Skip to content
StripeStripe

Incident Response Manager - Abuse Operations

Leads end-to-end fraud and abuse incident response, investigating high-risk accounts, coordinating cross-functional mitigation, and improving detection and response capabilities. Requires 10+ years of security or fraud incident response experience, strong Python and SQL expertise, and experience with forensics and automated workflows.

About the job

Responsibilities

  • Lead fraud and abuse incident response end-to-end, coordinating workstreams, investigating high-risk activity and accounts, and making actionable mitigation recommendations under pressure.
  • Investigate, mitigate, and remediate urgent fraud incidents, including account takeovers and card testing, using FT3-mapped detection and signal enrichment.
  • Analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors; classify findings using Fraud Taxonomy 3.0.
  • Develop, document, and execute incident response strategies, runbooks, and capabilities to improve fraud and abuse detection and prevention.
  • Partner with security, data science, legal, and policy teams to build automated or agentic response solutions, refine KPIs, and deliver incident reporting.
  • Mentor teammates, lead incident response engineering projects, and improve quality standards across the team.

Requirements

  • 10+ years of experience leading security or fraud incident response.
  • B.S. or M.S. in Computer Science, or equivalent experience.
  • Expert knowledge of Python and SQL; familiarity with other programming languages.
  • Experience with log analysis, network security, digital forensics, and incident response investigations.
  • Ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
  • Strong written and verbal communication skills, with experience driving cross-functional alignment independently.

Preferred Qualifications

  • Expertise in fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
  • Understanding of threat-actor goals, behaviors, and tactics, techniques, and procedures.
  • Experience with engineering, data processing, and analysis tools such as Databricks and Trino.
  • Familiarity with big-data processing and data-science frameworks, including PySpark, Pandas, and scikit-learn.
  • Experience with tactical threat intelligence or hunting sophisticated threat actors in an enterprise environment.
  • Ability to use data and a user-centric approach to address complex product-integrity challenges.

Skills

Python, SQL, Log Analysis, Network Security, Digital Forensics, Incident Response, Threat Intelligence, Databricks, Trino, Pyspark, pandas, scikit-learn

Stripe

Stripe

Dublin, Ireland

Forward Deployed Security Engineer
No salary listedOn-site10+ YOESecurity Engineering

Leads live fraud and abuse incident response, investigates high-risk accounts, and helps merchants remediate security threats. Requires 10+ years of security or fraud incident-response experience, expert Python and SQL skills, and expertise in forensics, threat intelligence, and network security.

GitLab

GitLab

United States
Staff Security Researcher
$168k+/yrRemote7+ YOESecurity Engineering

Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.

Okta

Okta

Bellevue, WA
Staff Identity Governance and Access Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.

Twilio

Twilio

United States

Staff Security Engineer
$156k+/yrRemote7+ YOESecurity Engineering

Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.

Ironclad

Ironclad

San Francisco, CA

Staff IAM Engineer
$170k+/yrHybrid4+ YOESecurity Engineering

Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.