WFH.teamOpen app
Back to remote jobs
Remote job detail

Investigator

Stripe

LocationUnited States
SeniorityMid-level
CompanyStripe
Verified recentlyOct 7
Compensation

Salary not listed

Salary details are shown when available from the source listing. Sign in before applying so the role can be reviewed against your resume, salary goals, seniority, timezone, and location eligibility.

Requirements and working style

Decision details from the source listing

Experience

3+ years stated

Education

B.S. or M.S. in Computer Science or a related field, or equivalent experience

Schedule

unspecified

These fields are normalized from the employer's text. Confirm details on the employer site before applying.

WFH.team analysis

What this posting tells you

Stripe is hiring a US-remote Investigator for its Abuse Operations team. The role investigates and leads responses to fraud and product-abuse incidents, analyzes high-risk accounts and large datasets, and partners with security, fraud, data science, legal, and policy teams. Minimum requirements include 3+ years of relevant incident-response experience, 3+ years analyzing large datasets or building behavioral fraud models, and expert Python and SQL knowledge.

Role lane

Backend, Customer success, Data, DevOps, Finance and investments, Legal, Operations, Product, QA and testing, Sales, Security, Software

Where you can work

United States

Working hours

Eastern, Pacific, Western European

Arrangement

Mid-level · full_time

Required signals
Incident response in security, product abuse, or trust domainsAnalyzing large datasets or building behavioral fraud detection modelsPythonSQLLog analysisNetwork securityDigital forensicsIncident response investigationsClear communicationRisk analysis
Preferred signals
Adversarial mindset and knowledge of threat actor tactics, techniques, and proceduresDatabricksTrinoPySparkPandasScikit-learnTactical threat intelligenceThreat hunting
Confirm before applying
  • Compensation is not listed
Market context

Backend hiring on WFH.team

3,831active related roles
1,096new in the latest period
167.8jobs per 100 candidates
$186kmedian of comparable listed ranges

Category counts come from WFH.team's latest published remote job market snapshot.

Explore the remote job market
Skills and signals
Incident response in security, product abuse, or trust domainsAnalyzing large datasets or building behavioral fraud detection modelsPythonSQLLog analysisNetwork securityDigital forensicsIncident response investigationsClear communicationRisk analysisAdversarial mindset and knowledge of threat actor tactics, techniques, and proceduresDatabricksTrinoPySparkPandasScikit-learnRemote within the United States
Job description

Investigator at Stripe

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

About the team

Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve technical incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.

What you’ll do

You'll play a critical role in safeguarding our financial ecosystem by investigating high-risk accounts and identifying complex patterns of fraud during incidents. You will lead incident response for product abuse and fraud events, conducting deep-dive analyses to identify root causes. By collaborating cross-functionally, you will drive improvements that enhance our fraud detection and prevention strategies at scale. Your expertise will be essential in automating response processes through agentic approaches, allowing us to safeguard merchants and neutralize threats with speed and precision.

Responsibilities

  • Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped detection and signals enrichment to reduce uncertainty and accelerate response.
  • As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 (Fraud Taxonomy 3.0) to standardize threat intelligence.
  • Lead incident root cause analyses to identify gaps in current systems and strategies, leveraging the FT3 framework, data-driven model to drive enhancements and process improvements for emerging fraud risks.
  • Streamline incident response capabilities, ensuring the tooling and processes are clear, accurate and efficient
  • Work cross-functionally with security, fraud and data science teams to build agentic solutions for responding to abuse incidents at scale
  • Effectively communicate cross-functionally with legal and policy teams to assess and mitigate risks, while demonstrating strong problem-solving under pressure.
  • Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team

Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • 3+ years of experience conducting incident response in security, product abuse or trust domains
  • 3+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to fraud detection
  • B.S. or M.S. Computer Science or related field, or equivalent experience
  • Expert knowledge of Python and SQL, and familiarity with other programming languages
  • Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
  • Ability to communicate results clearly and focus on impact
  • Ability to think creatively and holistically about reducing risk in a complex environment

Preferred qualifications

  • An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
  • Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
  • Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
  • Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
  • Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges
Company context

Working remotely at Stripe

Stripe is a software platform for starting and running internet businesses.

Headquarters
Australia, United States, Japan, France, Germany, India, Ireland, Mexico, Netherlands, United Kingdom, and Singapore
Team size
1001-5000
Founded
2009
Application process

Review current openings on Stripe's official careers page before applying.

JavaScriptPythonHTML5JavaCSS 3C#RubyKotlinSwiftGo
Research Stripe
Remote Investigator at Stripe | WFH.team