Stripe logo
Stripe
Posted 25 days agoVerified live 2d ago

Security Engineer

Brief overview

Remote
MastersOr in progress
3+ yrsMinimum
694 H-1B approvalsDept. of Labor
302 green cardsCertified filings
PythonGoJavaSQLAPI Security ControlsRate LimitingAuthentication and AuthorizationInput ValidationAutomated Software TestingA/B TestingThreat ModelingSecure System Architecture

About the company

Stripe is an API technology company that provides online payment processing and commerce solutions for Internet businesses.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
694H-1B approved
98%approval rate
112new H-1B hires
302PERM certified
$172,744median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
2023149
2024265
2025211
202669
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
202342
202486
202558
202641
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
202372
202447
2025170
202613
Top sponsored roles
Software EngineerBackend/API EngineerBackend / API EngineerProduct ManagerData Analyst
Sponsored employees from
IndiaChinaCanadaUnited KingdomSouth Africa

Job description

Summary

Stripe is a financial infrastructure platform for businesses. The Security Engineer on the Abuse Control Engineering team designs, prototypes, and incubates technical defenses against complex abuse vectors. The role translates threat intelligence into technical controls, runs risk experiments, builds regression testing suites, and transitions mature defenses to product teams.

Responsibilities

  • **Rapid Control Prototyping:** Design, prototype, and deploy technical controls across API, protocol, and product boundaries to immediately close high-impact abuse vectors. **Evidence-Based Technical Requirements:** Translate empirical attacker evidence and FT3 threat research Abuse Research, Fraud and Security into precise technical abuse requirements and control specifications
  • **Control Co-Design:** Collaborate closely with teams across Stripe to co-design resilient, secure controls across payment, onboarding, identity, and Connect surfaces
  • **Risk Experimentation:** Run rigorous experiments and A/B tests to measure risk reduction against legitimate user conversion impact, optimizing controls to minimize friction while neutralizing threats
  • **Regression Testing:** Build comprehensive regression testing suites and automated attack simulations with Abuse Research to ensure mitigated abuse vectors do not recur
  • **Stakeholder Management:** Execute ACE’s incubation model by defining handoff criteria, operational documentation, and target dates to transfer successful controls to product teams

Skills

  • 3+ years of experience in Security Engineering, Software Engineering, Application Security, or Anti-Abuse Engineering in a high-scale production environment
  • B.S. or M.S. in Computer Science, Cybersecurity, Software Engineering, or a related technical field, or equivalent practical experience
  • Strong software development background with expert proficiency in Python, Go, Java, or similar production languages, alongside expert SQL skills for analyzing system telemetry
  • Hands-on engineering experience building API-level safeguards, rate-limiting frameworks, authentication/authorization checks, or input validation controls
  • Demonstrated experience with automated testing frameworks, including writing unit, integration, and regression tests for critical backend software
  • Strong cross-functional collaboration and communication skills, with a track record of partnering across security, product, and platform teams to drive technical outcomes
  • Proven track record of designing and executing A/B tests, evaluating control efficacy, and balancing security safeguards against user conversion friction
  • Deep expertise in threat modeling, secure system architecture, and modern application security design principles
  • Familiarity with established threat frameworks (e.g., FT3, MITRE ATT&CK) and applying adversary kill chain analysis to build resilient defenses
  • Strong domain knowledge of financial fraud vectors, threat actor TTPs, and attacker infrastructure (e.g., Account Takeover, Card Testing, Credential Stuffing)
  • Hands-on experience with large-scale data processing platforms (e.g., Databricks, Trino, PySpark) to monitor and measure control performance across distributed systems
  • Demonstrated capability in incubating software features, establishing clear operational handoff criteria, and seamlessly transitioning ownership to partner engineering teams

Qualifications

Must Haves

  • 3+ years of experience in Security Engineering, Software Engineering, Application Security, or Anti-Abuse Engineering in a high-scale production environment
  • B.S. or M.S. in Computer Science, Cybersecurity, Software Engineering, or a related technical field, or equivalent practical experience
  • Strong software development background with expert proficiency in Python, Go, Java, or similar production languages, alongside expert SQL skills for analyzing system telemetry
  • Hands-on engineering experience building API-level safeguards, rate-limiting frameworks, authentication/authorization checks, or input validation controls
  • Demonstrated experience with automated testing frameworks, including writing unit, integration, and regression tests for critical backend software
  • Strong cross-functional collaboration and communication skills, with a track record of partnering across security, product, and platform teams to drive technical outcomes

Nice to Haves

  • Proven track record of designing and executing A/B tests, evaluating control efficacy, and balancing security safeguards against user conversion friction
  • Deep expertise in threat modeling, secure system architecture, and modern application security design principles
  • Familiarity with established threat frameworks (e.g., FT3, MITRE ATT&CK) and applying adversary kill chain analysis to build resilient defenses
  • Strong domain knowledge of financial fraud vectors, threat actor TTPs, and attacker infrastructure (e.g., Account Takeover, Card Testing, Credential Stuffing)
  • Hands-on experience with large-scale data processing platforms (e.g., Databricks, Trino, PySpark) to monitor and measure control performance across distributed systems
  • Demonstrated capability in incubating software features, establishing clear operational handoff criteria, and seamlessly transitioning ownership to partner engineering teams

More jobs like this