The opportunity
Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data…
What you'll do
Lead fraud and abuse incident response end-to-end as Incident Response: Manager (IRM), coordinating workstreams, investigating high risk activity and accounts, and making actionable mitigation recommendations under pressure.
Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card: testing), utilizing FT3-mapped (Fraud Taxonomy 3.0) detection and signals enrichment to reduce uncertainty and accelerate response.
As part of incidents, analyze high-risk accounts to identify fraudulent: merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.
Develop, document, and execute incident response strategies, runbooks, and: capabilities to continuously improve fraud and abuse detection and prevention.
Partner cross-functionally with security, data science, legal, and policy: teams to build agentic response solutions, refine KPIs, and deliver clear incident reporting.
Mentor teammates, lead key incident response engineering projects, and: elevate quality standards across the team.
What they're looking for
- + years of experience leading security or fraud incident response;
- B.S./M.S. in Computer Science or equivalent experience.
- Expert knowledge of Python and SQL, and familiarity with other programming languages
- Existing experience with log analysis (e.g. first or third party: applications, system / data access, event logs), network security, digital forensics, and incident response investigations
- Proven ability to build automated response workflows, leverage threat: intelligence, and make risk mitigation recommendations.
- Strong written and verbal communication skills with a track record of driving: cross-functional alignment with minimal oversight.
- Broad expertise across fraud and abuse mitigation, risk management, product: trust, and threat intelligence in a complex platform environment.
- An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.