Stripe

Abuse Research Engineer

Stripe$130K — $160K *
US-AnywhereRemote in United States
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in threat intelligence, threat hunting, or incident response.
  • 5+ years analyzing large datasets to identify anomalies and trends.
  • B.S. or M.S. in Computer Science, Cybersecurity, or related field.
  • Expert in Python and SQL for automation and big data management.
  • Experience in log analysis and digital forensics.
  • Strong communication skills to present technical findings to non-technical stakeholders.

Responsibilities

  • Conduct proactive threat hunting across Stripe systems and external data.
  • Enrich the FT3 framework with insights from datasets and incidents.
  • Integrate and automate threat feeds into engineering workflows with Fraud Intelligence.
  • Translate technical research into actionable advisories for cross-functional teams.
  • Simulate adversary behavior using automated testing frameworks and validate controls.

Benefits

  • Comprehensive health and wellness programs.
  • Access to professional development resources.
  • Flexible work arrangements and remote work options.
  • Support for ongoing education and certifications.
Full Job Description
What you'll do

As an Abuse Research Engineer in the Abuse Research Group, you will play a critical role in safeguarding Stripe's financial ecosystem by proactively hunting for advanced threats, dissecting complex fraud vectors, and extracting actionable adversary intelligence. Rather than relying solely on reactive alerts, you will develop and execute hypothesis-driven threat hunting operations across internal telemetry and external sources to uncover fraudulent tools, tactics, and techniques (TTPs) before they impact Stripe's platform. Central to this work is FT3 (Fraud Taxonomy 3.0), Stripe's multi-layered taxonomy that decomposes monolithic fraud into structured kill chains. Collaborating cross-functionally with Fraud Ops, Strategy, Risk, Onboarding, and Security, you will integrate threat intelligence, build agentic simulation workflows, and systematically eliminate product vulnerabilities.
Responsibilities
  • Proactive Threat Hunting & Kill Chain Analysis: Formulate hypotheses and conduct iterative threat hunting operations across Stripe systems and external data.
  • FT3 Taxonomy: Apply and enrich the FT3 framework across empirical datasets and incidents, standardizing threat intelligence across kill chain phases and targeted API endpoints.
  • Threat Intelligence & Signal Expansion: Partner with teams like Fraud Intelligence to integrate, curate, and automate threat feeds into engineering workflows.
  • Cross-Functional Advisories & Strategic Controls: Translate raw research and retrospective findings into actionable threat advisories and control recommendations (policy, technical systems, support workflows, and detection mechanisms) for stakeholders across Fraud, Risk, Onboarding, and Security.
  • Agentic Testing & Adversary Simulation: Utilize agentic automated testing frameworks to simulate adversary TTPs, validate whether deployed controls interrupt empirical kill chains, and generate regression scenarios to exercise controls.
Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
  • 5+ years of experience conducting threat intelligence, threat hunting, or technical incident response within cyber security, product abuse, or trust domains.
  • 5+ years of experience analyzing large, complex datasets using data analytics tools to identify anomalies, map behavioral trends, and solve complex fraud problems.
  • B.S. or M.S. in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
  • Expert proficiency in Python and SQL, with demonstrated experience using code and scripting to automate workflows, build investigative tools, or query big data pipelines.
  • Hands-on experience in log analysis (e.g., application logs, API route telemetry, network security events), digital forensics, and cyber investigation methodologies.
  • Strong communication skills with a proven ability to translate complex technical research into clear, actionable recommendations and advisories for cross-functional partners.
Preferred qualifications
  • Deep technical understanding of threat actor motivations, infrastructure, and TTPs specific to financial fraud (e.g., ATO, Card Testing, Credential Stuffing).
  • Familiarity with standardized taxonomies such as FT3 or MITRE ATT&CK.
  • Proficiency with engineering, data processing, and analysis platforms such as Databricks, Trino, PySpark, Pandas, or Scikit-Learn.
  • Proven background utilizing Threat Intelligence Platforms (TIPs), tactical threat feeds, OSINT, and breach intelligence.
  • Demonstrated capability building or leveraging agentic LLM tools, automated testing systems, or control validation frameworks to model adversary behavior at scale.

About Stripe

Stripe is a technology company that builds economic infrastructure for the internet. Businesses of every size—from new startups to public companies—use our software to accept payments and manage their businesses online. Stripe helps new companies get started and grow their revenues, and established businesses accelerate into new markets and launch new business models. Stripe powers businesses all over the world, from the new startup that just launched yesterday to the Fortune 500 companies that we all know and love. Stripe is headquartered in San Francisco, with offices in Dublin, London, Paris, Singapore, Tokyo, and more.
Learn more about Stripe
Size
4,000 employees
Industry
Founded
2010

Similar Jobs

More Jobs at Stripe

More Finance & Insurance Jobs

Find similar Abuse Research Engineer jobs: