Stripe

Security Engineer - Proactive Threat

Stripe
Apply
12 hours ago
Dublin, IrelandSenior

Responsibilities

  • Conduct penetration tests across web applications, APIs, cloud environments, mobile applications, and internal infrastructure.
  • Plan and execute red team, assumed-breach, and objective-based assessments that emulate real-world adversary tactics and techniques.
  • Partner with detection engineering, threat intelligence, and incident response teams to validate controls, identify coverage gaps, and improve detection and response capabilities.
  • Provide adversary tradecraft insights for detection rules, threat-hunting hypotheses, and incident response playbooks.
  • Support incident investigations through offensive expertise, log analysis, and root cause analysis.
  • Design, develop, and maintain custom offensive tools, scripts, automation frameworks, internal platforms, and scalable workflows.
  • Automate testing, payload generation, and reporting workflows and contribute to internal security tooling repositories.
  • Produce actionable reports explaining technical findings, business risk, and remediation guidance to technical and non-technical stakeholders.
  • Serve as a subject-matter expert and stakeholder contact for offensive security programs and company-wide security initiatives.
  • Lead offensive security projects, mentor junior team members, stay current on threats and vulnerabilities, and share research internally and externally.

Requirements

  • At least 5 years of experience in offensive security, penetration testing, red teaming, or a related field.
  • Strong programming skills in Python, Go, or similar languages, with experience building tools, automation, or custom exploits.
  • Deep knowledge of web application security, including OWASP Top 10, ASVS, injection, authentication flaws, and business logic vulnerabilities.
  • Hands-on experience with AWS, Azure, or GCP, including cloud-native attack techniques and misconfigurations.
  • Proficiency with offensive tools and frameworks such as Burp Suite, Cobalt Strike, Mythic, Sliver, and BloodHound.
  • Familiarity with MITRE ATT&CK and adversary tradecraft involving initial access, privilege escalation, lateral movement, and exfiltration.
  • Strong written and verbal communication skills and the ability to translate technical findings into risk-based recommendations.
  • Preferred qualifications include fintech or regulated-industry security experience, vulnerability research, exploit development, CVE discovery, purple-team collaboration, threat hunting, and log analysis.
  • Preferred qualifications include experience with Splunk, Databricks, PySpark, osquery, AI/LLM-assisted development tools, agentic automation, and security testing of AI/ML or LLM-based applications.
  • Open-source contributions, published research, conference presentations, and certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications are valued.

Tech Stack

Categories

Stripe

About Stripe

10,000+ employees

Stripe builds financial infrastructure for internet businesses, offering APIs and tools for online and in‑person payments, subscriptions, marketplaces/payouts, fraud prevention, identity, tax, issuing, and treasury. It monetizes through per‑transaction fees and SaaS pricing for advanced products. Founded in 2010 and headquartered in South San Francisco, Stripe is privately held and serves companies from startups to large enterprises worldwide.

Contact me