
Remote opportunity at
StripeAbuse Research Engineer
Stripe functions as a financial infrastructure provider, offering payment acceptance and revenue management tools for enterprises and startups globally. The organization is hiring an Abuse Research…
Career Tools
About This Role
Stripe functions as a financial infrastructure provider, offering payment acceptance and revenue management tools for enterprises and startups globally. The organization is hiring an Abuse Research Engineer to join the Abuse Research Group. This role focuses on proactive threat investigations, mapping fraudulent pathways, and analyzing adversary behavior rather than waiting for alerts. The professional in this position will design automated testing tools, study novel attack vectors, and formulate strategic control…
Job Description
Stripe functions as a financial infrastructure provider, offering payment acceptance and revenue management tools for enterprises and startups globally. The organization is hiring an Abuse Research Engineer to join the Abuse Research Group. This role focuses on proactive threat investigations, mapping fraudulent pathways, and analyzing adversary behavior rather than waiting for alerts. The professional in this position will design automated testing tools, study novel attack vectors, and formulate strategic control recommendations to eliminate vulnerabilities.
The role suits individuals with a strong background in cybersecurity, threat hunting, or product abuse investigations who can work collaboratively across multiple departments. Key partners for this role include Fraud Operations, Strategy, Risk, Onboarding, and Security teams. The position involves leveraging the company's Fraud Taxonomy 3.0 framework to categorize threats, integrate intelligence feeds, and execute hypothesis-driven detection operations.
Candidates will spend their time building simulation workflows, executing agentic testing frameworks, and transforming raw research into tangible security guidance. This position offers an opportunity to protect a major financial ecosystem by systematically identifying bad actor techniques and verifying that deployed controls effectively disrupt attack lifecycles.
Responsibilities
- Conduct iterative, hypothesis-driven threat hunting operations across company systems and external data sources.
- Apply and enrich the Fraud Taxonomy 3.0 framework across empirical datasets and incidents.
- Collaborate with internal teams to integrate, curate, and automate threat feeds into engineering workflows.
- Translate raw research findings into actionable threat advisories and control recommendations for cross-functional partners.
- Utilize agentic automated testing frameworks to simulate adversary tactics, techniques, and procedures.
- Generate regression scenarios to test whether implemented controls successfully interrupt attack kill chains.
Requirements
- Minimum of five years of experience in threat intelligence, threat hunting, or technical incident response within cybersecurity, product abuse, or trust domains.
- Minimum of five years of experience analyzing large and complex datasets with data analytics tools to identify anomalies and behavioral trends.
- Expert proficiency in Python and SQL for scripting, workflow automation, tool building, and big data pipeline querying.
- Practical experience performing log analysis, digital forensics, and cyber investigation methodologies.
- Strong communication abilities to convey technical research into clear recommendations for stakeholders.
Qualifications
- Bachelor of Science or Master of Science in Computer Science, Cybersecurity, a related technical discipline, or equivalent practical experience.
- Deep technical familiarity with financial fraud threat actor motivations, infrastructure, and tactics.
- Familiarity with structured taxonomies including Fraud Taxonomy 3.0 or MITRE ATT&CK.
- Competency with data processing and analytics platforms such as Databricks, Trino, PySpark, Pandas, or Scikit-Learn.
- Background utilizing Threat Intelligence Platforms, tactical feeds, open-source intelligence, and breach intelligence.
- Experience building or using agentic large language model tools, automated testing systems, or control validation frameworks.
- Involvement in industry conferences, webinars, or threat-sharing groups alongside certifications such as GCTI, GCFA, or OSCP.
Core Skills
Frequently Asked Questions
What is the location or remote work policy for this role?
The source posting states the position is remote from the United States.
What is the employment type?
The posting lists the employment type as full-time.
What are the core technical skill requirements?
Applicants must demonstrate expert proficiency in Python and SQL, along with at least five years of experience in threat hunting, threat intelligence, or technical incident response.
Is the salary specified in the job posting?
No, the posting does not specify salary information.
Sample Interview Questions
AI-generated questions tailored to this specific role — a preview of the full practice set.