Forward Deployed Security Engineer
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.
What you’ll do
In this role, you will play a critical part in safeguarding our financial ecosystem through two main pillars: actively responding to live fraud and abuse incidents as a hands-on security engineer, and serving as a key bridge between incidents and merchants to help them remediate threats, improve security posture, and protect their accounts. Leveraging your technical depth in fraud, abuse, and security engineering, you will investigate high-risk accounts, perform post-incident analyses, gather operational requirements, and drive agentic response capabilities ensuring we neutralize threats with speed and precision while elevating Stripe's product integrity function.
Responsibilities
- Respond to live fraud and abuse incidents as a Forward Deployed Security Engineer, investigating high-risk activity, neutralizing active attacks, and mitigating security risks across the ecosystem.
- Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped (Fraud Taxonomy 3.0) detection and signals enrichment to reduce uncertainty and accelerate response.
- As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.
- Develop, document, and execute incident response strategies, runbooks, and capabilities to continuously improve fraud and abuse detection and prevention.
- Act as a dedicated technical bridge during and after incidents to work directly with impacted merchants and customers, helping them investigate root causes, remediate vulnerabilities, and secure their accounts.
- Serve as an operational and technical liaison for legal teams, policy partners, and threat intelligence communities.
- Build and nurture strong strategic relationships across external threat intelligence communities, peer working groups, and law enforcement agencies.
Who you are
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 10+ years of experience leading security or fraud incident response;
- B.S./M.S. in Computer Science or equivalent experience.
- Expert knowledge of Python and SQL, and familiarity with other programming languages
- Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
- Proven ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
- Strong written and verbal communication skills with a track record of driving cross-functional alignment with minimal oversight.
- Previous work with law enforcement
- Engagement in threat intelligence sharing communities
Preferred qualifications
- Broad expertise across fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
- An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
- Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
- Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
- Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
- Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges.
- Speaker or participant in external conferences or similar industry engagements
Abuse Investigator
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve technical incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.
What you’ll do
You'll play a critical role in safeguarding our financial ecosystem by investigating high-risk accounts and identifying complex patterns of fraud during incidents. You will lead incident response for product abuse and fraud events, conducting deep-dive analyses to identify root causes. By collaborating cross-functionally, you will drive improvements that enhance our fraud detection and prevention strategies at scale. Your expertise will be essential in automating response processes through agentic approaches, allowing us to safeguard merchants and neutralize threats with speed and precision.
Responsibilities
- Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped detection and signals enrichment to reduce uncertainty and accelerate response.
- As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 (Fraud Taxonomy 3.0) to standardize threat intelligence.
- Lead incident root cause analyses to identify gaps in current systems and strategies, leveraging the FT3 framework, data-driven model to drive enhancements and process improvements for emerging fraud risks.
- Streamline incident response capabilities, ensuring the tooling and processes are clear, accurate and efficient
- Work cross-functionally with security, fraud and data science teams to build agentic solutions for responding to abuse incidents at scale
- Effectively communicate cross-functionally with legal and policy teams to assess and mitigate risks, while demonstrating strong problem-solving under pressure.
- Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team
Who you are
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 3+ years of experience conducting incident response in security, product abuse or trust domains
- 3+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to fraud detection
- B.S. or M.S. Computer Science or related field, or equivalent experience
- Expert knowledge of Python and SQL, and familiarity with other programming languages
- Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
- Ability to communicate results clearly and focus on impact
- Ability to think creatively and holistically about reducing risk in a complex environment
Preferred qualifications
- An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
- Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
- Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
- Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
- Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges
Abuse Investigator
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve technical incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.
What you’ll do
You'll play a critical role in safeguarding our financial ecosystem by investigating high-risk accounts and identifying complex patterns of fraud during incidents. You will lead incident response for product abuse and fraud events, conducting deep-dive analyses to identify root causes. By collaborating cross-functionally, you will drive improvements that enhance our fraud detection and prevention strategies at scale. Your expertise will be essential in automating response processes through agentic approaches, allowing us to safeguard merchants and neutralize threats with speed and precision.
Responsibilities
- Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped detection and signals enrichment to reduce uncertainty and accelerate response.
- As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 (Fraud Taxonomy 3.0) to standardize threat intelligence.
- Lead incident root cause analyses to identify gaps in current systems and strategies, leveraging the FT3 framework, data-driven model to drive enhancements and process improvements for emerging fraud risks.
- Streamline incident response capabilities, ensuring the tooling and processes are clear, accurate and efficient
- Work cross-functionally with security, fraud and data science teams to build agentic solutions for responding to abuse incidents at scale
- Effectively communicate cross-functionally with legal and policy teams to assess and mitigate risks, while demonstrating strong problem-solving under pressure.
- Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team
Who you are
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 3+ years of experience conducting incident response in security, product abuse or trust domains
- 3+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to fraud detection
- B.S. or M.S. Computer Science or related field, or equivalent experience
- Expert knowledge of Python and SQL, and familiarity with other programming languages
- Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
- Ability to communicate results clearly and focus on impact
- Ability to think creatively and holistically about reducing risk in a complex environment
Preferred qualifications
- An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
- Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
- Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
- Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
- Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges
Security Incident Response Manager - Abuse Operations
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.
What you’ll do
In this role, you will play a critical part in safeguarding our financial ecosystem by investigating high-risk accounts, identifying complex fraud patterns, performing post-incident analyses, and driving cross-functional improvements to scale fraud detection. Building on these core operational duties, you will leverage your fraud, abuse, or product trust experience to improve incident response capabilities across Stripe by managing the entire fraud and abuse incident response process, developing response plans, leading workstreams, and serving as incident commander to ensure timely resolution. Furthermore, you will conduct gamedays to pressure-test response processes, drive proactive improvements, and help automate response workflows using agentic approaches ensuring we neutralize threats with speed and precision while continuously elevating Stripe's fraud and abuse incident response function.
Responsibilities
- Lead fraud and abuse incident response end-to-end as Incident Response Manager (IRM), coordinating workstreams, investigating high risk activity and accounts, and making actionable mitigation recommendations under pressure.
- Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped (Fraud Taxonomy 3.0) detection and signals enrichment to reduce uncertainty and accelerate response.
- As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.
- Develop, document, and execute incident response strategies, runbooks, and capabilities to continuously improve fraud and abuse detection and prevention.
- Partner cross-functionally with security, data science, legal, and policy teams to build agentic response solutions, refine KPIs, and deliver clear incident reporting.
- Mentor teammates, lead key incident response engineering projects, and elevate quality standards across the team.
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 10+ years of experience leading security or fraud incident response;
- B.S./M.S. in Computer Science or equivalent experience.
- Expert knowledge of Python and SQL, and familiarity with other programming languages
- Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
- Proven ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
- Strong written and verbal communication skills with a track record of driving cross-functional alignment with minimal oversight.
Preferred qualifications
- Broad expertise across fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
- An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
- Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
- Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
- Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
- Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges.
Integration Engineer, Metronome
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
Metronome is the leading usage-based billing platform built for modern software companies. With Metronome, companies can launch products faster, offer any pricing model, and streamline finance workflows without writing code. Our platform computes millions of invoices per billing period and is scaling rapidly to accommodate new customers, saving them hours of development time and manual invoicing and enabling them to use consumption data to better serve their customers. Our customers love our product and approach, and we’re humbled to work with amazing companies like OpenAI, Databricks, NVIDIA, Confluent, and Anthropic.
You'll be joining an experienced team that includes founders who have successfully built and sold startups before. Our founders and employees have direct experience building and scaling teams through massive growth at companies like Dropbox, Clever, and New Relic. On the back of this experience and our success-to-date, we’ve raised over $128M from leading investors including NEA, Andreessen Horowitz, General Catalyst, Elad Gil, and Workday Ventures. We’re also proud to have founders and executives of companies like Segment, Plaid, Looker, Gitlab, Confluent, HashiCorp, and Snowflake, as investors who have experienced the pain we're solving firsthand.
About the team
The Solutions Architecture team at Metronome is a technical group that sits at the intersection of sales, growth, product, and R&D. In simple terms, we own the technical aspects of the customer lifecycle between after sales and before handoff to post-implementation teams.
As a member of the Solutions Architecture team, you’ll primarily be focused on ensuring customers successfully implement Metronome’s products and realize value quickly.
Responsibilities
- Using proficient discovery and scoping to understand what challenges our clients face in billing, launching new products, pricing & packaging, quote-to-cash, customer experience, and related areas.
- Doing whatever it takes to support clients throughout the entire implementation lifecycle, including requirements gathering, technical design, integration design, testing, data migration, and launch.
- Providing expert guidance to clients regarding usage-based pricing and consumption business models.
- Hands on configuration of Metronome’s system on behalf of clients
- Designing integrations between Metronome’s APIs and the clients business systems to align to Metronome best practices (including CRM/ CPQ, Payments, Taxation, ERP, Billing Providers, Reporting and Analytics tools).
- Acting as a liaison between the field and Metronome R&D to advocate for client needs and feature requests.
- Partnering with implementation managers and other project team members to provide visibility into progress and proactively identify risks and issues
- Building relationships with people at our client organizations, from day-to-day operators to C-Suite executives. We believe in meeting our customers in-person whenever possible.
- Designing integrations of Metronome into prospect systems and consultatively influencing the direction of our prospects’ pricing and packaging.
- Ensuring a proper handoff to our post-implementation teams (Customer Success and Technical Support).
Who you are
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Expect these engagements to be complex, deep, technical, and most of all interesting. Metronome directly influences how the internet monetizes - AI is an obvious current example - and our group is on the front lines driving this influence with our prospects. Metronome is a startup. As such, there’s a lot still to figure out and tremendous room for high-agency people to impact our direction and strategy, build processes from zero to one, and generally make a difference. If this excites you as much as it excites us, let’s talk.
Minimum requirements
- 10+ years of experience working in technical and/or customer-facing roles involving SaaS products (for example, roles like sales engineering, solutions architecture, technical account management).
- Deep knowledge of the quote-to-cash space, including integrating with or otherwise interacting with tools like Salesforce, NetSuite, CPQs, Billing, Tax, Payments, etc.
- Experience leading complex, multi-phase technology transformation programs for enterprise companies.
- Experience in fast-moving startup environments that value high agency.
- Ability to quickly learn and communicate technical concepts to technical, go-to-market, and finance stakeholders.
- Excitement for building and improving GTM playbooks, processes, and reusable assets.
Preferred qualifications
- Experience as a software engineer, product manager, or in other technical roles.
- Strong understanding of project management and program management fundamentals and principles
- Experience working with users from one or more of the following personas: Finance/ CFO, Engineering/ CTO, Product/ CPO, Sales Ops/ CRO, and Billing Operations.
- Experience with logs, metrics, billing, finance, or other infrastructure or financial tooling and concepts.
Recruiting Coordinator (Contract)
Sr. Forward Deployed Engineer
Sr. Forward Deployed Engineer
Sr. Forward Deployed Engineer
Sr. Forward Deployed Engineer
The full posting opens here — pay, setting and the full description, without leaving the list.