滥用研究工程师
查看雇主原标题
Abuse Research EngineerStripe · Remote from the US
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 54/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 远程职位
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 远程职位+8
- 稀有职位+5
- 公司来源健康度+8
该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译我们是谁
关于 Stripe
Stripe 是一个面向企业的金融基础设施平台。数百万家公司——从全球最大的企业到最有抱负的初创公司——都在使用 Stripe 来接受付款、增长收入并加速新的商业机会。我们的使命是提升互联网的 GDP,而我们面前还有大量工作要做。这意味着,在你职业生涯中最重要的工作中,你将拥有一个前所未有的机会,让全球经济触手可及。
关于团队
滥用研究组(ARG)负责跨 Stripe 产品开展主动威胁狩猎和对手行为分析。该团队不是被动响应警报,而是绘制端到端的欺诈和滥用路径,验证新型攻击向量,并识别助长欺诈的产品条件。通过使用代理式自动化测试和模拟工具,ARG 将研究转化为可执行的威胁通告、战略性控制建议和回归场景,以系统性地消除漏洞。
你将做什么
作为滥用研究组的一名滥用研究工程师,你将在保护 Stripe 金融生态系统中发挥关键作用,主动狩猎高级威胁、剖析复杂欺诈向量,并提取可执行的对手情报。你将不仅仅依赖被动警报,而是跨内部遥测数据和外部来源,制定并执行假设驱动的威胁狩猎行动,在欺诈工具、战术和技术(TTP)影响 Stripe 平台之前将其发现。这项工作的核心是 FT3(欺诈分类法 3.0),这是 Stripe 的多层分类法,将单体式欺诈分解为结构化的杀伤链。你将与欺诈运营、战略、风险、入驻和安全等团队跨职能协作,整合威胁情报,构建代理式模拟工作流,并系统性地消除产品漏洞。
职责
• P
岗位职责
作为滥用研究组的一名滥用研究工程师,你将在保护 Stripe 金融生态系统中发挥关键作用,主动狩猎高级威胁、剖析复杂欺诈向量,并提取可执行的对手情报。你将不仅仅依赖被动警报,而是跨内部遥测数据和外部来源,制定并执行假设驱动的威胁狩猎行动,在欺诈工具、战术和技术(TTP)影响 Stripe 平台之前将其发现。这项工作的核心是 FT3(欺诈分类法 3.0),这是 Stripe 的多层分类法,将单体式欺诈分解为结构化的杀伤链。你将与欺诈运营、战略、风险、入驻和安全等团队跨职能协作,整合威胁情报,构建代理式模拟工作流,并系统性地消除产品漏洞。
• 主动威胁狩猎与杀伤链分析:提出假设,并跨 Stripe 系统和外部数据开展迭代式威胁狩猎行动。
• FT3 分类法:在经验数据集和事件中应用并丰富 FT3 框架,在杀伤链阶段和定向 API 端点之间标准化威胁情报。
• 威胁情报与信号扩展:与欺诈情报等团队合作,将威胁源整合、策划并自动化到工程工作流中。
• 跨职能通告与战略控制:将原始研究和回顾性发现转化为可执行的威胁通告和控制建议(政策、技术系统、支持工作流和检测机制),供欺诈、风险、入驻和安全等各利益相关方使用。
• 代理式测试与对手模拟:利用代理式自动化测试框架模拟对手 TTP,验证已部署控制措施是否能中断经验杀伤链,并生成回归场景以检验控制措施。
任职要求
我们正在寻找符合该职位最低要求的人选。如果你符合这些要求,鼓励你申请。优先资格是加分项,而非要求。
最低要求
• 5 年以上在网络安全、产品滥用或信任领域从事威胁情报、威胁狩猎或技术事件响应的经验。
• 5 年以上使用数据分析工具分析大型复杂数据集的经验,以识别异常、映射行为趋势并解决复杂欺诈问题。
• 计算机科学、网络安全或相关技术领域的学士或硕士学位,或同等实践经验。
• 精通 Python 和 SQL,并具有使用代码和脚本自动化工作流、构建调查工具或查询大数据管道的实际经验。
• 具备日志分析(例如应用日志、API 路由遥测、网络安全事件)、数字取证和网络调查方法的实操经验。
• 出色的沟通能力,并具备将复杂技术研究转化为清晰、可执行建议和通告以供跨职能合作伙伴使用的 proven 能力。
• 对金融欺诈(例如 ATO、Card Testing、Credential Stuffing)特有的威胁行为者动机、基础设施和 TTP 有深入的技术理解。
• 熟悉 FT3 或 MITRE ATT&CK 等标准化分类法。
• 熟练使用 Databricks、Trino、PySpark、Pandas 或 Scikit-Learn 等工程、数据处理和分析平台。
• 具有使用威胁情报平台(TIP)、战术威胁源、OSINT 和泄露情报的 proven 背景。
• 具备构建或利用代理式 LLM 工具、自动化测试系统或控制验证框架以大规模建模对手行为的 proven 能力。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
Abuse Research Group (ARG) handles proactive threat hunting and adversary behavior analysis across Stripe products. Rather than reacting to alerts, the team maps end-to-end fraud and abuse paths, validates novel attack vectors, and identifies product conditions that enable fraud. Using agentic automated testing and simulation tools, ARG translates research into actionable threat advisories, strategic control recommendations, and regression scenarios to systematically eliminate vulnerabilities.
What you’ll do
As an Abuse Research Engineer in the Abuse Research Group, you will play a critical role in safeguarding Stripe’s financial ecosystem by proactively hunting for advanced threats, dissecting complex fraud vectors, and extracting actionable adversary intelligence. Rather than relying solely on reactive alerts, you will develop and execute hypothesis-driven threat hunting operations across internal telemetry and external sources to uncover fraudulent tools, tactics, and techniques (TTPs) before they impact Stripe’s platform. Central to this work is FT3 (Fraud Taxonomy 3.0), Stripe’s multi-layered taxonomy that decomposes monolithic fraud into structured kill chains. Collaborating cross-functionally with Fraud Ops, Strategy, Risk, Onboarding, and Security, you will integrate threat intelligence, build agentic simulation workflows, and systematically eliminate product vulnerabilities.
Responsibilities
• P
岗位职责
As an Abuse Research Engineer in the Abuse Research Group, you will play a critical role in safeguarding Stripe’s financial ecosystem by proactively hunting for advanced threats, dissecting complex fraud vectors, and extracting actionable adversary intelligence. Rather than relying solely on reactive alerts, you will develop and execute hypothesis-driven threat hunting operations across internal telemetry and external sources to uncover fraudulent tools, tactics, and techniques (TTPs) before they impact Stripe’s platform. Central to this work is FT3 (Fraud Taxonomy 3.0), Stripe’s multi-layered taxonomy that decomposes monolithic fraud into structured kill chains. Collaborating cross-functionally with Fraud Ops, Strategy, Risk, Onboarding, and Security, you will integrate threat intelligence, build agentic simulation workflows, and systematically eliminate product vulnerabilities.
• Proactive Threat Hunting & Kill Chain Analysis: Formulate hypotheses and conduct iterative threat hunting operations across Stripe systems and external data.
• FT3 Taxonomy: Apply and enrich the FT3 framework across empirical datasets and incidents, standardizing threat intelligence across kill chain phases and targeted API endpoints.
• Threat Intelligence & Signal Expansion: Partner with teams like Fraud Intelligence to integrate, curate, and automate threat feeds into engineering workflows.
• Cross-Functional Advisories & Strategic Controls: Translate raw research and retrospective findings into actionable threat advisories and control recommendations (policy, technical systems, support workflows, and detection mechanisms) for stakeholders across Fraud, Risk, Onboarding, and Security.
• Agentic Testing & Adversary Simulation: Utilize agentic automated testing frameworks to simulate adversary TTPs, validate whether deployed controls interrupt empirical kill chains, and generate regression scenarios to exercise controls.
任职要求
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
• 5+ years of experience conducting threat intelligence, threat hunting, or technical incident response within cyber security, product abuse, or trust domains.
• 5+ years of experience analyzing large, complex datasets using data analytics tools to identify anomalies, map behavioral trends, and solve complex fraud problems.
• B.S. or M.S. in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
• Expert proficiency in Python and SQL, with demonstrated experience using code and scripting to automate workflows, build investigative tools, or query big data pipelines.
• Hands-on experience in log analysis (e.g., application logs, API route telemetry, network security events), digital forensics, and cyber investigation methodologies.
• Strong communication skills with a proven ability to translate complex technical research into clear, actionable recommendations and advisories for cross-functional partners.
• Deep technical understanding of threat actor motivations, infrastructure, and TTPs specific to financial fraud (e.g., ATO, Card Testing, Credential Stuffing).
• Familiarity with standardized taxonomies such as FT3 or MITRE ATT&CK.
• Proficiency with engineering, data processing, and analysis platforms such as Databricks, Trino, PySpark, Pandas, or Scikit-Learn.
• Proven background utilizing Threat Intelligence Platforms (TIPs), tactical threat feeds, OSINT, and breach intelligence.
• Demonstrated capability building or leveraging agentic LLM tools, automated testing systems, or control validation frameworks to model adversary behavior at scale.