WFH.teamOpen app
Back to remote jobs
Remote job detail

Abuse Research Engineer

Stripe

LocationUnited States
SeniorityMid-level to senior
CompanyStripe
Verification agingSep 30
Compensation

Salary not listed

Salary details are shown when available from the source listing. Sign in before applying so the role can be reviewed against your resume, salary goals, seniority, timezone, and location eligibility.

Requirements and working style

Decision details from the source listing

Experience

5+ years stated

Education

B.S. or M.S. in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience

Schedule

unspecified

These fields are normalized from the employer's text. Confirm details on the employer site before applying.

WFH.team analysis

What this posting tells you

Stripe seeks an Abuse Research Engineer for its Abuse Research Group. The role focuses on proactive threat hunting, fraud kill-chain analysis, threat intelligence, adversary simulation, and actionable security controls. Requires at least 5 years of relevant threat intelligence, hunting, or incident response experience and at least 5 years analyzing complex datasets. The position is remote in the United States.

Role lane

Backend, Customer success, Data, DevOps, Finance and investments, Operations, Product, QA and testing, Sales, Security, Software, Customer support

Where you can work

United States

Working hours

Timezone overlap is not stated.

Arrangement

Mid-level to senior · full_time

Required signals
Threat intelligence, threat hunting, or technical incident responseLarge-scale data analysisPythonSQLLog analysisDigital forensicsCyber investigation methodologiesCross-functional communication
Preferred signals
Financial fraud threat actor analysisFT3 or MITRE ATT&CKDatabricksTrinoPySparkPandasScikit-LearnThreat Intelligence PlatformsOSINTBreach intelligenceAgentic LLM toolsAutomated testing and control validation frameworksGCTI, GCFA, or OSCP certifications
Confirm before applying
  • Required timezone overlap is not stated
  • Compensation is not listed
Market context

Backend hiring on WFH.team

3,831active related roles
1,096new in the latest period
167.8jobs per 100 candidates
$186kmedian of comparable listed ranges

Category counts come from WFH.team's latest published remote job market snapshot.

Explore the remote job market
Skills and signals
Threat intelligence, threat hunting, or technical incident responseLarge-scale data analysisPythonSQLLog analysisDigital forensicsCyber investigation methodologiesCross-functional communicationFinancial fraud threat actor analysisFT3 or MITRE ATT&CKDatabricksTrinoPySparkPandasScikit-LearnThreat Intelligence PlatformsRemote within the United States
Job description

Abuse Research Engineer at Stripe

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

About the team

Abuse Research Group (ARG) handles proactive threat hunting and adversary behavior analysis across Stripe products. Rather than reacting to alerts, the team maps end-to-end fraud and abuse paths, validates novel attack vectors, and identifies product conditions that enable fraud. Using agentic automated testing and simulation tools, ARG translates research into actionable threat advisories, strategic control recommendations, and regression scenarios to systematically eliminate vulnerabilities.

What you’ll do

As an Abuse Research Engineer in the Abuse Research Group, you will play a critical role in safeguarding Stripe’s financial ecosystem by proactively hunting for advanced threats, dissecting complex fraud vectors, and extracting actionable adversary intelligence. Rather than relying solely on reactive alerts, you will develop and execute hypothesis-driven threat hunting operations across internal telemetry and external sources to uncover fraudulent tools, tactics, and techniques (TTPs) before they impact Stripe’s platform. Central to this work is FT3 (Fraud Taxonomy 3.0), Stripe’s multi-layered taxonomy that decomposes monolithic fraud into structured kill chains. Collaborating cross-functionally with Fraud Ops, Strategy, Risk, Onboarding, and Security, you will integrate threat intelligence, build agentic simulation workflows, and systematically eliminate product vulnerabilities.

Responsibilities

  • Proactive Threat Hunting & Kill Chain Analysis: Formulate hypotheses and conduct iterative threat hunting operations across Stripe systems and external data.
  • FT3 Taxonomy: Apply and enrich the FT3 framework across empirical datasets and incidents, standardizing threat intelligence across kill chain phases and targeted API endpoints.
  • Threat Intelligence & Signal Expansion: Partner with teams like Fraud Intelligence to integrate, curate, and automate threat feeds into engineering workflows.
  • Cross-Functional Advisories & Strategic Controls: Translate raw research and retrospective findings into actionable threat advisories and control recommendations (policy, technical systems, support workflows, and detection mechanisms) for stakeholders across Fraud, Risk, Onboarding, and Security.
  • Agentic Testing & Adversary Simulation: Utilize agentic automated testing frameworks to simulate adversary TTPs, validate whether deployed controls interrupt empirical kill chains, and generate regression scenarios to exercise controls.

Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • 5+ years of experience conducting threat intelligence, threat hunting, or technical incident response within cyber security, product abuse, or trust domains.
  • 5+ years of experience analyzing large, complex datasets using data analytics tools to identify anomalies, map behavioral trends, and solve complex fraud problems.
  • B.S. or M.S. in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
  • Expert proficiency in Python and SQL, with demonstrated experience using code and scripting to automate workflows, build investigative tools, or query big data pipelines.
  • Hands-on experience in log analysis (e.g., application logs, API route telemetry, network security events), digital forensics, and cyber investigation methodologies.
  • Strong communication skills with a proven ability to translate complex technical research into clear, actionable recommendations and advisories for cross-functional partners.

Preferred qualifications

  • Deep technical understanding of threat actor motivations, infrastructure, and TTPs specific to financial fraud (e.g., ATO, Card Testing, Credential Stuffing).
  • Familiarity with standardized taxonomies such as FT3 or MITRE ATT&CK.
  • Proficiency with engineering, data processing, and analysis platforms such as Databricks, Trino, PySpark, Pandas, or Scikit-Learn.
  • Proven background utilizing Threat Intelligence Platforms (TIPs), tactical threat feeds, OSINT, and breach intelligence.
  • Demonstrated capability building or leveraging agentic LLM tools, automated testing systems, or control validation frameworks to model adversary behavior at scale.
  • Participation in industry conferences, webinars, or threat-sharing groups, alongside relevant professional certifications (e.g., GCTI, GCFA, OSCP).
Company context

Working remotely at Stripe

Stripe is a software platform for starting and running internet businesses.

Headquarters
Australia, United States, Japan, France, Germany, India, Ireland, Mexico, Netherlands, United Kingdom, and Singapore
Team size
1001-5000
Founded
2009
Application process

Review current openings on Stripe's official careers page before applying.

JavaScriptPythonHTML5JavaCSS 3C#RubyKotlinSwiftGo
Research Stripe
Remote Abuse Research Engineer at Stripe | WFH.team