滥用控制工程工程经理
查看雇主原标题
Engineering Manager, Abuse Control EngineeringStripe · Seattle, SF, NYC, Remote in the US
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
职位描述
机器翻译我们是谁
关于 Stripe
Stripe 是一个面向企业的金融基础设施平台。数百万家公司——从全球最大的企业到最有雄心的初创公司——都在使用 Stripe 来接受付款、增长收入并加速新的商业机会。我们的使命是提升互联网的 GDP,而我们面前还有大量工作要做。这意味着,在你职业生涯中最重要的工作中,你将拥有一个前所未有的机会,让全球经济触手可及。
关于团队
Abuse Control Engineering (ACE) 是 Stripe 的快速响应技术防御与控制孵化器。当紧急滥用向量出现时,ACE 利用真实的攻击者遥测数据来弥合缺口,在漏洞被大规模利用之前对软件防护措施进行原型设计、测试和部署。我们与 Fraud、Risk 和 Product Engineering 紧密合作,开展严格实验,在积极降低风险与合法用户转化之间取得平衡。ACE 既作为突击团队又作为孵化器运作,与 Abuse Research 合作构建自动化回归测试套件,以永久阻止威胁复发,并将成熟的控制措施无缝移交给 Stripe 各处的长期产品负责人。
你将做什么
作为 Abuse Control Engineering 的工程经理,你将领导一个团队,负责弥合紧急的跨产品防御缺口,并孵化控制措施,直到它们准备好被长期接管。你将对团队的技术方向、人员领导、招聘、辅导和跨职能执行负责。
你将帮助团队将攻击者证据转化为清晰的技术优先级,指导防护措施的设计和评估,并确保决策同时考虑风险降低和合法用户的体验。你还将建立有纪律的孵化和交接实践,使成功的控制措施以明确的所有权、文档、标准和时限移交给合适的产品团队。
职责
• 设定技术方向:定义并传达团队的技术战略和优先级,以识别跨产品滥用缺口、孵化控制措施,并防止已缓解威胁的复发。
• 领导并发展团队:招聘、管理、辅导和支持工程师;提供明确的期望和反馈;并为工程师创造机会,以拓展他们的技术判断力、领导力和影响力。
• 指导基于证据的决策:确保攻击者证据、产品背景
岗位职责
作为 Abuse Control Engineering 的工程经理,你将领导一个团队,负责弥合紧急的跨产品防御缺口,并孵化控制措施,直到它们准备好被长期接管。你将对团队的技术方向、人员领导、招聘、辅导和跨职能执行负责。
你将帮助团队将攻击者证据转化为清晰的技术优先级,指导防护措施的设计和评估,并确保决策同时考虑风险降低和合法用户的体验。你还将建立有纪律的孵化和交接实践,使成功的控制措施以明确的所有权、文档、标准和时限移交给合适的产品团队。
• 设定技术方向:定义并传达团队的技术战略和优先级,以识别跨产品滥用缺口、孵化控制措施,并防止已缓解威胁的复发。
• 领导并发展团队:招聘、管理、辅导和支持工程师;提供明确的期望和反馈;并为工程师创造机会,以拓展他们的技术判断力、领导力和影响力。
• 指导基于证据的决策:确保攻击者证据、产品背景和可衡量结果能够为技术滥用需求、控制设计和投资决策提供依据。
• 推动安全的控制设计:与 Application Security 和产品工程团队合作,开发具有韧性、范围适当且与其运行系统兼容的防护措施。
• 监督实验:指导评估风险降低以及控制措施对合法用户转化影响的实验,帮助团队做出明智权衡并改进其方法。
• 构建持久防御:确保团队开发回归测试和其他机制,以检测先前已缓解的滥用模式是否会复发。
• 管理控制孵化:为孵化的控制措施建立明确的成功衡量标准、运营期望、文档、目标负责人、交接标准和目标日期。
• 完成所有权交接:让团队及其合作伙伴负责将成功的控制措施移交给永久拥有相关界面的产品团队,除非某项控制措施被有意保留为服务多个产品的持久能力。
• 领导跨职能执行:围绕优先级、权衡、职责和交付计划,协调安全、产品、工程和其他合作伙伴,包括在需要紧急协调的情况下。
任职要求
我们正在寻找符合该职位最低要求的人选。如果你符合这些要求,我们鼓励你申请。优先资格是加分项,而非要求。
最低要求
• 具备管理工程团队的经验,包括设定方向、安排工作优先级,并对交付和技术成果负责。
• 在软件工程、安全工程、应用安全、反滥用工程或密切相关领域具备相关技术基础,并通过专业经验、教育或同等路径发展而来。
• 具备招聘、辅导和发展不同经验水平工程师的经验,包括提供可执行的反馈并支持职业成长。
• 具备领导跨职能技术工作的经验,涉及目标、专业领域或所有权边界不同的团队。
• 能够评估技术设计、提出有效问题,并指导涉及可靠性、安全、风险和产品权衡的工程决策。
• 具备向工程团队和跨职能利益相关者清晰传达技术战略、优先级、风险和决策的经验。
• 能够在模糊或紧急情况下创造清晰度,并将广泛的风险问题转化为可执行计划、明确所有权和可衡量结果。
• 具备指导实验或 A/B 测试的经验,包括评估控制有效性,并在降低风险与对合法用户转化的影响之间取得平衡。
• 了解威胁建模、安全系统设计或现代应用安全实践。
• 熟悉 API 防护措施和滥用控制,例如速率限制、授权检查、输入验证、升级验证挑战或相关保护机制。
• 了解金融欺诈模式、攻击者行为、攻击方法或用于实施滥用的基础设施。
• 具备使用或监督涉及大规模数据平台工作的经验,以分析系统活动、识别模式或衡量控制性能。
• 具备孵化技术能力并通过明确的成功标准、文档、运营准备和目标日期将其移交给长期负责人的经验。
• 具备领导分布式团队或协调多个地点或时区团队执行的经验。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE bridges the gap using real attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale. We partner closely with Fraud, Risk and Product Engineering to run rigorous experiments, balancing aggressive risk mitigation against legitimate user conversion. Operating as both a strike team and an incubator, ACE builds automated regression suites in partnership with Abuse Research to permanently block threat recurrence and seamlessly transfers mature controls to long-term product owners across Stripe.
What you’ll do
As the Engineering Manager for Abuse Control Engineering, you will lead a team responsible for closing urgent, cross-product defense gaps and incubating controls until they are ready for long-term ownership. You will be accountable for the team’s technical direction, people leadership, hiring, coaching, and cross-functional execution.
You will help the team turn attacker evidence into clear technical priorities, guide the design and evaluation of safeguards, and ensure that decisions account for both risk reduction and the experience of legitimate users. You will also establish disciplined incubation and handoff practices so that successful controls move to the appropriate product teams with clear ownership, documentation, criteria, and timelines.
Responsibilities
• Set technical direction: Define and communicate the team’s technical strategy and priorities for identifying cross-product abuse gaps, incubating controls, and preventing the recurrence of mitigated threats.
• Lead and develop the team: Hire, manage, coach, and support engineers; provide clear expectations and feedback; and create opportunities for engineers to expand their technical judgment, leadership, and impact.
• Guide evidence-based decisions: Ensure that attacker evidence, product conte
岗位职责
As the Engineering Manager for Abuse Control Engineering, you will lead a team responsible for closing urgent, cross-product defense gaps and incubating controls until they are ready for long-term ownership. You will be accountable for the team’s technical direction, people leadership, hiring, coaching, and cross-functional execution.
You will help the team turn attacker evidence into clear technical priorities, guide the design and evaluation of safeguards, and ensure that decisions account for both risk reduction and the experience of legitimate users. You will also establish disciplined incubation and handoff practices so that successful controls move to the appropriate product teams with clear ownership, documentation, criteria, and timelines.
• Set technical direction: Define and communicate the team’s technical strategy and priorities for identifying cross-product abuse gaps, incubating controls, and preventing the recurrence of mitigated threats.
• Lead and develop the team: Hire, manage, coach, and support engineers; provide clear expectations and feedback; and create opportunities for engineers to expand their technical judgment, leadership, and impact.
• Guide evidence-based decisions: Ensure that attacker evidence, product context, and measurable outcomes inform technical abuse requirements, control designs, and investment decisions.
• Drive secure control design: Partner with Application Security and product engineering teams to develop safeguards that are resilient, appropriately scoped, and compatible with the systems in which they operate.
• Oversee experimentation: Guide experiments that assess risk reduction and the effect of controls on legitimate user conversion, helping the team make informed tradeoffs and refine its approach.
• Build durable defenses: Ensure the team develops regression tests and other mechanisms that can detect whether previously mitigated abuse patterns recur.
• Manage control incubation: Establish clear success measures, operational expectations, documentation, destination owners, handoff criteria, and target dates for incubated controls.
• Complete ownership handoffs: Hold the team and its partners accountable for transferring successful controls to the product teams that permanently own the relevant surfaces, except where a control is intentionally maintained as a durable capability serving multiple products.
• Lead cross-functional execution: Align security, product, engineering, and other partners around priorities, tradeoffs, responsibilities, and delivery plans, including in situations that require urgent coordination.
任职要求
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
• Experience managing an engineering team, including setting direction, prioritizing work, and being accountable for delivery and technical outcomes.
• A relevant technical foundation in software engineering, security engineering, application security, anti-abuse engineering, or a closely related field, developed through professional experience, education, or an equivalent path.
• Experience hiring, coaching, and developing engineers with different levels of experience, including providing actionable feedback and supporting career growth.
• Experience leading cross-functional technical work involving teams with different goals, areas of expertise, or ownership boundaries.
• Ability to evaluate technical designs, ask effective questions, and guide engineering decisions involving reliability, security, risk, and product tradeoffs.
• Experience communicating technical strategy, priorities, risks, and decisions clearly to engineering teams and cross-functional stakeholders.
• Ability to create clarity in ambiguous or urgent situations and translate broad risk problems into actionable plans, ownership, and measurable outcomes.
• Experience guiding experimentation or A/B testing, including evaluating control effectiveness and balancing risk reduction against effects on legitimate user conversion.
• Knowledge of threat modeling, secure systems design, or modern application security practices.
• Familiarity with API safeguards and abuse controls such as rate limits, authorization checks, input validation, step-up challenges, or related protective mechanisms.
• Knowledge of financial-fraud patterns, attacker behavior, attack methods, or the infrastructure used to conduct abuse.
• Experience using or overseeing work involving large-scale data platforms to analyze system activity, identify patterns, or measure control performance.
• Experience incubating technical capabilities and transferring them to long-term owners through explicit success criteria, documentation, operational readiness, and target dates.
• Experience leading a distributed team or coordinating execution across teams in multiple locations or time zones.