Abuse Research Engineer
Core
Proactively hunt for advanced threats, dissect complex fraud vectors, and extract adversary intelligence to safeguard Stripe's financial ecosystem.
Role type
Senior IC abuse research engineer (threat hunting & fraud analysis)
Builds
Actionable threat advisories, strategic control recommendations, and regression scenarios to eliminate product vulnerabilities
Domain
Cybersecurity / Financial Fraud / Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
threat hunting, kill chain analysis, threat intelligence integration, log analysis, digital forensics, cyber investigation, Python, SQL, data analytics, hypothesis-driven research, cross-functional advisory
Preferred skills
financial fraud TTPs (ATO, Card Testing, Credential Stuffing), FT3/MITRE ATT&CK taxonomies, Databricks/Trino/PySpark/Pandas/Scikit-Learn, Threat Intelligence Platforms (TIPs), OSINT, agentic LLM tools, automated testing systems
Technologies
Python, SQL, Databricks, Trino, PySpark, Pandas, Scikit-Learn, FT3, MITRE ATT&CK
Responsibilities
Formulate hypotheses and conduct iterative threat hunting operations across internal and external data; Apply and enrich the FT3 framework across empirical datasets and incidents; Integrate, curate, and automate threat feeds into engineering workflows; Translate research findings into actionable threat advisories and control recommendations; Utilize agentic automated testing frameworks to simulate adversary TTPs and validate deployed controls
Seniority
Senior, hands-on IC