Stripe

Offensive Security Engineer

Stripe • $170K — $255K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in offensive security, penetration testing or red teaming
  • Strong programming skills in Python, Go or similar languages
  • Deep knowledge of web application security, including OWASP Top 10
  • Hands-on experience with cloud platforms like AWS, Azure, or GCP
  • Proficiency with offensive tools such as Burp Suite and Cobalt Strike
  • Familiarity with MITRE ATT&CK framework and adversary tradecraft
  • Excellent communication skills to convey technical findings clearly

Responsibilities

  • Conduct penetration tests across web and cloud applications
  • Plan and execute red team engagements simulating real-world threats
  • Perform assessments to evaluate detection and response capabilities
  • Collaborate with defensive teams to improve security controls
  • Contribute insights for detection rule development and threat hunting
  • Support incident investigations with offensive expertise
  • Design and maintain custom tools and automation frameworks

Benefits

  • Equity participation in Stripe's growth
  • 401(k) plan with matching contributions
  • Comprehensive medical, dental, and vision coverage
  • Wellness stipends
  • Annual budget for training, certifications, and conference attendance
Full Job Description
What you'll do

As an Offensive Security Engineer on the Proactive Threat team, you will simulate the tactics, techniques, and procedures (TTPs) of real-world adversaries to uncover security risks across Stripe's products and infrastructure. You'll conduct hands-on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities. Your work will directly influence how Stripe builds, ships, and secures financial infrastructure used by millions of businesses worldwide.

Beyond assessments, you'll design and build offensive tooling and automation that amplifies the team's impact. You'll leverage threat intelligence to prioritize testing efforts, contribute to incident investigations when needed, and act as a subject-matter expert for security initiatives across the company.
Responsibilities
  • Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure
  • Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios
  • Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams
  • Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity
  • Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks
  • Support incident investigations by providing offensive expertise, log analysis, and root cause analysis when required
  • Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverage
  • Build internal platforms and workflows that enable scalable, repeatable offensive operations
  • Contribute to internal security tooling repositories and champion engineering best practices within the team
  • Automate repetitive testing tasks, payload generation, and reporting workflows using modern development practices
  • Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non-technical stakeholders
  • Act as a subject-matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and Stripe-wide security initiatives
  • Lead offensive security projects end-to-end, mentor junior team members, and foster a culture of continuous learning and knowledge sharing
  • Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and contribute to the broader security community
Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
  • 5+ years of experience in offensive security, penetration testing, red teaming, or a related field
  • Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits
  • Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.)
  • Hands-on experience with cloud platforms (AWS, Azure, or GCP), including cloud-native attack techniques and misconfigurations
  • Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks
  • Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including TTPs for initial access, privilege escalation, lateral movement, and exfiltration
  • Excellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk-based recommendations
  • Ability to think like an adversary - creative, persistent, and able to holistically assess risk in complex environments
Preferred qualifications
  • Experience conducting offensive security in fintech, financial services, or other highly regulated environments
  • Background in vulnerability research, exploit development, or CVE discovery
  • Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations)
  • Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support
  • Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows
  • Interest or experience in agentic automation - using LLMs or autonomous agents to augment reconnaissance, vulnerability discovery, or exploitation workflows
  • Experience testing AI/ML systems or LLM-based applications for security weaknesses (prompt injection, training data extraction, model manipulation, etc.)
  • Contributions to open-source security tools, published research, blog posts, or conference presentations
  • Relevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications
Location

This role is remote within the United States. While you are welcome to visit Stripe offices for team meetings, on-sites, and events, our expectation is that you would regularly work from home. The team primarily coordinates across Eastern and Pacific time zones, with regular collaboration with stakeholders in Europe and Asia.
Compensation & Benefits

The annual US base salary range for this role is $170,400 - $255,700. This range may span multiple career levels and will be refined during the interview process based on experience, qualifications, and location.

Additional benefits include:
  • Equity participation in Stripe's growth
  • 401(k) plan with matching contributions from day one
  • Comprehensive medical, dental, and vision coverage
  • Wellness stipends
  • Annual budget for training, certifications, and conference attendance

About Stripe

Stripe is a technology company that builds economic infrastructure for the internet. Businesses of every size—from new startups to public companies—use our software to accept payments and manage their businesses online. Stripe helps new companies get started and grow their revenues, and established businesses accelerate into new markets and launch new business models. Stripe powers businesses all over the world, from the new startup that just launched yesterday to the Fortune 500 companies that we all know and love. Stripe is headquartered in San Francisco, with offices in Dublin, London, Paris, Singapore, Tokyo, and more.
Learn more about Stripe
Size
4,000 employees
Industry
Founded
2010

Similar Jobs

More Jobs at Stripe

More Information Technology Jobs

Find similar Offensive Security Engineer jobs: