Security Engineer - Threat Detection
Core
Design, build, and maintain high-fidelity detections for malicious activity across Stripe's infrastructure, applications, and cloud environments using detection-as-code practices.
Role type
Senior IC security engineer (threat detection & hunting)
Builds
Detection logic, automation workflows, and tooling for threat detection and response
Domain
Cybersecurity, Threat Intelligence, Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
detection engineering, threat hunting, adversary tradecraft analysis, malware analysis, reverse engineering, SIEM development, network/endpoint detection, telemetry analysis, detection query languages (SPL, KQL, EQL, YARA-L, SQL), Python programming
Preferred skills
fintech security experience, purple team operations, big data log analysis (Databricks, PySpark), AI/LLM-assisted development, agentic automation, detection validation tools (Atomic Red Team, ATT&CK Evaluations)
Technologies
Splunk, Chronicle, Elastic, CrowdStrike NG-SIEM, Panther, Microsoft Sentinel, AWS, GCP, Azure, Windows, Linux, macOS
Responsibilities
Design and tune detections across modern SIEM platforms covering full attack lifecycle TTPs; Conduct hypothesis-driven threat hunts to identify malicious activity and validate controls; Perform malware analysis and reverse engineering to extract indicators; Build network-based and endpoint-based detections across multiple OS platforms; Partner with Threat Intelligence to operationalize intel reports; Collaborate with IR and offensive security teams to refine detections; Build data pipelines and automation for detection-as-code; Map detection coverage to MITRE ATT&CK; Lead projects and mentor teammates
Seniority
Senior, hands-on IC with mentorship responsibilities