Security Engineer - Offensive SecurityNew

Hybrid · IrelandFinance

The opportunity

The Proactive Threat team is responsible for identifying vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure — before adversaries do. We operate as a hybrid offensive function: conducting penetration testing,…

What you'll do

  • Conduct comprehensive penetration tests across web applications, APIs, cloud: environments (AWS/GCP/Azure), mobile applications, and internal infrastructure

  • Plan and execute red team engagements that emulate the TTPs of cyber and: criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios

  • Perform assumed-breach and objective-based assessments to test detection and: response capabilities in coordination with defensive teams

  • Partner with detection engineering, threat intelligence, and incident: response teams to validate security controls, identify coverage gaps, and improve detection fidelity

  • Contribute adversary tradecraft insights to inform detection rule: development, threat hunting hypotheses, and incident response playbooks

  • Support incident investigations by providing offensive expertise, log: analysis, and root cause analysis when required

What they're looking for

  • + years of experience in offensive security, penetration testing, red teaming, or a related field
  • Strong programming skills in Python, Go, or similar languages, with: demonstrated experience building tools, automation, or custom exploits
  • Deep knowledge of web application security, including OWASP Top 10, ASVS, and: common vulnerability classes (injection, auth flaws, business logic, etc.)
  • Hands-on experience with cloud platforms (AWS, Azure, or GCP), including: cloud-native attack techniques and misconfigurations
  • Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic,: Sliver, BloodHound, or similar frameworks
  • Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK,: including TTPs for initial access, privilege escalation, lateral movement, and exfiltration
  • Excellent written and verbal communication skills, with the ability to: translate complex technical findings into clear, risk-based recommendations
  • Ability to think like an adversary: creative, persistent, and able to holistically assess risk in complex environments
Security Engineer - Offensive Security at Stripe | Role Match