WFH.teamOpen app
Back to remote jobs
Remote job detail

Security Engineer

Stripe

LocationUnited States
Senioritymid_senior
CompanyStripe
Verified recentlyChecked today
Compensation

Salary not listed

Salary details are shown when available from the source listing. Sign in before applying so the role can be reviewed against your resume, salary goals, seniority, timezone, and location eligibility.

Requirements and working style

Decision details from the source listing

Experience

3+ years stated

Education

B.S. or M.S. in Computer Science, Cybersecurity, Software Engineering or related technical field, or equivalent practical experience

Work authorization

United States work authorization

Schedule

fixed

Required overlap

Not specified

These fields are normalized from the employer's text. Confirm details on the employer site before applying.

WFH.team analysis

What this posting tells you

Stripe is hiring a mid-senior level Security Engineer for their Abuse Control Engineering team. The role is US Remote and full-time. Candidates need 3+ years experience in security or software engineering fields with strong programming skills in Python, Go, or Java plus SQL. Responsibilities include designing and prototyping rapid technical protections against abuse, collaborating cross-functionally, running experiments to balance risk and user impact, and building automated regression tests. Preferred skills include threat modeling, financial fraud knowledge, and experience with large scale data platforms. Education minimum is BS/MS or equivalent practical experience. No salary or visa sponsorship details provided.

Role lane

Backend, Customer success, Data, Design and creative, DevOps, Finance and investments, Product, QA and testing, Sales, Security, Software, Writing and content

Where you can work

United States

Working hours

US timezones

Arrangement

mid_senior · full_time

Required signals
Security EngineeringSoftware EngineeringApplication SecurityAnti-Abuse EngineeringPythonGoJavaSQLAPI safeguardsrate-limiting frameworksauthentication/authorization checksinput validation controlsautomated testing frameworksunit testingintegration testingregression testingcross-functional collaboration
Preferred signals
A/B testingthreat modelingsecure system architectureapplication security designFT3 frameworkMITRE ATT&CKadversary kill chain analysisfinancial fraud vectorsthreat actor TTPsattacker infrastructurelarge-scale data processing platformsDatabricksTrinoPySparksoftware feature incubationoperational handoff
Confirm before applying
  • Compensation is not listed
Market context

Backend hiring on WFH.team

6,091active related roles
3,247new in the latest period
286.2jobs per 100 candidates
$203kmedian of comparable listed ranges

Category counts come from WFH.team's latest published remote job market snapshot.

Explore the remote job market
Skills and signals
Security EngineeringSoftware EngineeringApplication SecurityAnti-Abuse EngineeringPythonGoJavaSQLAPI safeguardsrate-limiting frameworksauthentication/authorization checksinput validation controlsautomated testing frameworksunit testingintegration testingregression testingUS Remote
Job description

Security Engineer at Stripe

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

About the team

Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE bridges the gap using real attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale. We partner closely with Fraud, Risk and Product Engineering to run rigorous experiments, balancing aggressive risk mitigation against legitimate user conversion. Operating as both a strike team and an incubator, ACE builds automated regression suites in partnership with Abuse Research to permanently block threat recurrence and seamlessly transfers mature controls to long-term product owners across Stripe.

What you’ll do

As an Abuse Control Engineer on the Abuse Control Engineering (ACE) team, you will design, prototype, and incubate technical defenses that safeguard Stripe’s financial ecosystem against complex, cross-cutting abuse vectors.

Where emerging threat patterns identify Stripe product weaknesses, ACE steps in to rapidly build and experiment with technical safeguards. Driven by empirical evidence and Stripe’s FT3 (Fraud Taxonomy 3.0) framework, you will translate threat intelligence into hard technical control requirements (e.g., API rate-limiting, step-up challenges, parameter validation, pre-debit holds). You will carefully balance security and product velocity, running experiments to evaluate risk reduction against user conversion impact. Managing controls through a strict incubation lifecycle, you will build automated regression suites to prevent recurrence and partner with native product teams to hand off mature, long-term defenses.

Responsibilities

  • Rapid Control Prototyping: Design, prototype, and deploy technical controls across API, protocol, and product boundaries to immediately close high-impact abuse vectors. Evidence-Based Technical Requirements: Translate empirical attacker evidence and FT3 threat research Abuse Research, Fraud and Security into precise technical abuse requirements and control specifications.
  • Control Co-Design: Collaborate closely with teams across Stripe to co-design resilient, secure controls across payment, onboarding, identity, and Connect surfaces.
  • Risk Experimentation: Run rigorous experiments and A/B tests to measure risk reduction against legitimate user conversion impact, optimizing controls to minimize friction while neutralizing threats.
  • Regression Testing: Build comprehensive regression testing suites and automated attack simulations with Abuse Research to ensure mitigated abuse vectors do not recur.
  • Stakeholder Management: Execute ACE’s incubation model by defining handoff criteria, operational documentation, and target dates to transfer successful controls to product teams.

Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • 3+ years of experience in Security Engineering, Software Engineering, Application Security, or Anti-Abuse Engineering in a high-scale production environment.
  • B.S. or M.S. in Computer Science, Cybersecurity, Software Engineering, or a related technical field, or equivalent practical experience.
  • Strong software development background with expert proficiency in Python, Go, Java, or similar production languages, alongside expert SQL skills for analyzing system telemetry.
  • Hands-on engineering experience building API-level safeguards, rate-limiting frameworks, authentication/authorization checks, or input validation controls.
  • Demonstrated experience with automated testing frameworks, including writing unit, integration, and regression tests for critical backend software.
  • Strong cross-functional collaboration and communication skills, with a track record of partnering across security, product, and platform teams to drive technical outcomes.

Preferred qualifications

  • Proven track record of designing and executing A/B tests, evaluating control efficacy, and balancing security safeguards against user conversion friction.
  • Deep expertise in threat modeling, secure system architecture, and modern application security design principles.
  • Familiarity with established threat frameworks (e.g., FT3, MITRE ATT&CK) and applying adversary kill chain analysis to build resilient defenses.
  • Strong domain knowledge of financial fraud vectors, threat actor TTPs, and attacker infrastructure (e.g., Account Takeover, Card Testing, Credential Stuffing).
  • Hands-on experience with large-scale data processing platforms (e.g., Databricks, Trino, PySpark) to monitor and measure control performance across distributed systems.
  • Demonstrated capability in incubating software features, establishing clear operational handoff criteria, and seamlessly transitioning ownership to partner engineering teams.
Company context

Working remotely at Stripe

Stripe is a software platform for starting and running internet businesses.

Headquarters
Australia, United States, Japan, France, Germany, India, Ireland, Mexico, Netherlands, United Kingdom, and Singapore
Team size
1001-5000
Founded
2009
Application process

Review current openings on Stripe's official careers page before applying.

JavaScriptPythonHTML5JavaCSS 3C#RubyKotlinSwiftGo
Research Stripe