The opportunity
The Proactive Threat team is responsible for identifying vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure — before adversaries do. We operate as a hybrid offensive function: conducting penetration testing,…
What you'll do
Conduct comprehensive penetration tests across web applications, APIs, cloud: environments (AWS/GCP/Azure), mobile applications, and internal infrastructure
Plan and execute red team engagements that emulate the TTPs of cyber and: criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios
Perform assumed-breach and objective-based assessments to test detection and: response capabilities in coordination with defensive teams
Partner with detection engineering, threat intelligence, and incident: response teams to validate security controls, identify coverage gaps, and improve detection fidelity
Contribute adversary tradecraft insights to inform detection rule: development, threat hunting hypotheses, and incident response playbooks
Support incident investigations by providing offensive expertise, log: analysis, and root cause analysis when required
What they're looking for
- + years of experience in offensive security, penetration testing, red teaming, or a related field
- Strong programming skills in Python, Go, or similar languages, with: demonstrated experience building tools, automation, or custom exploits
- Deep knowledge of web application security, including OWASP Top 10, ASVS, and: common vulnerability classes (injection, auth flaws, business logic, etc.)
- Hands-on experience with cloud platforms (AWS, Azure, or GCP), including: cloud-native attack techniques and misconfigurations
- Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic,: Sliver, BloodHound, or similar frameworks
- Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK,: including TTPs for initial access, privilege escalation, lateral movement, and exfiltration
- Excellent written and verbal communication skills, with the ability to: translate complex technical findings into clear, risk-based recommendations
- Ability to think like an adversary: creative, persistent, and able to holistically assess risk in complex environments