反滥用研究工程师
Abuse Research Engineer
我们是谁
关于 Stripe
Stripe 是一家为 businesses 提供金融基础设施的平台。数以百万计的公司——从全球最大的企业到最具雄心的初创公司——都使用 Stripe 来接受支付、增长收入并加速新的商业机会。我们的使命是提升互联网的 GDP,而我们还有大量工作要做。这意味着你有机会在职业生涯中从事最重要的工作,将全球经济带给每个人。
关于团队
反欺诈研究组(Abuse Research Group, ARG)负责在 Stripe 产品中进行主动威胁狩猎和对手行为分析。不同于被动响应警报,该团队会绘制端到端的欺诈和滥用路径,验证新型攻击向量,并识别导致欺诈的产品条件。通过代理自动化测试和模拟工具,ARG 将研究成果转化为可操作的威胁通告、战略控制建议和回归场景,系统性地消除漏洞。
你将做的事情
作为反欺诈研究组的反欺诈研究工程师,你将在主动狩猎高级威胁、剖析复杂欺诈手段并提取可操作的对手情报方面发挥关键作用。你不会仅仅依赖于被动警报,而是会在内部遥测和外部来源上开展基于假设的威胁狩猎行动,提前发现欺诈工具、战术和技巧(TTPs),防止其对 Stripe 平台造成影响。这项工作的核心是 FT3(欺诈分类 3.0),这是 Stripe 的多层分类体系,能够将复杂的欺诈分解为结构化的杀伤链。你将与反欺诈运营、策略、风险、注册和安全团队跨职能协作,整合威胁情报,构建代理模拟工作流,并系统性地消除产品漏洞。
职责
- 主动威胁狩猎与杀伤链分析:提出假设并在 Stripe 系统和外部数据上进行迭代的威胁狩猎行动。
- FT3 分类体系:在实证数据集和事件中应用并丰富 FT3 框架,标准化杀伤链各阶段和目标 API 端点的威胁情报。
- 威胁情报与信号扩展:与欺诈情报团队合作,将威胁数据源集成、整理并自动化到工程工作流中。
- 跨职能建议
查看英文原文
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
Abuse Research Group (ARG) handles proactive threat hunting and adversary behavior analysis across Stripe products. Rather than reacting to alerts, the team maps end-to-end fraud and abuse paths, validates novel attack vectors, and identifies product conditions that enable fraud. Using agentic automated testing and simulation tools, ARG translates research into actionable threat advisories, strategic control recommendations, and regression scenarios to systematically eliminate vulnerabilities.
What you’ll do
As an Abuse Research Engineer in the Abuse Research Group, you will play a critical role in safeguarding Stripe’s financial ecosystem by proactively hunting for advanced threats, dissecting complex fraud vectors, and extracting actionable adversary intelligence. Rather than relying solely on reactive alerts, you will develop and execute hypothesis-driven threat hunting operations across internal telemetry and external sources to uncover fraudulent tools, tactics, and techniques (TTPs) before they impact Stripe’s platform. Central to this work is FT3 (Fraud Taxonomy 3.0), Stripe’s multi-layered taxonomy that decomposes monolithic fraud into structured kill chains. Collaborating cross-functionally with Fraud Ops, Strategy, Risk, Onboarding, and Security, you will integrate threat intelligence, build agentic simulation workflows, and systematically eliminate product vulnerabilities.
Responsibilities
- Proactive Threat Hunting & Kill Chain Analysis: Formulate hypotheses and conduct iterative threat hunting operations across Stripe systems and external data.
- FT3 Taxonomy: Apply and enrich the FT3 framework across empirical datasets and incidents, standardizing threat intelligence across kill chain phases and targeted API endpoints.
- Threat Intelligence & Signal Expansion: Partner with teams like Fraud Intelligence to integrate, curate, and automate threat feeds into engineering workflows.
- Cross-Functional Advisories & Strategic Controls: Translate raw research and retrospective findings into actionable threat advisories and control recommendations (policy, technical systems, support workflows, and detection mechanisms) for stakeholders across Fraud, Risk, Onboarding, and Security.
- Agentic Testing & Adversary Simulation: Utilize agentic automated testing frameworks to simulate adversary TTPs, validate whether deployed controls interrupt empirical kill chains, and generate regression scenarios to exercise controls.
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 5+ years of experience conducting threat intelligence, threat hunting, or technical incident response within cyber security, product abuse, or trust domains.
- 5+ years of experience analyzing large, complex datasets using data analytics tools to identify anomalies, map behavioral trends, and solve complex fraud problems.
- B.S. or M.S. in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
- Expert proficiency in Python and SQL, with demonstrated experience using code and scripting to automate workflows, build investigative tools, or query big data pipelines.
- Hands-on experience in log analysis (e.g., application logs, API route telemetry, network security events), digital forensics, and cyber investigation methodologies.
- Strong communication skills with a proven ability to translate complex technical research into clear, actionable recommendations and advisories for cross-functional partners.
Preferred qualifications
- Deep technical understanding of threat actor motivations, infrastructure, and TTPs specific to financial fraud (e.g., ATO, Card Testing, Credential Stuffing).
- Familiarity with standardized taxonomies such as FT3 or MITRE ATT&CK.
- Proficiency with engineering, data processing, and analysis platforms such as Databricks, Trino, PySpark, Pandas, or Scikit-Learn.
- Proven background utilizing Threat Intelligence Platforms (TIPs), tactical threat feeds, OSINT, and breach intelligence.
- Demonstrated capability building or leveraging agentic LLM tools, automated testing systems, or control validation frameworks to model adversary behavior at scale.