Offensive Security Engineer, Stripe

$163.1-244.7k

SQL
AWS
Python
Splunk
Azure
Pandas
Senior level
Remote in US
Stripe

A financial infrastructure platform for businesses

Be an early applicant

Stripe

A financial infrastructure platform for businesses

1001+ employees

FintechB2BPaymentsCredit cardsFinancial Services

Be an early applicant

$163.1-244.7k

SQL
AWS
Python
Splunk
Azure
Pandas
Senior level
Remote in US

1001+ employees

FintechB2BPaymentsCredit cardsFinancial Services

Company mission

To increase the GDP of the internet

Role

Who you are

  • 5+ years experience in offensive security or related field
  • B.S. or M.S. Computer Science or related field, or equivalent experience
  • Proven knowledge of web application security, including vulnerabilities such as OWASP Top10
  • Experience with cloud computing platforms such as AWS, Azure, or Google Cloud Platform
  • Knowledge of Python and SQL, and familiarity with other programming languages
  • Ability to analyze and interpret application logs to identify and investigate potential security incidents
  • Excellent written and verbal communication skills, including the ability to produce clear and concise reports
  • Ability to think creatively and holistically about identifying risk in a complex environment

Desirable

  • Experience in conducting offensive security activities in the fintech or financial sectors
  • An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors
  • Experience partnering with threat intelligence and incident response teams to perform log analysis, digital forensics, and incident response investigations
  • Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
  • Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
  • Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
  • Familiarity with network observability, security software, or data engineering solutions (osquery, Splunk, etc.)

What the job involves

  • The Attacker Engineering team performs offensive security assessments and penetration testing to identify vulnerabilities and weaknesses in Stripe's systems, applications, and networks before they impact Stripe’s business or users
  • We partner with other Stripe teams to defend against external attacks and respond to security incidents. The team is distributed, working primarily in Eastern and Pacific time zones, and will regularly coordinate with stakeholders in Europe and Asia
  • Using your security expertise, you'll uncover security weaknesses within Stripe by simulating the tactics, techniques, and procedures (TTPs) of real-world adversaries. This will involve utilizing both threat intelligence and collected telemetry to emulate cyber and criminal threat actors who may target Stripe
  • Astly, your analytic capabilities will be critical during security incidents to reduce uncertainty, uncover root causes, and inform future prevention and detection mechanisms
  • Conduct complex offensive security assessments across a variety of environments, including on-premise, cloud, and mobile applications
  • Develop scripts and tools to automate offensive security assessments
  • Provide technical expertise in areas such as network protocols, operating systems, and web application security
  • Work closely with other members of the Stripe security team to identify and mitigate security risks and vulnerabilities
  • Lead offensive security projects and mentor junior team members
  • Produce clear and concise reports testing plans, engagement models, findings, risks, and recommendations for remediation
  • Keep up-to-date with the latest security threats, vulnerabilities, and attack methods
  • Act as the subject-matter expert and primary contact for stakeholder teams invested in offensive security programs and Stripe-wide security initiatives
  • Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team

Our take

Stripe, nowadays a FinTech giant, spent the first few years since its founding building up its payments business, which primarily consisted of providing an API to eCommerce businesses so that they could easily integrate a payments option in their apps or websites, where before there was none.

More recently, Stripe has started to accelerate its growth with a significantly larger range of financial services including cash advances and credit cards. They also plan to build incorporation services, fraud protection, and more, diversifying its revenue away from payments and differentiating itself from its competitors.

To further expand its position, the company is looking to triple its presence in Ireland, and extend its services to countries with vast customer potential, including Brazil and India. Its latest venture, coming atop significant new funds, is to partner with OpenAI, the company behind ChatGPT - a win-win collaboration that will monetize OpenAI’s flagship products and at the same time enhance Stripe with GPT-4, as it moves forwards with intentions to "build the payments foundation for tomorrow's AI economy."

Freddie headshot

Freddie

Company Specialist

Insights

Top investors

Some candidates hear
back within 2 weeks

-5% employee growth in 12 months

Company

Funding (last 2 of 13 rounds)

Mar 2023

$6.5bn

GROWTH EQUITY VC

Mar 2021

$600m

SERIES H

Total funding: $8.7bn

Company benefits

  • Unlimited paid time off policy
  • Work from home opportunities
  • Comprehensive mental, physical and medical health plans
  • Fertility benefits and parental leave

Company values

  • Built for builders - The best reason to work at Stripe is that you will have colleagues who support and challenge you to do the best work of your career. We combine a big-picture mindset with obsessive attention to the details, down to the last pixel, API parameter, and word.
  • An environment of growth - We care about results more than CVs. We value managers who remain experts while developing talent and designing successful orgs. You can also have a big impact and advance far without managing anyone. We want you to take what you’ve been hired to do, and show us how it’s done – you might create something we never would have imagined. We have had account managers start a publishing arm, interns who have run business units, and hackathon participants who have built company-defining products.
  • Fast-paced, detail oriented - We balance innovation with scrupulous attention to every bit and byte involved in the movement of money – because we can’t do our job well unless we do both. When we started, we emailed every API error to everyone at the company. Now, we have more than 250 million API requests a day – and we still care about each one.
  • Voraciously curious - We wish there was a book that described what we need to do next (we’d even publish it), but since there isn’t, we all have to write it together. You will need to find answers to questions you’ve never been asked before. Sometimes, you will be the first person ever to contemplate a particular problem. We want people who devour books for fun and approach new challenges with eager curiosity.

Company HQ

SoMa, San Francisco, CA

Leadership

Patrick Collison

(Content Strategist)

Studied maths at MIT before founding Stripe. Also on the board of the Long Now Foundation.

John Collison

(President)

Studied at Harvard but dropped out to found Stripe.

Share this job

View 199 more jobs at Stripe