ARG Engineering Manager

Stripe · US - Remote · 8611 Security Analytics · listed August 10, 2026

The shape of it

Seniority
Manager
Experience asked
10+ years
Where
Remote
Requirements listed
7
Length
622 words

In the posting’s own words

The Abuse Research team is dedicated to proactively hunting for emerging abuse vectors and studying complex attacker behaviors. Rather than just reacting to alerts, the team maps complete abuse paths across Stripe products and external systems to validate novel findings and explain the underlying product conditions that enable fraud. By building continuous abuse tests with agentic testing and related systems, they translate their deep research into actionable threat advisories, strategic control recommendations, and regression scenarios that fortify Stripe’s defenses.

What it asks for · 7

  • 10+ years of experience leading security engineering or research teams, with a track record of managing technical ICs doing investigative, intelligence, or detection work.
  • B.S. or M.S. Computer Science or related field, or equivalent experience in Security
  • Experience recruiting, growing, and leading technical teams, including performance management
  • Excellent written and verbal communication skills, including the ability to develop and deliver operational or incident-related information to leadership
  • Familiarity with fraud and abuse patterns specific to payments and fintech
  • Hands-on experience with threat intelligence tradecraft: OSINT, dark web collection, actor attribution, and working with structured intelligence frameworks (ATT&CK, STIX/TAXII, or equivalent)
  • Strong understanding of threat actor tactics, techniques, and procedures (TTPs)

Also a plus

  • Background in security research, threat intelligence, or fraud detection engineering — prior experience leading or working in teams that study adversary behavior, build detection systems, or operate intelligence programs; experience in payments, fintech, or financial crime is a strong plus.
  • Technical fluency across the domains ARG works in — threat intelligence, fraud signal development, detection engineering, and OSINT.
  • Experience managing or growing technical research teams, ideally in a domain where the work is investigative, ambiguous, and doesn't map cleanly to sprint velocity.

What the job covers

  • Lead, develop, and retain a team of threat intelligence analysts, fraud researchers, and detection engineers who thrive at the intersection of adversarial research and engineering
  • Set and execute the research agenda across threat actor tracking, fraud investigation, merchant ecosystem defense, and automated detection engineering
  • Provide technical depth and analytical judgment on complex investigations, including API key takeovers, account compromise campaigns, and KYC bypass techniques
  • Operationalize research findings into production-level detection rules, automated response mechanisms, and cross-functional escalations
  • Collaborate with Risk, Trust & Safety, Fraud Platform, and Security Engineering to translate abuse research into proactive platform protections
  • Coordinate with external stakeholders, including law enforcement, to disrupt and attribute high-impact threat actors
  • Coach and mentor individual contributors to support their career development while maintaining high technical standards

Degree language

  • B.S. or M.S. Computer Science or related field, or equivalent experience in Security

Tools and skills named

Security & compliance
  • Security5×
  • KYC
Ways of working
  • Cross-functional
  • Mentorship
  • Testing
Operations & finance
  • Recruiting

Words the posting leans on

  • research11×
  • threat11×
  • fraud10×
  • detection9×
  • abuse7×
  • engineering7×
  • experience7×
  • technical7×
  • threat intelligence5×
  • investigations4×
  • requirements4×
  • abuse research3×
  • arg3×
  • detection engineering3×
  • development3×
  • findings3×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Stripe

every open role at Stripe

How this page was made

An automated read of a public job posting, fetched August 25, 2026 and last changed by Stripe on August 18, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.