Skip to content
StripeStripe

Abuse Investigator

Investigates high-risk accounts and leads incident response for fraud and product-abuse events, using behavioral analysis and threat intelligence to identify root causes and improve detection. Requires 3+ years of incident response and fraud-data analysis experience, plus strong Python and SQL skills.

About the job

Responsibilities

  • Investigate, mitigate, and remediate urgent fraud incidents, including account takeovers and card testing, using detection and signal-enrichment methods.
  • Analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors; classify threats using the Fraud Taxonomy 3.0 framework.
  • Lead incident root-cause analyses to identify system and strategy gaps and drive data-informed improvements for emerging fraud risks.
  • Improve incident-response tooling and processes for clarity, accuracy, and efficiency.
  • Collaborate with security, fraud, and data science teams to build agentic solutions for responding to abuse incidents at scale.
  • Work with legal and policy teams to assess and mitigate risks.
  • Lead projects, mentor teammates, and develop quality standards.

Requirements

  • 3+ years of experience conducting incident response in security, product abuse, or trust domains.
  • 3+ years of experience analyzing large datasets to solve problems and/or building behavioral models for fraud detection.
  • Bachelor's or master's degree in Computer Science or a related field, or equivalent experience.
  • Expert knowledge of Python and SQL; familiarity with other programming languages.
  • Experience with log analysis, network security, digital forensics, and incident-response investigations.
  • Strong communication, problem-solving, and risk-reduction skills.

Preferred Qualifications

  • Adversarial mindset and understanding of threat-actor goals, behaviors, and tactics, techniques, and procedures.
  • Experience with engineering, data-processing, and analysis tools such as Databricks and Trino.
  • Familiarity with big-data and data-science frameworks such as PySpark, Pandas, and scikit-learn.
  • Experience with tactical threat intelligence and threat hunting for sophisticated enterprise threat actors.
  • Ability to use data and a user-centric approach to address complex product-integrity challenges.

Skills

Python, SQL, Log Analysis, Network Security, Digital Forensics, Incident Response, Fraud Detection, Databricks, Trino, Pyspark, pandas, scikit-learn, Threat Intelligence, Threat Hunting, Data Analysis

Stripe

Stripe

Seattle, WA
Abuse Investigator
No salary listedOn-site3+ YOESecurity Engineering

Investigates and leads response to high-risk fraud and product-abuse incidents, analyzes threat patterns, and drives root-cause and prevention improvements. Requires 3+ years of incident response and fraud-oriented data analysis, plus Python, SQL, and security investigation expertise.

Supabase

Supabase

Remote

Platform Security Engineer
No salary listedRemote5+ YOESecurity Engineering

Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.

Kodex

Kodex

Sydney, Australia

Threat Intelligence Specialist – EMEA
No salary listedRemote3+ YOESecurity Engineering

The Threat Intelligence Specialist investigates identity fraud and threat actors, conducts pivot-based OSINT, and collaborates with law enforcement agencies across EMEA. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.

Twilio

Twilio

United Kingdom
Security Engineer, Incident Response
No salary listedRemote3+ YOESecurity Engineering

Leads technical response to security events across cloud infrastructure, services, and applications, covering triage, containment, remediation, automation, and post-incident improvements. Requires 3+ years of cloud security incident response experience and expertise with SIEM, SOAR, and major cloud platforms.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.