865,875open jobs
54,430companies
146,062added this week
Browse all
Salary
$170k – $256k per year
Location
Remote (United States, PT hours)
Seniority
Senior · 5+ years exp

Confirmed on the employer's own hiring board on Sep 28, 2026. First seen by Alion on Sep 25, 2026. Stripe scores B on the Alion truth index.

Overview
Company
Impact
Profile match
Stripe is a financial infrastructure company founded in 2010 by the Irish brothers Patrick and John Collison, dual-headquartered in South San Francisco and Dublin. Its APIs let businesses accept payments, run marketplaces, issue cards, manage subscriptions and handle tax and compliance without building banking integrations themselves, and it processes well over a trillion dollars of volume a year for customers ranging from startups to the largest technology companies. Beyond payments the company has expanded into treasury and issuing, revenue and finance automation, stablecoin infrastructure through its Bridge acquisition, and fraud prevention powered by its own machine learning models.

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies-from the world's largest enterprises to the most ambitious startups-use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

The Proactive Threat team is responsible for identifying vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure - before adversaries do. We operate as a hybrid offensive function: conducting penetration testing, emulating real-world threat actors through red team operations, and partnering closely with our defensive security teams to validate detection capabilities and improve Stripe's overall security posture.

We are builders first. Our team develops custom tooling, automation frameworks, and internal platforms that scale our offensive capabilities and enable repeatable, high-fidelity assessments. We believe the best offensive security engineers are equal parts hacker and engineer.

The team is distributed across the United States, primarily operating in Eastern and Pacific time zones, and collaborates regularly with security, engineering, and product stakeholders across Stripe - including teams in Europe and Asia.

What you'll do

As an Offensive Security Engineer on the Proactive Threat team, you will simulate the tactics, techniques, and procedures (TTPs) of real-world adversaries to uncover security risks across Stripe's products and infrastructure. You'll conduct hands-on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities. Your work will directly influence how Stripe builds, ships, and secures financial infrastructure used by millions of businesses worldwide.

Beyond assessments, you'll design and build offensive tooling and automation that amplifies the team's impact. You'll leverage threat intelligence to prioritize testing efforts, contribute to incident investigations when needed, and act as a subject-matter expert for security initiatives across the company.

Responsibilities

  • Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure
  • Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios
  • Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams
  • Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity
  • Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks
  • Support incident investigations by providing offensive expertise, log analysis, and root cause analysis when required
  • Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverage
  • Build internal platforms and workflows that enable scalable, repeatable offensive operations
  • Contribute to internal security tooling repositories and champion engineering best practices within the team
  • Automate repetitive testing tasks, payload generation, and reporting workflows using modern development practices
  • Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non-technical stakeholders
  • Act as a subject-matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and Stripe-wide security initiatives
  • Lead offensive security projects end-to-end, mentor junior team members, and foster a culture of continuous learning and knowledge sharing
  • Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and contribute to the broader security community

Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • 5+ years of experience in offensive security, penetration testing, red teaming, or a related field
  • Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits
  • Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.)
  • Hands-on experience with cloud platforms (AWS, Azure, or GCP), including cloud-native attack techniques and misconfigurations
  • Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks
  • Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including TTPs for initial access, privilege escalation, lateral movement, and exfiltration
  • Excellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk-based recommendations
  • Ability to think like an adversary - creative, persistent, and able to holistically assess risk in complex environments

Preferred qualifications

  • Experience conducting offensive security in fintech, financial services, or other highly regulated environments
  • Background in vulnerability research, exploit development, or CVE discovery
  • Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations)
  • Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support
  • Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows
  • Interest or experience in agentic automation - using LLMs or autonomous agents to augment reconnaissance, vulnerability discovery, or exploitation workflows
  • Experience testing AI/ML systems or LLM-based applications for security weaknesses (prompt injection, training data extraction, model manipulation, etc.)
  • Contributions to open-source security tools, published research, blog posts, or conference presentations
  • Relevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications

Location

This role is remote within the United States. While you are welcome to visit Stripe offices for team meetings, on-sites, and events, our expectation is that you would regularly work from home. The team primarily coordinates across Eastern and Pacific time zones, with regular collaboration with stakeholders in Europe and Asia.

Compensation & Benefits

The annual US base salary range for this role is $170,400 - $255,700. This range may span multiple career levels and will be refined during the interview process based on experience, qualifications, and location.

Additional benefits include:

  • Equity participation in Stripe's growth
  • 401(k) plan with matching contributions from day one
  • Comprehensive medical, dental, and vision coverage
  • Wellness stipends
  • Annual budget for training, certifications, and conference attendance
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
865,875 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
≈ $103k – $205k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Irving
Python
Ruby
PowerShell
Bash
AI/ML
Machine Learning
DevOps
Rest API
Kali Linux
Azure
AWS
Kubernetes
Linux
TCP/IP
DNS
Cybersecurity
Burp Suite
Metasploit
Nmap
ISO 27001
OWASP Top 10
PCI DSS
HIPAA
NIST 800-53
FedRAMP
Threat Modeling
OWASP
QA
Postman
Insomnia
Apply
$122k – $241k per year • Remote (United States) • Contractor • 5+ years exp • High School Diploma • Durham
PowerShell
DevOps
Azure
IAM
Cybersecurity
Microsoft Sentinel
Zscaler
Zero Trust
Microsoft Entra ID
Active Directory
Cryptography
Vault
Apply
$85k – $107k per year • Hybrid • 4+ years exp • Bachelor's Degree • Cranberry Township
Python
PowerShell
YARA
Cybersecurity
Microsoft Sentinel
YARA
Microsoft Defender
MITRE ATT&CK
SIEM
Apply
≈ $95k – $190k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Atlanta
Cybersecurity
NIST CSF
Active Directory
Management
ServiceNow
Apply
≈ $82k – $170k per year (Estimated) • In office • Full-Time • 3+ years exp • Atlanta
AI/ML
Anomaly Detection
DevOps
Linux
Cybersecurity
ISO 27001
HIPAA
SIEM
Apply
$197k – $225k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • New York • McLean • Cambridge • Richmond
Python
JavaScript
Rust
TypeScript
C#
Node JS
Scala
DevOps
GCP
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Bitbucket
GitHub
Management
Agile
Apply
$179k – $205k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • San Jose • McLean • Cambridge • San Francisco • New York
Python
JavaScript
Rust
TypeScript
C#
Node JS
Scala
DevOps
GCP
Azure
CI/CD
Git
AWS
Docker
Kubernetes
Bitbucket
GitHub
Management
Agile
Apply
≈ $52k – $125k per year (Estimated) • In office • Riyadh
DevOps
Azure
AWS
Apply
≈ $52k – $125k per year (Estimated) • In office • Jeddah
DevOps
Azure
AWS
Apply
Databricks/Python/AWS 12 hours ago
Hybrid • Full-Time • Chennai
Python
SQL
Python
pySpark
Databases
Databricks
AI/ML
Spark
DevOps
Azure DevOps
Azure
CI/CD
AWS
Apply
Security Engineer 3 days ago
≈ $129k – $249k per year (Estimated) • Remote (United States) • 3+ years exp • Bachelor's Degree
Python
Go
Java
SQL
Python
pySpark
Databases
Databricks
Trino
AI/ML
Spark
Cybersecurity
Cyber Kill Chain
Threat Modeling
Analytics
A/B Testing
Management
Stripe
Apply
≈ $202k – $384k per year (Estimated) • Remote (United States, European time zones hours) • 10+ years exp • Bachelor's Degree • Seattle
Python
JavaScript
SQL
Node JS
Python
pySpark
Node JS
Commander.js
Databases
Databricks
Trino
AI/ML
Spark
AI Agents
Pandas
Management
Stripe
Apply
≈ $161k – $364k per year (Estimated) • In office • New York
Python
JavaScript
Ruby
Frontend
React.js
DevOps
GCP
CI/CD
AWS
IAM
Management
Stripe
Apply
≈ $137k – $282k per year (Estimated) • In office • 4+ years exp • New York
Go
Swift
Objective-C
DevOps
AWS
Platform Engineering
Linux
Windows
DNS
Management
Stripe
Apply
≈ $157k – $356k per year (Estimated) • In office • Seattle
AI/ML
AI Agents
LLM Guardrails
DevOps
GCP
Azure
AWS
Kubernetes
IAM
Linux
Cybersecurity
Threat Modeling
Management
Stripe
Apply
See all jobs
This is one of many
865,875 more open roles from verified company boards, updated every day.