Skip to content
StripeStripe

Abuse Research Engineer

Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.

About the job

Responsibilities

  • Conduct hypothesis-driven threat hunting across internal Stripe systems, telemetry, and external data sources.
  • Apply and enrich the FT3 fraud taxonomy across datasets and incidents, standardizing threat intelligence across kill-chain phases and targeted API endpoints.
  • Integrate, curate, and automate threat feeds into engineering workflows.
  • Translate research findings into threat advisories and recommendations for policy, technical controls, support workflows, and detection mechanisms.
  • Use agentic automated testing frameworks to simulate adversary tactics, techniques, and procedures (TTPs), validate controls, and generate regression scenarios.
  • Collaborate with Fraud Operations, Strategy, Risk, Onboarding, Security, and Fraud Intelligence teams.

Requirements

  • 5+ years of experience in threat intelligence, threat hunting, or technical incident response within cybersecurity, product abuse, or trust domains.
  • 5+ years of experience analyzing complex datasets with data analytics tools to identify anomalies, map behavioral trends, and solve fraud problems.
  • Bachelor's or master's degree in Computer Science, Cybersecurity, a related technical field, or equivalent practical experience.
  • Expert proficiency in Python and SQL.
  • Experience using code and scripting to automate workflows, build investigative tools, or query big-data pipelines.
  • Hands-on experience with log analysis, digital forensics, and cyber investigation methodologies.
  • Strong communication skills and the ability to translate technical research into actionable recommendations.

Preferred Qualifications

  • Understanding of threat-actor motivations, infrastructure, and TTPs related to financial fraud, including account takeover, card testing, and credential stuffing.
  • Familiarity with FT3 or MITRE ATT&CK.
  • Experience with Databricks, Trino, PySpark, Pandas, or scikit-learn.
  • Experience with threat intelligence platforms, tactical threat feeds, OSINT, and breach intelligence.
  • Experience building or using agentic LLM tools, automated testing systems, or control-validation frameworks to model adversary behavior at scale.

Skills

Python, SQL, Threat Hunting, Threat Intelligence, Digital Forensics, Log Analysis, Data Analytics, Mitre Att&Ck, Databricks, Trino, Pyspark, pandas, scikit-learn, Osint, Agentic Llms

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

hud

hud

San Francisco, CA

Security Engineer
No salary listedOn-siteSecurity Engineering

Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Offensive Security
$300k+/yrHybrid5+ YOESecurity Engineering

Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.

OpenAI

OpenAI

San Francisco, CA

Software Engineer, HSM Infrastructure Security, Consumer Devices
$347k+/yrOn-site5+ YOESecurity Engineering

Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.