The opportunity
Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data…
What you'll do
Respond to live fraud and abuse incidents as a Forward Deployed Security: Engineer, investigating high-risk activity, neutralizing active attacks, and mitigating security risks across the ecosystem.
Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card: testing), utilizing FT3-mapped (Fraud Taxonomy 3.0) detection and signals enrichment to reduce uncertainty and accelerate response.
As part of incidents, analyze high-risk accounts to identify fraudulent: merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.
Develop, document, and execute incident response strategies, runbooks, and: capabilities to continuously improve fraud and abuse detection and prevention.
Act as a dedicated technical bridge during and after incidents to work: directly with impacted merchants and customers, helping them investigate root causes, remediate vulnerabilities, and secure their accounts.
Serve as an operational and technical liaison for legal teams, policy: partners, and threat intelligence communities.
What they're looking for
- + years of experience leading security or fraud incident response;
- B.S./M.S. in Computer Science or equivalent experience.
- Expert knowledge of Python and SQL, and familiarity with other programming languages
- Existing experience with log analysis (e.g. first or third party: applications, system / data access, event logs), network security, digital forensics, and incident response investigations
- Proven ability to build automated response workflows, leverage threat: intelligence, and make risk mitigation recommendations.
- Strong written and verbal communication skills with a track record of driving: cross-functional alignment with minimal oversight.
- Previous work with law enforcement
- Engagement in threat intelligence sharing communities