# Incident Response Manager - Abuse Operations

**Company:** [Stripe](https://hotfix.jobs/companies/stripe)
**Location:** Seattle, WA, San Francisco, CA, New York, NY, Chicago, IL, Atlanta, GA, Dublin, Ireland
**Role:** Security Engineering
**Experience:** 10+ years
**Skills:** Python, SQL, Log Analysis, Network Security, Digital Forensics, Incident Response, Threat Intelligence, Databricks, Trino, Pyspark, pandas, scikit-learn
**Posted:** 2026-09-03

> Leads end-to-end fraud and abuse incident response, investigating high-risk accounts, coordinating cross-functional mitigation, and improving detection and response capabilities. Requires 10+ years of security or fraud incident response experience, strong Python and SQL expertise, and experience with forensics and automated workflows.

## Job Description

## Responsibilities
- Lead fraud and abuse incident response end-to-end, coordinating workstreams, investigating high-risk activity and accounts, and making actionable mitigation recommendations under pressure.
- Investigate, mitigate, and remediate urgent fraud incidents, including account takeovers and card testing, using FT3-mapped detection and signal enrichment.
- Analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors; classify findings using Fraud Taxonomy 3.0.
- Develop, document, and execute incident response strategies, runbooks, and capabilities to improve fraud and abuse detection and prevention.
- Partner with security, data science, legal, and policy teams to build automated or agentic response solutions, refine KPIs, and deliver incident reporting.
- Mentor teammates, lead incident response engineering projects, and improve quality standards across the team.

## Requirements
- 10+ years of experience leading security or fraud incident response.
- B.S. or M.S. in Computer Science, or equivalent experience.
- Expert knowledge of Python and SQL; familiarity with other programming languages.
- Experience with log analysis, network security, digital forensics, and incident response investigations.
- Ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
- Strong written and verbal communication skills, with experience driving cross-functional alignment independently.

## Preferred Qualifications
- Expertise in fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
- Understanding of threat-actor goals, behaviors, and tactics, techniques, and procedures.
- Experience with engineering, data processing, and analysis tools such as Databricks and Trino.
- Familiarity with big-data processing and data-science frameworks, including PySpark, Pandas, and scikit-learn.
- Experience with tactical threat intelligence or hunting sophisticated threat actors in an enterprise environment.
- Ability to use data and a user-centric approach to address complex product-integrity challenges.

## Similar jobs

- [Forward Deployed Security Engineer](https://hotfix.jobs/jobs/eea32ce9-298f-4136-b08a-056bc6e91835) - Stripe - Dublin, Ireland
- [Staff Security Researcher](https://hotfix.jobs/jobs/6b308cd8-be33-459a-b904-08e54567ad7b) - GitLab - Remote - $168k – $238k/yr
- [Staff Identity Governance and Access Engineer](https://hotfix.jobs/jobs/8fe7fe60-ff7a-48f4-a805-f3f100e1814f) - Okta - Bellevue, WA - $161k – $221k/yr
- [Staff Security Engineer](https://hotfix.jobs/jobs/29576103-a601-455c-a963-ce04128098e5) - Twilio - Remote - $156k – $194k/yr
- [Staff IAM Engineer](https://hotfix.jobs/jobs/7a722d47-b173-4ffc-9981-f10ed9f3ce9c) - Ironclad - San Francisco, CA - $170k – $190k/yr

**Apply:** https://hotfix.jobs/jobs/71053b9f-bd13-4cfb-957f-ad2c78e23c5a
**Canonical:** https://hotfix.jobs/jobs/71053b9f-bd13-4cfb-957f-ad2c78e23c5a