Engineering Manager, Abuse Control Engineering

Stripe · Seattle, SF, NYC, Remote in the US · 8611 Security Analytics · listed September 16, 2026

The shape of it

Seniority
Manager
Where
Remote
Requirements listed
7
Length
822 words

In the posting’s own words

Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE bridges the gap using real attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale. We partner closely with Fraud, Risk and Product Engineering to run rigorous experiments, balancing aggressive risk mitigation against legitimate user conversion. Operating as both a strike team and an incubator, ACE builds automated regression suites in partnership with Abuse Research to permanently block threat recurrence and seamlessly transfers mature controls to long-term product owners across Stripe.

What it asks for · 7

  • Experience managing an engineering team, including setting direction, prioritizing work, and being accountable for delivery and technical outcomes.
  • A relevant technical foundation in software engineering, security engineering, application security, anti-abuse engineering, or a closely related field, developed through professional experience, education, or an equivalent path.
  • Experience hiring, coaching, and developing engineers with different levels of experience, including providing actionable feedback and supporting career growth.
  • Experience leading cross-functional technical work involving teams with different goals, areas of expertise, or ownership boundaries.
  • Ability to evaluate technical designs, ask effective questions, and guide engineering decisions involving reliability, security, risk, and product tradeoffs.
  • Experience communicating technical strategy, priorities, risks, and decisions clearly to engineering teams and cross-functional stakeholders.
  • Ability to create clarity in ambiguous or urgent situations and translate broad risk problems into actionable plans, ownership, and measurable outcomes.

Also a plus

  • Experience guiding experimentation or A/B testing, including evaluating control effectiveness and balancing risk reduction against effects on legitimate user conversion.
  • Knowledge of threat modeling, secure systems design, or modern application security practices.
  • Familiarity with API safeguards and abuse controls such as rate limits, authorization checks, input validation, step-up challenges, or related protective mechanisms.
  • Knowledge of financial-fraud patterns, attacker behavior, attack methods, or the infrastructure used to conduct abuse.
  • Experience using or overseeing work involving large-scale data platforms to analyze system activity, identify patterns, or measure control performance.
  • Experience incubating technical capabilities and transferring them to long-term owners through explicit success criteria, documentation, operational readiness, and target dates.
  • Experience leading a distributed team or coordinating execution across teams in multiple locations or time zones.

What the job covers

  • Set technical direction: Define and communicate the team’s technical strategy and priorities for identifying cross-product abuse gaps, incubating controls, and preventing the recurrence of mitigated threats.
  • Lead and develop the team: Hire, manage, coach, and support engineers; provide clear expectations and feedback; and create opportunities for engineers to expand their technical judgment, leadership, and impact.
  • Guide evidence-based decisions: Ensure that attacker evidence, product context, and measurable outcomes inform technical abuse requirements, control designs, and investment decisions.
  • Drive secure control design: Partner with Application Security and product engineering teams to develop safeguards that are resilient, appropriately scoped, and compatible with the systems in which they operate.
  • Oversee experimentation: Guide experiments that assess risk reduction and the effect of controls on legitimate user conversion, helping the team make informed tradeoffs and refine its approach.
  • Build durable defenses: Ensure the team develops regression tests and other mechanisms that can detect whether previously mitigated abuse patterns recur.
  • Manage control incubation: Establish clear success measures, operational expectations, documentation, destination owners, handoff criteria, and target dates for incubated controls.
  • Complete ownership handoffs: Hold the team and its partners accountable for transferring successful controls to the product teams that permanently own the relevant surfaces, except where a control is intentionally maintained as a durable capability serving multiple products.
  • Lead cross-functional execution: Align security, product, engineering, and other partners around priorities, tradeoffs, responsibilities, and delivery plans, including in situations that require urgent coordination.

Tools and skills named

Ways of working
  • Cross-functional4×
  • Technical writing3×
  • Mentorship2×
  • Testing
Security & compliance
  • Security6×
  • Threat modeling
Data
  • Experimentation3×

Words the posting leans on

  • control17×
  • technical13×
  • engineering12×
  • experience11×
  • abuse9×
  • product9×
  • risk8×
  • security6×
  • decisions5×
  • design5×
  • ownership5×
  • requirements5×
  • attacker4×
  • clear4×
  • cross-functional4×
  • guide4×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Stripe

every open role at Stripe

How this page was made

An automated read of a public job posting, fetched September 16, 2026 and last changed by Stripe on September 16, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.