Full-Time

Offensive Security Engineer

Posted on 8/28/2024

Stripe

Stripe

10,001+ employees

Online payment processing solutions provider

No salary listed

Senior

Remote in USA

Category
Cybersecurity
IT & Security
Required Skills
Microsoft Azure
Python
SQL
Operating Systems
AWS
Google Cloud Platform
Connection
Connection
Connection
logo

Get referrals →

You have ways to get a Stripe referral from your network.

💡

Applications through a referral are 3x more likely to get an interview!

Requirements
  • 5+ years experience in offensive security or related field
  • B.S. or M.S. Computer Science or related field, or equivalent experience
  • Proven knowledge of web application security, including vulnerabilities such as OWASP Top10
  • Experience with cloud computing platforms such as AWS, Azure, or Google Cloud Platform
  • Knowledge of Python and SQL, and familiarity with other programming languages
  • Ability to analyze and interpret application logs to identify and investigate potential security incidents
  • Excellent written and verbal communication skills, including the ability to produce clear and concise reports
  • Ability to think creatively and holistically about identifying risk in a complex environment
Responsibilities
  • Conduct complex offensive security assessments across a variety of environments, including on-premise, cloud, and mobile applications.
  • Develop scripts and tools to automate offensive security assessments
  • Provide technical expertise in areas such as network protocols, operating systems, and web application security.
  • Work closely with other members of the Stripe security team to identify and mitigate security risks and vulnerabilities.
  • Lead offensive security projects and mentor junior team members.
  • Produce clear and concise reports testing plans, engagement models, findings, risks, and recommendations for remediation
  • Keep up-to-date with the latest security threats, vulnerabilities, and attack methods.
  • Act as the subject-matter expert and primary contact for stakeholder teams invested in offensive security programs and Stripe-wide security initiatives
  • Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team

Stripe provides online payment processing solutions for internet businesses through a suite of payment APIs. These APIs enable businesses to accept and process payments easily over the internet. Stripe serves a diverse clientele, including small startups and large enterprises, across various sectors such as e-commerce, subscription services, and marketplaces. The company focuses on simplifying and securing online payments, charging fees based on the volume of transactions processed. Its offerings include core payment services, billing tools for subscriptions, solutions for managing payments in marketplaces, and additional services like fraud prevention, business financing, and identity verification. Stripe's goal is to make online transactions seamless and secure for businesses of all sizes.

Company Size

10,001+

Company Stage

Private

Total Funding

$10.6B

Headquarters

South San Francisco, California

Founded

2010

Simplify Jobs

Simplify's Take

What believers are saying

  • Stripe's partnership with Visa opens new markets in Latin America with stablecoin-linked cards.
  • Stripe's collaboration with Trifecta Technologies enhances offerings for Salesforce platform users.
  • Stripe's integration with ActionKit strengthens its position in the nonprofit sector.

What critics are saying

  • Emerging stablecoin platforms like Rain challenge Stripe's traditional payment processing model.
  • Visa's AI-powered shopping agents may reduce reliance on traditional processors like Stripe.
  • Stripe's entry into the stablecoin market could lead to regulatory scrutiny and volatility.

What makes Stripe unique

  • Stripe offers a comprehensive suite of payment APIs for online businesses.
  • Stripe's Radar provides advanced fraud prevention for ACH and SEPA payments.
  • Stripe's stablecoin product leverages its existing payment infrastructure for market leadership.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Inclusive coverage - We provide a thoughtful and balanced set of benefits that allow Stripes to be their best selves and do great work. Whether that means offering comprehensive mental, physical, and medical health plans, supporting Stripes’ financial futures, providing fertility benefits and parental leave, or making sure Stripes have access to healthy food at the office, our robust programs put Stripes and their families first.

Growth by way of learning - We are voracious learners and teachers. Our Education team delivers an onboarding and product training curriculum for all new Stripes, and hosts expert-led courses on things like project management fundamentals and macroeconomics. Beyond the formal program, Stripes are constantly sharing knowledge with each other through conversation, documentation, reading groups, and informal talks.

A principled approach to food - The food program holds a special place in Stripe’s history and future. These Stripes come to our kitchen from a breadth of backgrounds and experiences, and focus on one proposition—respect. This is apparent not only in the local ingredients they work with or in the gracious, teamwork-driven buffet lines, but also in their approach to growing a global team through sustainable food practices and minimal waste.

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-1%

2 year growth

0%
PYMNTS
May 1st, 2025
Rain Joins Visa'S Pilot Program For Stablecoin Settlement

Rain, a global card-issuing platform built for stablecoins, joined Visa’s pilot program for stablecoin settlement. By fully tokenizing its credit card receivables and transitioning all settlement transactions for its Visa cards to USDC, Rain can now settle with Visa seven days a week, 365 days a year, the companies said in a Thursday (May 1) press release. The capability enhances Rain’s ability to help its partners — FinTechs and wallets — meet the growing demand for real-time global payments by issuing and using on-chain cards and settling in stablecoins, according to the release

PYMNTS
May 1st, 2025
Rain Joins Visa’S Pilot Program For Stablecoin Settlement

Rain, a global card-issuing platform built for stablecoins, joined Visa’s pilot program for stablecoin settlement. By fully tokenizing its credit card receivables and transitioning all settlement transactions for its Visa cards to USDC, Rain can now settle with Visa seven days a week, 365 days a year, the companies said in a Thursday (May 1) press release. The capability enhances Rain’s ability to help its partners — FinTechs and wallets — meet the growing demand for real-time global payments by issuing and using on-chain cards and settling in stablecoins, according to the release

PYMNTS
May 1st, 2025
This Week In B2B: Rewiring Legacy Payment Rails With Stablecoins And Automation

Sleek tech is turbocharging the B2B space. And slow wires and clunky payment systems going the way of the fax machine couldn’t be happening at a better time for businesses. The global financial ecosystem is in flux, driven by a confluence of high-stakes innovation and mounting geopolitical tensions around trade tariffs. But B2B FinTech innovation [] The post This Week in B2B: Rewiring Legacy Payment Rails With Stablecoins and Automation appeared first on PYMNTS.com.

FF News
May 1st, 2025
Stripe Radar Now Protects Ach And Sepa Payments From Fraud

Stripe announced an expansion of Radar, Stripe’s AI-powered fraud prevention product, for ACH and SEPA payments.Radar assesses more than 1,000 characteristics of a potential transaction in order to determine, in less than 100 milliseconds, the likelihood that it’s fraudulent. On average, Radar users see a 42% reduction in SEPA fraud and a 20% reduction in ACH fraud.Ben Winfield, Radar product manager, wrote on LinkedIn:“Over the last year, we’ve seen a 40% increase in noncard payment volume on Stripe. Now, we’re extending Radar fraud protection to ACH and SEPA payments. We’ve applied the same AI architecture Radar uses for cards to new models that automatically screen and help block risky ACH and SEPA transactions.”Xero, Jobber, and FreshBooks are already using Radar’s new models

PYMNTS
Apr 30th, 2025
Visa And Bridge Partner To Enable Stablecoin-Linked Cards

Visa and Bridge have partnered to launch a card-issuing product that enables cardholders to use their stablecoin balance to make purchases at any merchant location that accepts Visa. With this collaboration, FinTech developers using Bridge — a stablecoin orchestration platform owned by Stripe — can offer stablecoin-linked Visa cards to their end customers, the companies said in a Wednesday (April 30) press release. This offering now enables the issuing of these card programs in six countries in Latin America: Argentina, Colombia, Ecuador, Mexico, Peru and Chile, according to the release

INACTIVE