安全事件响应工程师
Security Incident Response Engineer
关于Stripe
Stripe是面向企业的金融基础设施平台。数以百万计的公司——从全球最大的企业到最具雄心的初创公司——使用Stripe来接受支付、增长收入并加速新的商业机会。我们的使命是提高互联网的GDP,我们面前有大量工作要做。这意味着你有机会在职业生涯中从事最重要的工作,同时让全球经济触手可及。
关于团队
安全事件响应团队致力于在威胁影响Stripe的业务或用户之前进行分析、调查和响应。从外部攻击到内部威胁,我们的目标是以速度和精准度进行响应,进行修复,并支持事件复盘流程。该团队是分布式的,工作在多个美洲时区,会定期与欧洲、中东和亚太地区的利益相关者协调。
你会做什么
你将利用你的安全工程经验来提升Stripe的事件响应能力。重点在于用户和实体行为分析以及终端设备加固,你将深入了解Stripe的系统、工具和工作流程,以区分合法活动和恶意活动。通过威胁情报和收集的遥测数据,你将指导并构建针对Stripe的信号增强逻辑和事件响应解决方案,这些方案能随着公司的发展而扩展。最后,你的分析能力将在安全事件中至关重要,以减少不确定性,发现根本原因,并为未来的预防和检测机制提供依据。
职责
- 分析和调查发生在客户设备上的各种威胁或活动
- 为检测模型开发需求,并对现有系统进行改进
- 收集、转换并导入来自不同来源的原始数据到威胁检测管道中
- 简化事件响应能力,确保工具和流程清晰
- 与安全工程和数据科学团队跨职能合作,构建用于大规模分析安全事件数据的解决方案,保护Stripe的网络、系统和数据免受威胁
- 提供可操作的见解,以帮助识别、防止、检测和响应异常或潜在恶意的用户和实体活动
- 作为专业领域专家,成为投资于安全分析的利益相关者团队的主要联系人
查看英文原文
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
The Security Incident Response team works to analyze, investigate, and respond to threats before they impact Stripe’s business or users. From external attacks to insider threats, our goal is to respond with speed and precision, remediate, and support the incident postmortem process. The team is distributed, working across multiple AMER time zones, and will regularly coordinate with stakeholders in EMEA and APAC.
What you’ll do
You will leverage your security engineering experience to improve incident response capabilities at Stripe. With an emphasis on user and entity behavior analytics, as well as endpoint hardening, you will gain a deep understanding of Stripe’s systems, tooling, and workflows to be able to differentiate between legitimate and malicious activity. Using both threat intelligence and collected telemetry, you will guide and build Stripe-specific signals enrichment logic and incident response solutions that scale with our company. Lastly, your analytic capabilities will be critical during security incidents to reduce uncertainty, uncover root causes, and inform future prevention and detection mechanisms.
Responsibilities
- Analyze and investigate a broad range of threats or activities occurring on client devices
- Develop requirements for detection models and enhancements to existing systems
- Collect, transform, and ingest raw data from disparate sources into threat detection pipelines
- Streamline incident response capabilities, ensuring the tooling and processes are clear
- Work cross-functionally with security engineering and data science teams to build solutions for analyzing security events data at scale and protecting Stripe networks, systems, and data from threats
- Provide actionable insights to help identify, prevent, detect, and respond to anomalous or potentially malicious user and entity activity
- Act as the subject-matter expert and primary contact for stakeholder teams invested in Security Analytics and Detection programs as well as Stripe-wide security initiatives
- Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 3+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to security
- B.S. or M.S. Computer Science or related field, or equivalent experience
- Expert knowledge of Python and SQL, and familiarity with other programming languages
- Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
- Proficiency with developing and using novel analytical methods to build, automate, and improve detection and response systems
- Ability to communicate results clearly and focus on impact
- Ability to think creatively and holistically about reducing risk in a complex environment
Preferred qualifications
- An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
- Experience with software engineering, data processing and analysis tools (e.g. Databricks/Jupyter, Trino, etc.)
- Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
- Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
- Familiarity with network observability, security software, or data engineering solutions (osquery, Splunk/LogScale, etc.)
- Experience in one or more of the following areas: user and entity behavior analytics (UEBA), security information event management (SIEM), security orchestration automation and response (SOAR), or data loss prevention (DLP)