Security Engineer, Offensive Security
Remote, North America
Stripe
Stripe powers online and in-person payment processing and financial solutions for businesses of all sizes. Accept payments, send payouts, and automate financial processes with a suite of APIs and no-code tools.Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
The team performs offensive security assessments and penetration testing to identify vulnerabilities and weaknesses in Stripe's systems, applications, and networks before they impact Stripe’s business or users. We partner with other Stripe teams to defend against external attacks and respond to security incidents. The team is distributed, working primarily in Eastern and Pacific time zones, and will regularly coordinate with stakeholders in Europe and Asia.
What you’ll do
Using your security expertise, you'll uncover security weaknesses within Stripe by simulating the tactics, techniques, and procedures (TTPs) of real-world adversaries. This will involve utilizing both threat intelligence and collected telemetry to emulate cyber and criminal threat actors who may target Stripe. Lastly, your analytic capabilities will be critical during security incidents to reduce uncertainty, uncover root causes, and inform future prevention and detection mechanisms.
Responsibilities
- Conduct complex offensive security assessments across a variety of environments, including on-premise, cloud, and mobile applications.
- Develop scripts and tools to automate offensive security assessments.
- Provide technical expertise in areas such as network protocols, operating systems, and web application security.
- Work closely with other members of the Stripe security team to identify and mitigate security risks and vulnerabilities.
- Lead offensive security projects and mentor junior team members.
- Produce clear and concise reports testing plans, engagement models, findings, risks, and recommendations for remediation.
- Keep up-to-date with the latest security threats, vulnerabilities, and attack methods.
- Act as the subject-matter expert and primary contact for stakeholder teams invested in offensive security programs and Stripe-wide security initiatives.
- Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team.
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement
Minimum requirements
- 5+ years experience in offensive security or related field.
- B.S. or M.S. Computer Science or related field, or equivalent experience.
- Proven knowledge of web application security, including vulnerabilities such as OWASP Top10.
- Experience with cloud computing platforms such as AWS, Azure, or Google Cloud Platform.
- Knowledge of Python and SQL, and familiarity with other programming languages.
- Ability to analyze and interpret application logs to identify and investigate potential security incidents.
- Excellent written and verbal communication skills, including the ability to produce clear and concise reports.
- Ability to think creatively and holistically about identifying risk in a complex environment.
Preferred qualifications
- Experience in conducting offensive security activities in the fintech or financial sectors.
- An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
- Experience partnering with threat intelligence and incident response teams to perform log analysis, digital forensics, and incident response investigations.
- Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.).
- Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.).
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security AWS Azure Big Data Cloud Computer Science Databricks FinTech Forensics GCP Incident response Log analysis Offensive security OWASP Pentesting Python Security assessment SQL Threat intelligence TTPs Vulnerabilities
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Senior Security Analyst jobs
- Open Information Security Specialist jobs
- Open Senior Cyber Security Engineer jobs
- Open Manager Pentest H/F jobs
- Open Cyber Security Specialist jobs
- Open Staff Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Principal Security Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Product Security Engineer jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open IT Security Analyst jobs
- Open Cybersecurity Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open Cybersecurity Consultant jobs
- Open Chief Information Security Officer jobs
- Open Senior Information Security Engineer jobs
- Open Security Specialist jobs
- Open Cybersecurity Specialist jobs
- Open Senior Penetration Tester jobs
- Open Security Researcher jobs
- Open Sr. Security Engineer jobs
- Open Senior Security Architect jobs
- Open IT Security Engineer jobs
- Open Clearance-related jobs
- Open Windows-related jobs
- Open ISO 27001-related jobs
- Open Application security-related jobs
- Open Network security-related jobs
- Open Agile-related jobs
- Open Pentesting-related jobs
- Open Vulnerability management-related jobs
- Open GCP-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open Analytics-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Java-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open IDS-related jobs
- Open Security Clearance-related jobs
- Open Malware-related jobs
- Open Kubernetes-related jobs
- Open EDR-related jobs
- Open CEH-related jobs
- Open IPS-related jobs