Skip to content
StripeStripe

Security Engineer

Designs and incubates technical defenses against complex abuse and fraud across Stripe’s payment, onboarding, identity, and Connect surfaces. Requires 3+ years of security or software engineering experience, strong production programming and SQL skills, and expertise in API safeguards and automated testing.

About the job

Responsibilities

  • Design, prototype, and deploy technical controls across API, protocol, and product boundaries to close high-impact abuse vectors.
  • Translate attacker evidence and threat research into technical abuse requirements and control specifications.
  • Co-design resilient controls across payment, onboarding, identity, and Connect surfaces.
  • Run experiments and A/B tests to measure risk reduction against legitimate-user conversion impact.
  • Build regression test suites and automated attack simulations to prevent recurrence.
  • Define handoff criteria, operational documentation, and target dates for transferring mature controls to product teams.

Requirements

  • 3+ years of experience in security engineering, software engineering, application security, or anti-abuse engineering in a high-scale production environment.
  • Bachelor’s or master’s degree in computer science, cybersecurity, software engineering, or a related technical field, or equivalent practical experience.
  • Expert proficiency in Python, Go, Java, or similar production languages, plus expert SQL skills for analyzing system telemetry.
  • Experience building API safeguards, rate-limiting frameworks, authentication and authorization checks, or input-validation controls.
  • Experience writing unit, integration, and regression tests for critical backend software.
  • Strong cross-functional collaboration and communication skills.

Nice-to-haves

  • Experience designing and executing A/B tests and balancing security safeguards against conversion friction.
  • Expertise in threat modeling, secure system architecture, and application security principles.
  • Familiarity with FT3, MITRE ATT&CK, and adversary kill-chain analysis.
  • Knowledge of financial fraud vectors, threat-actor tactics, techniques, and procedures, and attacker infrastructure, including account takeover, card testing, and credential stuffing.
  • Experience with Databricks, Trino, or PySpark for monitoring and measuring control performance across distributed systems.
  • Experience incubating software features, defining operational handoff criteria, and transitioning ownership to partner engineering teams.

Skills

Python, Go, Java, SQL, Api Security, Rate Limiting, Authentication, Authorization, Input Validation, Automated Testing, Threat Modeling, Mitre Att&Ck, Databricks, Trino, Pyspark

Datadog

Datadog

New York, NY

Security Engineer 2 - Cyber Threat Intelligence
$140k+/yrHybridSecurity Engineering

Security Engineer on the Cyber Threat Intelligence team responsible for developing threat intel tooling, conducting threat hunting, analyzing malware, and operationalizing intelligence into detections and response workflows.

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

hud

hud

San Francisco, CA

Security Engineer
No salary listedOn-siteSecurity Engineering

Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.

Stripe

Stripe

United States

Abuse Research Engineer
No salary listedRemote5+ YOESecurity Engineering

Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.