Backend Engineer, Security Infrastructure
Seattle, WA or New York City
Stripe
Stripe powers online and in-person payment processing and financial solutions for businesses of all sizes. Accept payments, send payouts, and automate financial processes with a suite of APIs and no-code tools.Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
The mission of the Security Infrastructure group is to protect Stripe user data. We accomplish this by providing a platform of core security primitives that achieve uncompromising security, are consistently applied, and are simple to use. We aim to integrate security so tightly into the foundation that engineers need not worry about the security & privacy of their code.Stripe will succeed at our mission of increasing the GDP of the internet only if we prove ourselves worthy of our users’ trust.
What you’ll do
Stripe will succeed at our mission of increasing the GDP of the internet only if we prove ourselves worthy of our users’ trust. As a Software Engineer on the Security Infrastructure team, your work will be a critical part of accomplishing this mission. Together, we will build reliable, comprehensible, and observable security into Stripe's foundations, with the steady support of our leadership team and peers.
Responsibilities
- Design, build, and operate the core security infrastructure used by all of Stripe’s engineering teams
- Uphold our high engineering standards and bring consistency to the many codebases and processes you will encounter
- Improve engineering standards, tooling, and processes
We are hiring for a few different roles within Security Infrastructure, potential teams and responsibilities include:
Authorization Infrastructure (Seattle based):
- Designing, building and operating highly reliable authorization infrastructure to protect resources (e.g. services and data) at Stripe
- Providing comprehensive and easy-to-use authorization solutions to mitigate inappropriate access
- Providing continuous identity governance via access visibility and access intelligence
Secure Endpoint Access (New York based) :
- Building and operating Stripe’s zero-trust networking infrastructure to provide secure, context aware access to internal resources
- Creating fast, secure by default reverse proxies that power and protect internal services for Stripes across the globe
- Providing an exceptional user experience for Stripe engineers to create, develop and test internal services from a variety of platforms
Cloud Security (Seattle based):
- Securely expanding our usage of AWS to include 100s, and eventually 1000s, of accounts, each configured with the proper security controls and baselines
- Building paved-path tooling that enable our engineers to interface with the cloud while enforcing least-privilege and audited access
- Partnering with infrastructure teams to carefully review planned cloud deployments for cloud security best practices
- Helping to design a secure, scalable cross-account networking strategy for cloud services
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 2+ years of industry software engineering experience and systems design
- Empathy, strong communication skills and a deep respect for the power of collaboration
- A learning mindset, regardless of level or experience
- The ability to drive clear next steps when encountering ambiguous spaces without clear lines of ownership
- High standards for code quality and a constructive attitude to help others raise the bar
- Software engineering experience in a high-stakes production environment
- A knack for considering how systems can fail and how to fix them
- An ability to think creatively and holistically about reducing risk in a complex environment
Preferred qualifications
- Experience deploying and operating services in cloud environments such as AWS, Azure, or GCP
- Ability to reason about security concerns and conduct threat models in cloud environments
- Experience in IAM (Identity and Access management)
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: AWS Azure Cloud GCP Governance IAM Privacy Strategy
Perks/benefits: Career development
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Information Security Specialist jobs
- Open Senior Information Security Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Consultant SOC / CERT H/F jobs
- Open Senior Information Security Engineer jobs
- Open Information Security Officer jobs
- Open Security Operations Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Ingénieur DevSecops H/F jobs
- Open Staff Security Engineer jobs
- Open Cybersecurity Consultant jobs
- Open Senior Security Architect jobs
- Open Chief Information Security Officer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open o365 Security Architect jobs
- Open Senior Security Analyst jobs
- Open Principal Security Engineer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Product Security Engineer jobs
- Open Security Researcher jobs
- Open Cyber Security Architect jobs
- Open GCP-related jobs
- Open SOC-related jobs
- Open Risk assessment-related jobs
- Open Network security-related jobs
- Open Governance-related jobs
- Open Pentesting-related jobs
- Open ISO 27001-related jobs
- Open Analytics-related jobs
- Open CISM-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open IAM-related jobs
- Open Malware-related jobs
- Open Java-related jobs
- Open Security Clearance-related jobs
- Open Vulnerability management-related jobs
- Open CISA-related jobs
- Open DevOps-related jobs
- Open Kubernetes-related jobs
- Open Security assessment-related jobs
- Open Forensics-related jobs
- Open APIs-related jobs
- Open SQL-related jobs
- Open CI/CD-related jobs
- Open EDR-related jobs