Security Engineer - Offensive Security

Stripe
Ireland
Workplace: OnsiteFull timeFunction: CybersecurityExperience: 5+ yearsSkills: ["Communication","Leadership","Problem-solving","Collaboration"]

Offensive Security Engineer on Stripe’s Proactive Threat team will simulate real-world attacker TTPs, perform hands-on penetration tests and red team engagements across web apps, APIs, cloud environments, and internal infrastructure, and develop custom offensive tooling. You’ll collaborate with blue teams to validate detections, influence secure product development, mentor others, and stay ahead of emerging threats while building scalable offensive platforms.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Stripe
Stripe
3 months ago

Security Engineer - Offensive Security

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 5 hours agoStatus: Live

Job Summary

Offensive Security Engineer on Stripe’s Proactive Threat team will simulate real-world attacker TTPs, perform hands-on penetration tests and red team engagements across web apps, APIs, cloud environments, and internal infrastructure, and develop custom offensive tooling. You’ll collaborate with blue teams to validate detections, influence secure product development, mentor others, and stay ahead of emerging threats while building scalable offensive platforms.
Location: Ireland
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure
  • •Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios
  • •Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams
  • •Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity
  • •Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks

Key Requirements

  • •5+ years of experience in offensive security, penetration testing, red teaming, or a related field
  • •Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits
  • •Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.)
  • •Hands-on experience with cloud platforms (AWS, Azure, or GCP), including cloud-native attack techniques and misconfigurations
  • •Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks
Experience:5+ yearsCybersecurityOffensive security
Skills:CommunicationLeadershipProblem-solvingCollaboration
Certifications:OSCPOSWEOSEPOSEDCRTOCPTSPNPTGXPNCloud security certifications
Languages:English
Tech Stack:PythonGoBurp SuiteCobalt StrikeMythicSliverBloodHoundMITRE ATT&CKAWSGCPAzureOWASP Top 10ASVS

Company Brief

Stripe
Provides payment processing APIs and financial infrastructure for internet businesses. Powers online payments for millions of companies from startups to Fortune 500s.
Industry: Payments
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Scaleup
Valuation: Decacorn (USD 10B+)
Funding: Series E+
Headquarters: San Francisco, United States
Founded: 2010
Glassdoor
Glassdoor: 4.2
WebsiteLinkedInGlassdoor