job description

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

About The Team

Abuse Research Group (ARG) handles proactive threat hunting and adversary behavior analysis across Stripe products. Rather than reacting to alerts, the team maps end-to-end fraud and abuse paths, validates novel attack vectors, and identifies product conditions that enable fraud. Using agentic automated testing and simulation tools, ARG translates research into actionable threat advisories, strategic control recommendations, and regression scenarios to systematically eliminate vulnerabilities.

What you’ll do

As an Abuse Research Engineer in the Abuse Research Group, you will play a critical role in safeguarding Stripe’s financial ecosystem by proactively hunting for advanced threats, dissecting complex fraud vectors, and extracting actionable adversary intelligence. Rather than relying solely on reactive alerts, you will develop and execute hypothesis-driven threat hunting operations across internal telemetry and external sources to uncover fraudulent tools, tactics, and techniques (TTPs) before they impact Stripe’s platform. Central to this work is FT3 (Fraud Taxonomy 3.0), Stripe’s multi-layered taxonomy that decomposes monolithic fraud into structured kill chains. Collaborating cross-functionally with Fraud Ops, Strategy, Risk, Onboarding, and Security, you will integrate threat intelligence, build agentic simulation workflows, and systematically eliminate product vulnerabilities.

Responsibilities
  • Proactive Threat Hunting & Kill Chain Analysis: Formulate hypotheses and conduct iterative threat hunting operations across Stripe systems and external data.
  • FT3 Taxonomy: Apply and enrich the FT3 framework across empirical datasets and incidents, standardizing threat intelligence across kill chain phases and targeted API endpoints.
  • Threat Intelligence & Signal Expansion: Partner with teams like Fraud Intelligence to integrate, curate, and automate threat feeds into engineering workflows.
  • Cross-Functional Advisories & Strategic Controls: Translate raw research and retrospective findings into actionable threat advisories and control recommendations (policy, technical systems, support workflows, and detection mechanisms) for stakeholders across Fraud, Risk, Onboarding, and Security.
  • Agentic Testing & Adversary Simulation: Utilize agentic automated testing frameworks to simulate adversary TTPs, validate whether deployed controls interrupt empirical kill chains, and generate regression scenarios to exercise controls.
Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum Requirements
  • 5+ years of experience conducting threat intelligence, threat hunting, or technical incident response within cyber security, product abuse, or trust domains.
  • 5+ years of experience analyzing large, complex datasets using data analytics tools to identify anomalies, map behavioral trends, and solve complex fraud problems.
  • B.S. or M.S. in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
  • Expert proficiency in Python and SQL, with demonstrated experience
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Abuse Research Engineer
Abuse Research Engineer

Stripe • Atlanta (GA)

On-site
USD 140,000 - 210,000
Abuse Research Engineer
Abuse Research Engineer

Socket.dev • United States

On-site
USD 180,000 - 240,000
Abuse Investigator
Abuse Investigator

Socket.dev • Seattle (WA), New York (NY)

On-site
USD 180,000 - 240,000
Abuse Investigator
Abuse Investigator

Visa Hunt • San Francisco (CA)

On-site
USD 180,000 - 240,000
ARG Engineering Manager
ARG Engineering Manager

EngineersOfAI • Northern (KY)

Hybrid
USD 180,000 - 240,000
ARG Engineering Manager
ARG Engineering Manager

Stripe • South San Francisco (CA)

On-site
USD 350,000 - 520,000
Abuse Investigator
Abuse Investigator

Free resume • Seattle (WA)

On-site
USD 180,000 - 240,000
Abuse Investigator
Abuse Investigator

Stripe • Northern (KY)

Hybrid
USD 180,000 - 250,000
Security Incident Response Manager, Abuse Operations
Security Incident Response Manager, Abuse Operations

Triwill Group • Seattle (WA), Northern (KY)

Hybrid
USD 150,000 - 190,000
Security Incident Response Manager, Abuse Operations
Security Incident Response Manager, Abuse Operations

Stripe • Seattle (WA)

Hybrid
USD 188,000 - 283,000
Equity
401(k)
Medical, dental, and vision benefits
+2