云安全工程师
查看雇主原标题
Cloud Security EngineerStripe · Seattle
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 42/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 稀有职位+1
- 公司来源健康度+8
该职位未包含:已披露薪资、远程职位、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译我们是谁
关于 Stripe
Stripe 是一个面向企业的金融基础设施平台。数百万家公司——从全球最大的企业到最有抱负的初创公司——都在使用 Stripe 来接受付款、增长收入并加速新的商业机会。我们的使命是提升互联网的 GDP,而我们面前还有大量工作要做。这意味着你拥有一个前所未有的机会,在从事你职业生涯中最重要的工作的同时,让全球经济触手可及。
关于团队
Stripe 为世界各地的企业提供支持。我们处理支付、运营市场平台、检测欺诈、帮助创业者从世界任何地方创办企业、构建世界级且对开发者友好的 API 等等。我们运营的几乎每一个系统都会接触敏感的金融或个人数据——这使安全成为 Stripe 的首要任务。
只有当我们证明自己值得用户信任时,Stripe 才能成功实现提升互联网 GDP 的使命。作为安全团队的工程师,你将设计和开发框架、系统和解决方案,以确保 Stripe 工程基础设施的安全,最重要的是确保我们用户数据的隐私。
云安全团队通过构建核心安全控制和服务来加速 Stripe 的业务优先事项,使各团队能够在治理良好的云平台之上快速且安全地构建,并与基础设施团队合作,在该平台扩展时利用新颖的基础设施或集成来推进选定的关键业务优先事项。
你将做什么
职责
• 与其他利益相关者和我们的用户密切合作,设计、构建和运营 Stripe 所有工程团队使用的核心安全基础设施
• 坚持我们高标准的工程要求,并为你将遇到的众多代码库和流程带来一致性
岗位职责
• 与其他利益相关者和我们的用户密切合作,设计、构建和运营 Stripe 所有工程团队使用的核心安全基础设施
• 坚持我们高标准的工程要求,并为你将遇到的众多代码库和流程带来一致性
• 通过改进工程标准、工具和流程来促进团队学习
• 设计和构建持久耐用的解决方案,将 Stripe 的安全性推进到超越当前最先进水平
• 在安全、铺好的道路和护栏之上帮助扩展 Stripe 的云足迹
• 优化安全控制,使其具备令人愉悦的用户体验
• 与构建我们云基础设施集成或采用新的云托管服务的基础设施和工程团队紧密合作
• 就系统和安全做出有影响力的决策——包括其边缘情况、故障模式和生命周期
• 使用数据确定适当的基线,以衡量安全性
• 定义能够可靠地向威胁团队提供信号的基础设施
• 评估并原型化新的安全工具和实践
你可能从事的工作
• 设计和实施支持安全不变量并执行我们安全原则的控制措施,同时提供出乎意料地出色的用户体验
• 为新收购的公司提供迁移到 Stripe 安全平台的路径,与他们的工程师一起嵌入工作,并以行动为导向
• 用于平台相关配置的 CI 工具,包括 IAM 角色、SCP 及相关组件
• 面向常用和较新云技术的护栏和安全控制
• 扩展我们的云身份基础设施,为 AI 和代理式访问提供铺好的路径
• 用于持续降低我们云服务中的权限和访问范围的自动化工具
任职要求
最低要求
• 同理心、出色的沟通能力,以及对协作力量的深切尊重
• 学习型心态,无论级别或经验如何
• 在遇到没有明确责任边界的模糊领域时,能够推动明确的下一步行动
• 对代码质量有高标准,并具备建设性态度以帮助他人提高标准
• 在高风险生产环境中的软件工程经验
• 善于思考系统可能如何失败以及如何修复它们
• 能够在复杂环境中创造性地、整体性地思考如何降低风险
• 具备在云原生环境中对软件或基础设施进行威胁建模的经验
• 曾使用安全监控工具(例如 CSPM、CNAAP)
• 善于思考系统可能如何失败以及如何修复它们
• 能够在复杂环境中创造性地、整体性地思考如何降低风险
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
Stripe powers businesses all over the world. We process payments, run marketplaces, detect fraud, help entrepreneurs start a business from anywhere in the world, build world-class developer-friendly APIs, and more. Nearly every system we operate interacts with sensitive financial or personal data—making security a top priority for Stripe.
Stripe will succeed at our mission of increasing the GDP of the internet only if we prove ourselves worthy of our users' trust. As an engineer on the Security team, you'll design and develop frameworks, systems, and solutions to ensure the security of Stripe's engineering infrastructure and, most importantly, privacy of our users' data.
The Cloud Security team accelerates Stripe's business priorities by building core security controls and services that empower teams to build quickly and securely on top of a well-governed cloud platform and partnering with infrastructure teams to advance select critical business priorities using novel infrastructure or integrations as that platform expands.
What you'll do
Responsibilities
• Design, build, and operate the core security infrastructure used by all of Stripe's engineering teams in close collaboration with other stakeholders and our users
• Uphold our high engineering standards and bring consiste
岗位职责
• Design, build, and operate the core security infrastructure used by all of Stripe's engineering teams in close collaboration with other stakeholders and our users
• Uphold our high engineering standards and bring consistency to the many codebases and processes you'll encounter
• Contribute to team learning by improving engineering standards, tooling, and processes
• Design and build durable solutions that will advance Stripe's security beyond the state of the art
• Help expand Stripe's cloud footprint on top of secure, paved roads and guardrails
• Optimize for security controls that have delightful user experiences
• Partner closely with infrastructure and engineering teams building integrations with our cloud infrastructure or adopting new cloud managed services
• Make impactful decisions about systems and security—their edge cases, failure modes, and life cycles
• Use data to determine appropriate baselines against which to measure security
• Define infrastructure that reliably feeds signals to threat teams
• Evaluate and prototype new security tools and practices
You may work on
• Designing and implementing controls that support security invariants and enforce our security principles while providing a surprisingly great user experience
• Providing a migration path for newly acquired companies onto the Stripe Secure Platform, embedding with their engineers and biasing for action
• CI tooling for platform-related configuration, including IAM roles, SCPs, and associated components
• Guardrails and security controls for both commonly used and newer cloud technologies
• Expanding our cloud identity infrastructure to provide paved paths for AI and agentic access
• Automation tooling for continually driving down permissions and access across our cloud services
任职要求
Minimum requirements
• Empathy, strong communication skills, and a deep respect for the power of collaboration
• A learning mindset, regardless of level or experience
• The ability to drive clear next steps when encountering ambiguous spaces without clear lines of ownership
• High standards for code quality and a constructive attitude to help others raise the bar
• Software engineering experience in a high-stakes production environment
• A knack for considering how systems can fail and how to fix them
• An ability to think creatively and holistically about reducing risk in a complex environment
• Experience conducting threat modeling of software or infrastructure in cloud-native environments
• Prior usage of security monitoring tools (e.g., CSPM, CNAAP)
• A knack for considering how systems can fail and how to fix them
• An ability to think creatively and holistically about reducing risk in a complex environment