Cloud Security Engineer

Stripe · Seattle · 8614 Office of the CISO & Partnership · listed May 4, 2026

The shape of it

Seniority
Not stated
Where
Not stated
Requirements listed
8
Length
654 words

In the posting’s own words

The Cloud Security team accelerates Stripe's business priorities by building core security controls and services that empower teams to build quickly and securely on top of a well-governed cloud platform and partnering with infrastructure teams to advance select critical business priorities using novel infrastructure or integrations as that platform expands.

What it asks for · 8

  • Empathy, strong communication skills, and a deep respect for the power of collaboration
  • A learning mindset, regardless of level or experience
  • The ability to drive clear next steps when encountering ambiguous spaces without clear lines of ownership
  • High standards for code quality and a constructive attitude to help others raise the bar
  • Software engineering experience in a high-stakes production environment
  • A knack for considering how systems can fail and how to fix them
  • An ability to think creatively and holistically about reducing risk in a complex environment
  • Experience with security on one or more of AWS, Azure, or GCP

Also a plus

  • Experience conducting threat modeling of software or infrastructure in cloud-native environments
  • Experience with Linux systems, Kubernetes, and container-based platforms
  • Prior usage of security monitoring tools (e.g., CSPM, CNAAP)
  • Experience in a multi-cloud or complex cloud environment
  • A knack for considering how systems can fail and how to fix them
  • An ability to think creatively and holistically about reducing risk in a complex environment

What the job covers

  • Design, build, and operate the core security infrastructure used by all of Stripe's engineering teams in close collaboration with other stakeholders and our users
  • Uphold our high engineering standards and bring consistency to the many codebases and processes you'll encounter
  • Contribute to team learning by improving engineering standards, tooling, and processes
  • Design and build durable solutions that will advance Stripe's security beyond the state of the art
  • Help expand Stripe's cloud footprint on top of secure, paved roads and guardrails
  • Optimize for security controls that have delightful user experiences
  • Partner closely with infrastructure and engineering teams building integrations with our cloud infrastructure or adopting new cloud managed services
  • Make impactful decisions about systems and security—their edge cases, failure modes, and life cycles
  • Use data to determine appropriate baselines against which to measure security
  • Define infrastructure that reliably feeds signals to threat teams
  • Evaluate and prototype new security tools and practices
  • Designing and implementing controls that support security invariants and enforce our security principles while providing a surprisingly great user experience

Tools and skills named

Security & compliance
  • Security11×
  • IAM
  • Threat modeling
Cloud & infra
  • AWS
  • Azure
  • GCP
  • Kubernetes
  • Linux
Product & design
  • User experience

Words the posting leans on

  • security11×
  • experience8×
  • cloud7×
  • infrastructure6×
  • engineering5×
  • systems4×
  • tooling3×
  • user3×
  • access2×
  • build2×
  • clear2×
  • collaboration2×
  • considering2×
  • design2×
  • engineering standards2×
  • fail2×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Stripe

every open role at Stripe

How this page was made

An automated read of a public job posting, fetched August 24, 2026 and last changed by Stripe on August 18, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.