Staff Security Engineer, Abuse ControlNew

The opportunity

Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE uses real-world attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale.

What you'll do

  • Rapid control prototyping: Design, prototype, and deploy technical controls across API, protocol, and product boundaries to address high-impact abuse vectors.

  • Evidence-based technical requirements: Translate empirical attacker evidence and FT3 threat research from Abuse Research, Fraud, and Security teams into precise technical abuse requirements and control specifications.

  • Control co-design: Collaborate with teams across Stripe to design resilient, secure controls across payments, onboarding, identity, and Connect surfaces.

  • Risk experimentation: Run rigorous experiments and A/B tests to measure risk reduction against the impact on legitimate user conversion, optimizing controls to minimize friction while neutralizing threats.

  • Regression testing: Build comprehensive regression test suites and automated attack simulations with Abuse Research to ensure mitigated abuse vectors do not recur.

  • Stakeholder management: Execute ACE’s incubation model by defining handoff criteria, operational documentation, timelines, and target dates for transferring successful controls to product teams.

What they're looking for

  • + years of experience in security engineering, software engineering,: application security, or anti-abuse engineering in a high-scale production environment.
  • A bachelor’s or master’s degree in computer science, cybersecurity, software: engineering, or a related technical field, or equivalent practical experience.
  • A strong software development background, with proficiency in Python, Go,: Java, or a similar production programming language, as well as advanced SQL skills for analyzing system telemetry.
  • Experience using frontier AI models for software development, learning, and analysis.
  • Hands-on experience building API-level safeguards, rate-limiting frameworks,: authentication or authorization checks, or input-validation controls.
  • Experience with automated testing frameworks, including writing unit,: integration, and regression tests for critical backend software.
  • Strong cross-functional collaboration and communication skills, with a track: record of partnering across security, product, and platform teams to drive technical outcomes.
  • A track record of designing and executing A/B tests, evaluating control: efficacy, and balancing security safeguards against user conversion friction.