Abuse Research Engineer
Core
Proactively hunt for advanced threats, dissect complex fraud vectors, and extract adversary intelligence to safeguard Stripe's financial ecosystem.
Role type
Senior IC abuse research engineer (threat hunting & fraud analysis)
Builds
Actionable threat advisories, strategic control recommendations, and regression scenarios to eliminate product vulnerabilities.
Domain
Cybersecurity, financial fraud, threat intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
threat hunting, kill chain analysis, threat intelligence, data analytics, Python, SQL, log analysis, digital forensics, cyber investigation
Preferred skills
financial fraud TTPs (ATO, Card Testing, Credential Stuffing), FT3/MITRE ATT&CK taxonomies, Databricks/Trino/PySpark/Pandas/Scikit-Learn, Threat Intelligence Platforms (TIPs), OSINT, agentic LLM tools, automated testing systems
Technologies
Python, SQL, Databricks, Trino, PySpark, Pandas, Scikit-Learn, FT3, MITRE ATT&CK
Responsibilities
Formulate hypotheses and conduct iterative threat hunting operations across Stripe systems and external data; Apply and enrich the FT3 framework across empirical datasets and incidents; Partner with teams to integrate, curate, and automate threat feeds into engineering workflows; Translate raw research and retrospective findings into actionable threat advisories and control recommendations; Utilize agentic automated testing frameworks to simulate adversary TTPs and validate deployed controls.
Seniority
Senior, hands-on IC