Your impact? Helping millions take back control of their online security, privacy, and data.
About the RoleWe're hiring a Fraud Prevention Engineer to own the technical side of fraud prevention in our Payments team. You'll sit between fraud analysts and engineering - investigating how attacks happen, building defenses, and translating between both worlds. Think: root cause analysis, Cloudflare/Turnstile optimization, technical roadmap ownership, and enabling analysts with deeper technical capabilities. This is the first hire in what will become a dedicated fraud prevention engineering function.
Main Responsibilities- Investigate fraud attacks end-to-end - identify vectors, perform root cause analysis at the infra and application level, implement countermeasures
- Configure and optimize Cloudflare (WAF, bot management, rate limiting, Workers) and Turnstile challenge flows
- Act as the technical bridge between fraud analysts, engineering, and product teams
- Analyze multiple attack vectors, plan and prioritize technical fraud prevention tasks on the roadmap
- Build tooling, scripts, and queries that elevate the fraud analyst team's technical capabilities
- Maintain deep understanding of payment flows (authorization, 3DS, tokenization) and where vulnerabilities sit
Core Requirements- 3+ years in fraud prevention, security engineering, or a technical role in payments
- JavaScript/TypeScript - comfortable with Cloudflare Workers, Turnstile, and browser-side challenge flows
- Backend understanding - can navigate server-side codebases, trace API flows, and read system logs
- Strong SQL - joins, window functions, large transaction datasets
- Hands-on Cloudflare experience (WAF, bot management, rate limiting) or similar edge/CDN security platforms
- Ability to communicate technical findings to non-technical stakeholders and vice versa
Bonus points- Python scripting for automation and data analysis
- Experience with log/observability tools (ELK, Grafana, Datadog)
- Background in application security or threat modeling
- Familiarity with fraud platforms (Forter, Riskified, Sift) or in-house rule engines
- Git workflow, CI/CD basics