Engineering Manager, Abuse Control Engineering

Stripe

Seattle, San Francisco, New York (WA, CA, NY)

Hybrid

USD 190,000 - 240,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Stripe is seeking an Engineering Manager for Abuse Control Engineering to lead a rapid-response defense team. You will own technical direction, people leadership, hiring, coaching, and cross-functional execution, turning attacker evidence into prioritized safeguards while balancing risk and user experience.

You will drive incubation, handoffs, and collaboration with security, product, and engineering teams to harden defenses across Stripe’s surfaces.

Qualifications

  • Experience managing an engineering team and delivering technical outcomes.
  • Foundations in software security engineering or anti-abuse engineering.
  • Experience hiring, coaching, and developing engineers.
  • Experience leading cross-functional technical work.
  • Ability to evaluate designs and guide decisions on reliability, security, risk, and product tradeoffs.
  • Clear communication of technical strategy, priorities, risks to teams.
  • Ability to create clarity in ambiguous or urgent situations.

Responsibilities

  • Define and communicate the team’s technical strategy and priorities for identifying cross-product abuse gaps, incubating controls, and preventing recurrence of threats.
  • Hire, coach, and support engineers; set expectations and provide feedback; create growth opportunities.
  • Guide evidence-based decisions using attacker evidence, product context, and measurable outcomes.
  • Drive secure control design with security and product engineering teams.
  • Oversee experiments to assess risk reduction and impact on legitimate user conversion.
  • Establish incubation and handoff practices with clear ownership, criteria, and timelines.
  • Complete ownership handoffs to product teams that will own the controls long-term.

Skills

Engineering team leadership
Hiring and coaching
Cross-functional leadership
Technical decision making
Strategic communication
Clarity under pressure

Job description

Who we are
About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

About the team

Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE bridges the gap using real attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale. We partner closely with Fraud, Risk and Product Engineering to run rigorous experiments, balancing aggressive risk mitigation against legitimate user conversion. Operating as both a strike team and an incubator, ACE builds automated regression suites in partnership with Abuse Research to permanently block threat recurrence and seamlessly transfers mature controls to long‑term product owners across Stripe.

What you’ll do

As the Engineering Manager for Abuse Control Engineering, you will lead a team responsible for closing urgent, cross-product defense gaps and incubating controls until they are ready for long‑term ownership. You will be accountable for the team’s technical direction, people leadership, hiring, coaching, and cross‑functional execution.

You will help the team turn attacker evidence into clear technical priorities, guide the design and evaluation of safeguards, and ensure that decisions account for both risk reduction and the experience of legitimate users. You will also establish disciplined incubation and handoff practices so that successful controls move to the appropriate product teams with clear ownership, documentation, criteria, and timelines.

Responsibilities
  • Set technical direction: Define and communicate the team’s technical strategy and priorities for identifying cross-product abuse gaps, incubating controls, and preventing the recurrence of mitigated threats.
  • Lead and develop the team: Hire, manage, coach, and support engineers; provide clear expectations and feedback; and create opportunities for engineers to expand their technical judgment, leadership, and impact.
  • Guide evidence‑based decisions: Ensure that attacker evidence, product context, and measurable outcomes inform technical abuse requirements, control designs, and investment decisions.
  • Drive secure control design: Partner with Application Security and product engineering teams to develop safeguards that are resilient, appropriately scoped, and compatible with the systems in which they operate.
  • Oversee experimentation: Guide experiments that assess risk reduction and the effect of controls on legitimate user conversion, helping the team make informed tradeoffs and refine its approach.
  • Build durable defenses: Ensure the team develops regression tests and other mechanisms that can detect whether previously mitigated abuse patterns recur.
  • Manage control incubation: Establish clear success measures, operational expectations, documentation, destination owners, handoff criteria, and target dates for incubated controls.
  • Complete ownership handoffs: Hold the team and its partners accountable for transferring successful controls to the product teams that permanently own the relevant surfaces, except where a control is intentionally maintained as a durable capability serving multiple products.
  • Lead cross‑functional execution: Align security, product, engineering, and other partners around priorities, tradeoffs, responsibilities, and delivery plans, including in situations that require urgent coordination.
Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements
  • Experience managing an engineering team, including setting direction, prioritizing work, and being accountable for delivery and technical outcomes.
  • A relevant technical foundation in software engineering, security engineering, application security, anti‑abuse engineering, or a closely related field, developed through professional experience, education, or an equivalent path.
  • Experience hiring, coaching, and developing engineers with different levels of experience, including providing actionable feedback and supporting career growth.
  • Experience leading cross‑functional technical work involving teams with different goals, areas of expertise, or ownership boundaries.
  • Ability to evaluate technical designs, ask effective questions, and guide engineering decisions involving reliability, security, risk, and product tradeoffs.
  • Experience communicating technical strategy, priorities, risks, and decisions clearly to engineering teams and cross‑functional stakeholders.
  • Ability to create clarity in ambiguous or urgent situations and translate broad risk problems into actionable plans, ownership, and measurable outcomes.
Preferred qualifications
  • Experience guiding experimentation or A/B testing, including evaluating control effectiveness and balancing risk reduction against effects on legitimate user conversion.
  • Knowledge of threat modeling, secure systems design, or modern application security practices.
  • Familiarity with API safeguards and abuse controls such as rate limits, authorization checks, input validation, step‑up challenges, or related protective mechanisms.
  • Knowledge of financial‑fraud patterns, attacker behavior, attack methods, or the infrastructure used to conduct abuse.
  • Experience using or overseeing work involving large‑scale data platforms to analyze system activity, identify patterns, or measure control performance.
  • Experience incubating technical capabilities and transferring them to long‑term owners through explicit success criteria, documentation, operational readiness, and target dates.
  • Experience leading a distributed team or coordinating execution across teams in multiple locations or time zones.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineering Manager, Abuse Control Engineering
Engineering Manager, Abuse Control Engineering

Socket.dev • Seattle (WA)

On-site
USD 180,000 - 260,000
Engineering Manager, Abuse Control Engineering
Engineering Manager, Abuse Control Engineering

Triwill Group • Northern (KY), New York (NY)

Hybrid
USD 180,000 - 250,000
Engineering Manager, Abuse Control Engineering
Engineering Manager, Abuse Control Engineering

Stripe • Chicago (IL)

Hybrid
USD 236,000 - 354,000
Equity
Company bonus/bonuses
401(k) plan
+2
Security Engineer
Security Engineer

Stripe • United States

On-site
USD 173,000 - 260,000
Equity
Medical, dental, and vision benefits
Wellness stipends
Engineering Manager, Abuse Control & Risk Defense
Engineering Manager, Abuse Control & Risk Defense

Triwill Group • Northern (KY), New York (NY)

Hybrid
USD 180,000 - 250,000
Security Incident Response Manager, Abuse Operations
Security Incident Response Manager, Abuse Operations

Socket.dev • Seattle (WA)

On-site
USD 180,000 - 230,000
Abuse Investigator
Abuse Investigator

Stripe • Northern (KY)

Hybrid
USD 180,000 - 250,000
ARG Engineering Manager
ARG Engineering Manager

EngineersOfAI • Northern (KY)

Hybrid
USD 180,000 - 240,000
Lead, Abuse Control Engineering & Secure Defenses
Lead, Abuse Control Engineering & Secure Defenses

Stripe • Seattle (WA), San Francisco (CA), New York (NY)

Hybrid
USD 190,000 - 240,000
Abuse Investigator
Abuse Investigator

Free resume • Seattle (WA)

On-site
USD 180,000 - 240,000