# Abuse Research Engineer

**Company:** [Stripe](https://hotfix.jobs/companies/stripe)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** Python, SQL, Threat Hunting, Threat Intelligence, Digital Forensics, Log Analysis, Data Analytics, Mitre Att&Ck, Databricks, Trino, Pyspark, pandas, scikit-learn, Osint, Agentic Llms
**Posted:** 2026-09-09

> Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.

## Job Description

## Responsibilities
- Conduct hypothesis-driven threat hunting across internal Stripe systems, telemetry, and external data sources.
- Apply and enrich the FT3 fraud taxonomy across datasets and incidents, standardizing threat intelligence across kill-chain phases and targeted API endpoints.
- Integrate, curate, and automate threat feeds into engineering workflows.
- Translate research findings into threat advisories and recommendations for policy, technical controls, support workflows, and detection mechanisms.
- Use agentic automated testing frameworks to simulate adversary tactics, techniques, and procedures (TTPs), validate controls, and generate regression scenarios.
- Collaborate with Fraud Operations, Strategy, Risk, Onboarding, Security, and Fraud Intelligence teams.

## Requirements
- 5+ years of experience in threat intelligence, threat hunting, or technical incident response within cybersecurity, product abuse, or trust domains.
- 5+ years of experience analyzing complex datasets with data analytics tools to identify anomalies, map behavioral trends, and solve fraud problems.
- Bachelor's or master's degree in Computer Science, Cybersecurity, a related technical field, or equivalent practical experience.
- Expert proficiency in Python and SQL.
- Experience using code and scripting to automate workflows, build investigative tools, or query big-data pipelines.
- Hands-on experience with log analysis, digital forensics, and cyber investigation methodologies.
- Strong communication skills and the ability to translate technical research into actionable recommendations.

## Preferred Qualifications
- Understanding of threat-actor motivations, infrastructure, and TTPs related to financial fraud, including account takeover, card testing, and credential stuffing.
- Familiarity with FT3 or MITRE ATT&CK.
- Experience with Databricks, Trino, PySpark, Pandas, or scikit-learn.
- Experience with threat intelligence platforms, tactical threat feeds, OSINT, and breach intelligence.
- Experience building or using agentic LLM tools, automated testing systems, or control-validation frameworks to model adversary behavior at scale.

## Similar jobs

- [Security Engineer, Threat Intelligence](https://hotfix.jobs/jobs/a9d333c0-2242-416f-a470-d3a19f982046) - Fluidstack - New York, NY - $220k – $280k/yr
- [Security Scientist](https://hotfix.jobs/jobs/36a4a0c9-f833-41fb-bd29-ad40c4d5050f) - Figma - Remote - $140k – $348k/yr
- [Security Engineer](https://hotfix.jobs/jobs/061a2617-4d6a-4cf3-96a0-ad832100d55f) - hud - San Francisco, CA
- [Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e5c4fc22-2c3a-4334-8eae-e8ab5bcf2a8a) - Anthropic - San Francisco, CA - $300k – $320k/yr
- [Software Engineer, HSM Infrastructure Security, Consumer Devices](https://hotfix.jobs/jobs/c59b2911-dd77-45cf-a787-90da0f7be1b7) - OpenAI - San Francisco, CA - $347k – $445k/yr

**Apply:** https://hotfix.jobs/jobs/2f1effd6-b955-48c7-9d30-3d0aed220264
**Canonical:** https://hotfix.jobs/jobs/2f1effd6-b955-48c7-9d30-3d0aed220264