Staff Security Engineer, Abuse Control

Stripe
London
Full timeFunction: CybersecurityEducation: bachelorsSkills: ["Cross-functional collaboration","Communication","Experiment design","Risk mitigation","Evidence-based decision-making"]

Design, prototype, and incubate technical defenses on Stripe’s Abuse Control Engineering (ACE) team. Translate attacker telemetry and FT3 threat research into control requirements like API rate limits, step-up challenges, validation, and pre-debit holds. Run experiments and A/B tests to reduce abuse while minimizing conversion friction, and build automated regression suites that prevent threats from recurring—then hand off mature controls to product teams.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Stripe
Stripe
1 day ago

Staff Security Engineer, Abuse Control

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 32 minutes agoStatus: Live

Job Summary

Design, prototype, and incubate technical defenses on Stripe’s Abuse Control Engineering (ACE) team. Translate attacker telemetry and FT3 threat research into control requirements like API rate limits, step-up challenges, validation, and pre-debit holds. Run experiments and A/B tests to reduce abuse while minimizing conversion friction, and build automated regression suites that prevent threats from recurring—then hand off mature controls to product teams.
Location: London
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Rapidly prototype and deploy security controls across API, protocol, and product boundaries to address high-impact abuse vectors.
  • •Translate attacker evidence and FT3 threat research into precise abuse requirements and control specifications.
  • •Co-design resilient, secure controls across payments, onboarding, identity, and Connect surfaces with cross-functional teams.
  • •Run rigorous experiments and A/B tests to measure risk reduction versus impact on legitimate user conversion, optimizing to minimize friction.
  • •Build regression test suites and automated attack simulations, and manage ACE’s incubation lifecycle including operational handoff criteria to product teams.

Key Requirements

  • •10+ years of experience in security engineering, software engineering, application security, or anti-abuse engineering in a high-scale production environment.
  • •Bachelor’s or master’s degree in computer science, cybersecurity, software engineering, or a related technical field, or equivalent practical experience.
  • •Strong software development background with proficiency in Python, Go, Java (or similar) and advanced SQL skills for analyzing system telemetry.
  • •Experience building API-level safeguards, including rate-limiting frameworks, authentication/authorization checks, or input-validation controls.
  • •Hands-on automated testing experience, including writing unit, integration, and regression tests for critical backend software.
Education:Bachelor's
Skills:Cross-functional collaborationCommunicationExperiment designRisk mitigationEvidence-based decision-making
Tech Stack:PythonGoJavaSQLA/B testingAPI rate limitsAuthenticationAuthorizationInput validationUnit testingIntegration testingRegression testingDatabricksTrinoPySparkFT3MITRE ATT&CK

Company Brief

Stripe
Provides payment processing APIs and financial infrastructure for internet businesses. Powers online payments for millions of companies from startups to Fortune 500s.
Industry: Payments
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Scaleup
Valuation: Decacorn (USD 10B+)
Funding: Series E+
Headquarters: San Francisco, United States
Founded: 2010
Glassdoor
Glassdoor: 4.2
WebsiteLinkedInGlassdoor