Security Engineer - Proactive Threat
Stripe · Ireland · 8611 Security Analytics · listed April 17, 2026
The shape of it
Seniority
Senior
Experience asked
5+ years
Where
Hybrid
Requirements listed
8
Length
902 words
In the posting’s own words
The Proactive Threat team is responsible for identifying vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure — before adversaries do. We operate as a hybrid offensive function: conducting penetration testing, emulating real-world threat actors through red team operations, and partnering closely with our defensive security teams to validate detection capabilities and improve Stripe's overall security posture.
What it asks for · 8
- 5+ years of experience in offensive security, penetration testing, red teaming, or a related field
- Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits
- Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.)
- Hands-on experience with cloud platforms (AWS, Azure, or GCP), including cloud-native attack techniques and misconfigurations
- Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks
- Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including TTPs for initial access, privilege escalation, lateral movement, and exfiltration
- Excellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk-based recommendations
- Ability to think like an adversary — creative, persistent, and able to holistically assess risk in complex environments
Also a plus
- Experience conducting offensive security in fintech, financial services, or other highly regulated environments
- Background in vulnerability research, exploit development, or CVE discovery
- Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations)
- Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support
- Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows
- Interest or experience in agentic automation — using LLMs or autonomous agents to augment reconnaissance, vulnerability discovery, or exploitation workflows
- Experience testing AI/ML systems or LLM-based applications for security weaknesses (prompt injection, training data extraction, model manipulation, etc.)
- Contributions to open-source security tools, published research, blog posts, or conference presentations
What the job covers
- Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure
- Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios
- Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams
- Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity
- Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks
- Support incident investigations by providing offensive expertise, log analysis, and root cause analysis when required
- Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverage
- Build internal platforms and workflows that enable scalable, repeatable offensive operations
- Contribute to internal security tooling repositories and champion engineering best practices within the team
- Automate repetitive testing tasks, payload generation, and reporting workflows using modern development practices
- Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non-technical stakeholders
- Act as a subject-matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and Stripe-wide security initiatives
Tools and skills named
Security & compliance
- Security21×
- Penetration testing3×
Cloud & infra
- AWS2×
- Azure2×
- GCP2×
Ways of working
- Testing6×
Models & research
- LLM3×
- Machine learning
Data
- Databricks
- Spark
Languages
- Go
- Python
Words the posting leans on
- security21×
- offensive14×
- threat10×
- experience8×
- detection7×
- offensive security7×
- testing6×
- automation5×
- tools5×
- applications4×
- assessments4×
- capabilities4×
- cloud4×
- contribute4×
- development4×
- engineering4×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.