安全工程师
Security Engineer
我们是谁
关于 Stripe
Stripe 是一家面向企业的金融基础设施平台。数以百万计的公司——从全球最大的企业到最具雄心的初创公司——使用 Stripe 来接受支付、增长收入并加速新的商业机会。我们的使命是提升互联网的 GDP,我们还有大量工作要做。这意味着你有机会在职业生涯中从事最重要的工作,同时让全球经济惠及每个人。
关于团队
反滥用工程团队(Abuse Control Engineering,简称 ACE)是 Stripe 的快速响应技术防御与控制孵化器。当出现紧急的滥用途径时,ACE 会利用真实的攻击者遥测数据,快速构建、测试和部署软件防护措施,防止漏洞被大规模利用。我们与欺诈、风险和产品工程团队紧密合作,进行严格的实验,在积极的风险缓解与合法用户转化之间取得平衡。作为一支突击队和孵化器,ACE 与反滥用研究团队合作,构建自动化回归套件,永久阻止威胁的重复发生,并将成熟的控制措施无缝转移给 Stripe 内部的产品负责人。
你将负责
作为反滥用工程团队(ACE)的一名反滥用控制工程师,你将设计、原型化并孵化技术防御措施,以保护 Stripe 的金融生态系统免受复杂且跨领域的滥用行为。
当新兴的威胁模式暴露出 Stripe 产品的弱点时,ACE 会迅速构建并试验技术防护措施。基于实证证据和 Stripe 的 FT3(欺诈分类 3.0)框架,你将把威胁情报转化为硬性技术控制要求(例如 API 速率限制、升级挑战、参数验证、预扣款冻结)。你将仔细平衡安全性和产品开发速度,通过实验评估风险降低与用户转化的影响。通过严格的孵化生命周期管理控制措施,你将构建自动化回归套件以防止威胁再次发生,并与原生产品团队合作,移交成熟、长期有效的防护措施。
职责
- 快速控制原型设计:在 API、协议和产品边界上设计、原型化并部署技术控制措施,以立即关闭高影响的滥用途径。
- 基于证据的技术需求:将实证攻击者证据和 FT3 威胁研究转化为技术控制需求。
查看英文原文
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE bridges the gap using real attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale. We partner closely with Fraud, Risk and Product Engineering to run rigorous experiments, balancing aggressive risk mitigation against legitimate user conversion. Operating as both a strike team and an incubator, ACE builds automated regression suites in partnership with Abuse Research to permanently block threat recurrence and seamlessly transfers mature controls to long-term product owners across Stripe.
What you’ll do
As an Abuse Control Engineer on the Abuse Control Engineering (ACE) team, you will design, prototype, and incubate technical defenses that safeguard Stripe’s financial ecosystem against complex, cross-cutting abuse vectors.
Where emerging threat patterns identify Stripe product weaknesses, ACE steps in to rapidly build and experiment with technical safeguards. Driven by empirical evidence and Stripe’s FT3 (Fraud Taxonomy 3.0) framework, you will translate threat intelligence into hard technical control requirements (e.g., API rate-limiting, step-up challenges, parameter validation, pre-debit holds). You will carefully balance security and product velocity, running experiments to evaluate risk reduction against user conversion impact. Managing controls through a strict incubation lifecycle, you will build automated regression suites to prevent recurrence and partner with native product teams to hand off mature, long-term defenses.
Responsibilities
- Rapid Control Prototyping: Design, prototype, and deploy technical controls across API, protocol, and product boundaries to immediately close high-impact abuse vectors. Evidence-Based Technical Requirements: Translate empirical attacker evidence and FT3 threat research Abuse Research, Fraud and Security into precise technical abuse requirements and control specifications.
- Control Co-Design: Collaborate closely with teams across Stripe to co-design resilient, secure controls across payment, onboarding, identity, and Connect surfaces.
- Risk Experimentation: Run rigorous experiments and A/B tests to measure risk reduction against legitimate user conversion impact, optimizing controls to minimize friction while neutralizing threats.
- Regression Testing: Build comprehensive regression testing suites and automated attack simulations with Abuse Research to ensure mitigated abuse vectors do not recur.
- Stakeholder Management: Execute ACE’s incubation model by defining handoff criteria, operational documentation, and target dates to transfer successful controls to product teams.
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 3+ years of experience in Security Engineering, Software Engineering, Application Security, or Anti-Abuse Engineering in a high-scale production environment.
- B.S. or M.S. in Computer Science, Cybersecurity, Software Engineering, or a related technical field, or equivalent practical experience.
- Strong software development background with expert proficiency in Python, Go, Java, or similar production languages, alongside expert SQL skills for analyzing system telemetry.
- Hands-on engineering experience building API-level safeguards, rate-limiting frameworks, authentication/authorization checks, or input validation controls.
- Demonstrated experience with automated testing frameworks, including writing unit, integration, and regression tests for critical backend software.
- Strong cross-functional collaboration and communication skills, with a track record of partnering across security, product, and platform teams to drive technical outcomes.
Preferred qualifications
- Proven track record of designing and executing A/B tests, evaluating control efficacy, and balancing security safeguards against user conversion friction.
- Deep expertise in threat modeling, secure system architecture, and modern application security design principles.
- Familiarity with established threat frameworks (e.g., FT3, MITRE ATT&CK) and applying adversary kill chain analysis to build resilient defenses.
- Strong domain knowledge of financial fraud vectors, threat actor TTPs, and attacker infrastructure (e.g., Account Takeover, Card Testing, Credential Stuffing).
- Hands-on experience with large-scale data processing platforms (e.g., Databricks, Trino, PySpark) to monitor and measure control performance across distributed systems.
- Demonstrated capability in incubating software features, establishing clear operational handoff criteria, and seamlessly transitioning ownership to partner engineering teams.