The opportunity
Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE uses real-world attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale.
What you'll do
Rapid control prototyping: Design, prototype, and deploy technical controls across API, protocol, and product boundaries to address high-impact abuse vectors.
Evidence-based technical requirements: Translate empirical attacker evidence and FT3 threat research from Abuse Research, Fraud, and Security teams into precise technical abuse requirements and control specifications.
Control co-design: Collaborate with teams across Stripe to design resilient, secure controls across payments, onboarding, identity, and Connect surfaces.
Risk experimentation: Run rigorous experiments and A/B tests to measure risk reduction against the impact on legitimate user conversion, optimizing controls to minimize friction while neutralizing threats.
Regression testing: Build comprehensive regression test suites and automated attack simulations with Abuse Research to ensure mitigated abuse vectors do not recur.
Stakeholder management: Execute ACE’s incubation model by defining handoff criteria, operational documentation, timelines, and target dates for transferring successful controls to product teams.
What they're looking for
- + years of experience in security engineering, software engineering,: application security, or anti-abuse engineering in a high-scale production environment.
- A bachelor’s or master’s degree in computer science, cybersecurity, software: engineering, or a related technical field, or equivalent practical experience.
- A strong software development background, with proficiency in Python, Go,: Java, or a similar production programming language, as well as advanced SQL skills for analyzing system telemetry.
- Experience using frontier AI models for software development, learning, and analysis.
- Hands-on experience building API-level safeguards, rate-limiting frameworks,: authentication or authorization checks, or input-validation controls.
- Experience with automated testing frameworks, including writing unit,: integration, and regression tests for critical backend software.
- Strong cross-functional collaboration and communication skills, with a track: record of partnering across security, product, and platform teams to drive technical outcomes.
- A track record of designing and executing A/B tests, evaluating control: efficacy, and balancing security safeguards against user conversion friction.