4 days ago
Base Salary
$170k - $256k/yr
Responsibilities
- Conduct penetration tests across web applications, APIs, cloud environments, mobile applications, and internal infrastructure.
- Plan and execute red team, assumed-breach, and objective-based engagements that emulate real-world threat actors.
- Partner with detection engineering, threat intelligence, and incident response teams to validate controls and improve detection capabilities.
- Develop offensive tools, scripts, automation frameworks, internal platforms, payload-generation workflows, and reporting systems.
- Support incident investigations through offensive expertise, log analysis, and root cause analysis.
- Produce risk-based reports and communicate technical findings and remediation guidance to varied stakeholders.
- Lead offensive security projects, serve as a subject-matter expert, mentor junior team members, and share emerging threat research.
Requirements
- At least 5 years of experience in offensive security, penetration testing, red teaming, or a related field.
- Strong programming skills in Python, Go, or similar languages, with experience building tools, automation, or custom exploits.
- Deep knowledge of web application security, including OWASP Top 10, ASVS, injection, authentication flaws, and business logic vulnerabilities.
- Hands-on experience with AWS, Azure, or GCP, including cloud-native attack techniques and misconfigurations.
- Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, and BloodHound.
- Familiarity with MITRE ATT&CK, adversary tradecraft, and tactics including initial access, privilege escalation, lateral movement, and exfiltration.
- Strong written and verbal communication skills and the ability to translate technical findings into risk-based recommendations.
- Preferred qualifications include fintech or regulated-industry experience, vulnerability research, exploit development, CVE discovery, purple team operations, threat hunting, and incident response collaboration.
- Preferred qualifications include experience with Splunk, Databricks, PySpark, or osquery; AI/LLM-assisted development; agentic automation; AI/ML and LLM application security testing; open-source or research contributions; and certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications.
Benefits
- Remote work within the United States, with regular coordination across Eastern and Pacific time zones and collaboration with teams in Europe and Asia.
- Equity participation in Stripe's growth.
- 401(k) plan with matching contributions from day one.
- Comprehensive medical, dental, and vision coverage.
- Wellness stipends.
- Annual budget for training, certifications, and conference attendance.
About Stripe
Stripe builds financial infrastructure for internet businesses, offering APIs and tools for online and in‑person payments, subscriptions, marketplaces/payouts, fraud prevention, identity, tax, issuing, and treasury. It monetizes through per‑transaction fees and SaaS pricing for advanced products. Founded in 2010 and headquartered in South San Francisco, Stripe is privately held and serves companies from startups to large enterprises worldwide.
