Abuse Investigator

Stripe · Dublin · 8611 Security Analytics · listed September 3, 2026

The shape of it

Seniority
Mid level
Experience asked
3+ years
Where
Not stated
Requirements listed
7
Length
628 words

In the posting’s own words

Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve technical incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.

What it asks for · 7

  • 3+ years of experience conducting incident response in security, product abuse or trust domains
  • 3+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to fraud detection
  • B.S. or M.S. Computer Science or related field, or equivalent experience
  • Expert knowledge of Python and SQL, and familiarity with other programming languages
  • Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
  • Ability to communicate results clearly and focus on impact
  • Ability to think creatively and holistically about reducing risk in a complex environment

Also a plus

  • An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
  • Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
  • Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
  • Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
  • Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges

What the job covers

  • Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped detection and signals enrichment to reduce uncertainty and accelerate response.
  • As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 (Fraud Taxonomy 3.0) to standardize threat intelligence.
  • Lead incident root cause analyses to identify gaps in current systems and strategies, leveraging the FT3 framework, data-driven model to drive enhancements and process improvements for emerging fraud risks.
  • Streamline incident response capabilities, ensuring the tooling and processes are clear, accurate and efficient
  • Work cross-functionally with security, fraud and data science teams to build agentic solutions for responding to abuse incidents at scale
  • Effectively communicate cross-functionally with legal and policy teams to assess and mitigate risks, while demonstrating strong problem-solving under pressure.
  • Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team

Degree language

  • B.S. or M.S. Computer Science or related field, or equivalent experience

Tools and skills named

Security & compliance
  • Security4×
Data
  • Databricks
  • Pandas
  • Spark
Ways of working
  • Testing2×
  • Mentorship
Languages
  • Python
  • SQL

Words the posting leans on

  • incident13×
  • fraud10×
  • data8×
  • abuse6×
  • experience6×
  • incident response5×
  • requirements5×
  • threat5×
  • merchants4×
  • security4×
  • and/or3×
  • complex3×
  • cross-functionally3×
  • e.g3×
  • product abuse3×
  • risks3×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Stripe

every open role at Stripe

How this page was made

An automated read of a public job posting, fetched September 3, 2026 and last changed by Stripe on September 3, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.