Offensive Security Engineer
Core
Simulate adversary tactics to uncover security risks across Stripe's financial infrastructure via penetration testing, red teaming, and tool development.
Role type
Senior IC offensive security engineer (red team/pentester)
Builds
Custom offensive tooling, automation frameworks, and internal platforms for scalable security assessments
Domain
Financial services / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing, red teaming, Python/Go programming, cloud security (AWS/GCP/Azure), adversary tradecraft (MITRE ATT&CK), exploit development, threat intelligence analysis, incident investigation support, tool automation, technical reporting
Preferred skills
Fintech offensive security experience, vulnerability research, CVE discovery, purple team operations, big data log analysis (Splunk/PySpark), AI/LLM-assisted development, agentic automation, AI/ML system security testing, open-source security contributions
Technologies
Python, Go, Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, MITRE ATT&CK, AWS, Azure, GCP, Splunk, Databricks, PySpark, osquery, Claude Code, Cursor, GitHub Copilot
Responsibilities
Conduct comprehensive penetration tests across web apps, APIs, cloud environments, and mobile applications; execute red team engagements emulating real-world threat actors; design and build custom offensive tools and automation frameworks; partner with defensive teams to validate detection capabilities; contribute adversary insights to detection rule development; support incident investigations with offensive expertise; produce actionable risk reports for technical and non-technical stakeholders; mentor junior team members and share threat research
Seniority
Senior, hands-on IC