Abuse Research EngineerNew

The opportunity

Abuse Research Group (ARG) handles proactive threat hunting and adversary behavior analysis across Stripe products. Rather than reacting to alerts, the team maps end-to-end fraud and abuse paths, validates novel attack vectors, and identifies product conditions that enable fraud.

What you'll do

  • Proactive Threat Hunting & Kill Chain Analysis: Formulate hypotheses and conduct iterative threat hunting operations across Stripe systems and external data.

  • FT3 Taxonomy: Apply and enrich the FT3 framework across empirical datasets and incidents, standardizing threat intelligence across kill chain phases and targeted API endpoints.

  • Threat Intelligence & Signal Expansion: Partner with teams like Fraud Intelligence to integrate, curate, and automate threat feeds into engineering workflows.

  • Cross-Functional Advisories & Strategic Controls: Translate raw research and retrospective findings into actionable threat advisories and control recommendations (policy, technical systems, support workflows, and detection mechanisms) for stakeholders across Fraud, Risk, Onboarding, and Security.

  • Agentic Testing & Adversary Simulation: Utilize agentic automated testing frameworks to simulate adversary TTPs, validate whether deployed controls interrupt empirical kill chains, and generate regression scenarios to exercise controls.

What they're looking for

  • + years of experience conducting threat intelligence, threat hunting, or: technical incident response within cyber security, product abuse, or trust domains.
  • + years of experience analyzing large, complex datasets using data analytics: tools to identify anomalies, map behavioral trends, and solve complex fraud problems.
  • B.S. or M.S. in Computer Science, Cybersecurity, or a related technical: field, or equivalent practical experience.
  • Expert proficiency in Python and SQL, with demonstrated experience using code: and scripting to automate workflows, build investigative tools, or query big data pipelines.
  • Hands-on experience in log analysis (e.g., application logs, API route: telemetry, network security events), digital forensics, and cyber investigation methodologies.
  • Strong communication skills with a proven ability to translate complex: technical research into clear, actionable recommendations and advisories for cross-functional partners.
  • Deep technical understanding of threat actor motivations, infrastructure, and: TTPs specific to financial fraud (e.g., ATO, Card Testing, Credential Stuffing).
  • Familiarity with standardized taxonomies such as FT3 or MITRE ATT&CK.