# Security Engineer

**Company:** [Stripe](https://hotfix.jobs/companies/stripe)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 3+ years
**Skills:** Python, Go, Java, SQL, Api Security, Rate Limiting, Authentication, Authorization, Input Validation, Automated Testing, Threat Modeling, Mitre Att&Ck, Databricks, Trino, Pyspark
**Posted:** 2026-09-10

> Designs and incubates technical defenses against complex abuse and fraud across Stripe’s payment, onboarding, identity, and Connect surfaces. Requires 3+ years of security or software engineering experience, strong production programming and SQL skills, and expertise in API safeguards and automated testing.

## Job Description

## Responsibilities
- Design, prototype, and deploy technical controls across API, protocol, and product boundaries to close high-impact abuse vectors.
- Translate attacker evidence and threat research into technical abuse requirements and control specifications.
- Co-design resilient controls across payment, onboarding, identity, and Connect surfaces.
- Run experiments and A/B tests to measure risk reduction against legitimate-user conversion impact.
- Build regression test suites and automated attack simulations to prevent recurrence.
- Define handoff criteria, operational documentation, and target dates for transferring mature controls to product teams.

## Requirements
- 3+ years of experience in security engineering, software engineering, application security, or anti-abuse engineering in a high-scale production environment.
- Bachelor’s or master’s degree in computer science, cybersecurity, software engineering, or a related technical field, or equivalent practical experience.
- Expert proficiency in Python, Go, Java, or similar production languages, plus expert SQL skills for analyzing system telemetry.
- Experience building API safeguards, rate-limiting frameworks, authentication and authorization checks, or input-validation controls.
- Experience writing unit, integration, and regression tests for critical backend software.
- Strong cross-functional collaboration and communication skills.

## Nice-to-haves
- Experience designing and executing A/B tests and balancing security safeguards against conversion friction.
- Expertise in threat modeling, secure system architecture, and application security principles.
- Familiarity with FT3, MITRE ATT&CK, and adversary kill-chain analysis.
- Knowledge of financial fraud vectors, threat-actor tactics, techniques, and procedures, and attacker infrastructure, including account takeover, card testing, and credential stuffing.
- Experience with Databricks, Trino, or PySpark for monitoring and measuring control performance across distributed systems.
- Experience incubating software features, defining operational handoff criteria, and transitioning ownership to partner engineering teams.

## Similar jobs

- [Security Engineer 2 - Cyber Threat Intelligence](https://hotfix.jobs/jobs/dace61ec-d55c-4705-a07d-4371901a3ef0) - Datadog - New York, NY - $140k – $195k/yr
- [Security Engineer, Threat Intelligence](https://hotfix.jobs/jobs/a9d333c0-2242-416f-a470-d3a19f982046) - Fluidstack - New York, NY - $220k – $280k/yr
- [Security Scientist](https://hotfix.jobs/jobs/36a4a0c9-f833-41fb-bd29-ad40c4d5050f) - Figma - Remote - $140k – $348k/yr
- [Security Engineer](https://hotfix.jobs/jobs/061a2617-4d6a-4cf3-96a0-ad832100d55f) - hud - San Francisco, CA
- [Abuse Research Engineer](https://hotfix.jobs/jobs/2f1effd6-b955-48c7-9d30-3d0aed220264) - Stripe - Remote

**Apply:** https://hotfix.jobs/jobs/26b83508-25a3-4173-a70a-ed1b509f85b7
**Canonical:** https://hotfix.jobs/jobs/26b83508-25a3-4173-a70a-ed1b509f85b7