事件响应经理 - 滥用运营
查看雇主原标题
Incident Response Manager - Abuse OperationsStripe · Dublin
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 52/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 稀有职位匹配
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 稀有职位+11
- 公司来源健康度+8
该职位未包含:已披露薪资、远程职位、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译我们是谁
关于 Stripe
Stripe 是一个面向企业的金融基础设施平台。数百万家公司——从全球最大的企业到最有抱负的初创公司——都在使用 Stripe 来接受付款、增长收入并加速新的商业机会。我们的使命是提升互联网的 GDP,而我们面前还有大量工作要做。这意味着你拥有一个前所未有的机会,在从事你职业生涯中最重要的工作的同时,让全球经济触手可及。
关于团队
Abuse Operations 是一线事件响应与修复职能,负责处理影响 Stripe 及其商户的活跃产品滥用和欺诈问题。这个多学科团队涵盖事件经理、调查员、前沿部署安全工程师和数据科学家,负责化解活跃攻击、收集运营工具需求并主导事件处理。该团队直接与受影响的商户合作,以快速解决事件和政策滥用问题。这些团队成员主要在东部、太平洋和西欧时区开展工作,并经常与全球各地的利益相关方协调。
你将做什么
在这个职位中,你将通过调查高风险账户、识别复杂的欺诈模式、执行事后分析,以及推动跨职能改进以扩展欺诈检测,在保护我们的金融生态系统中发挥关键作用。在这些核心运营职责的基础上,你将利用自己在欺诈、滥用或产品信任方面的经验,通过管理整个欺诈和滥用事件响应流程、制定响应计划、领导工作流,并担任事件指挥官以确保及时解决,来提升 Stripe 整体的事件响应能力。此外,你将开展演练日以压力测试响应流程、推动主动改进,并帮助使用代理式方法自动化响应工作流
岗位职责
在这个职位中,你将通过调查高风险账户、识别复杂的欺诈模式、执行事后分析,以及推动跨职能改进以扩展欺诈检测,在保护我们的金融生态系统中发挥关键作用。在这些核心运营职责的基础上,你将利用自己在欺诈、滥用或产品信任方面的经验,通过管理整个欺诈和滥用事件响应流程、制定响应计划、领导工作流,并担任事件指挥官以确保及时解决,来提升 Stripe 整体的事件响应能力。此外,你将开展演练日以压力测试响应流程、推动主动改进,并帮助使用代理式方法自动化响应工作流,确保我们以速度和精准度化解威胁,同时持续提升 Stripe 的欺诈和滥用事件响应职能。
• 作为事件响应经理(IRM)端到端领导欺诈和滥用事件响应,协调工作流、调查高风险活动和账户,并在压力下提出可执行的缓解建议。
• 调查、缓解并修复紧急欺诈事件(例如 ATO、卡测试),利用 FT3 映射(Fraud Taxonomy 3.0)检测和信号增强来减少不确定性并加速响应。
• 作为事件处理的一部分,分析高风险账户以识别欺诈商户、卡测试、账户接管和其他欺诈途径,并使用 FT3 对其进行分类,以标准化威胁情报。
• 制定、记录并执行事件响应策略、运行手册和能力,以持续改进欺诈和滥用检测与预防。
• 与安全、数据科学、法律和政策团队跨职能合作,构建代理式响应解决方案、优化 KPI,并交付清晰的事件报告。
• 指导团队成员,领导关键的事件响应工程项目,并提升整个团队的质量标准。
任职要求
我们正在寻找符合该职位最低要求的人选。如果你符合这些要求,我们鼓励你申请。优先资格是加分项,而非要求。
最低要求
• 10 年以上领导安全或欺诈事件响应经验;
• 计算机科学学士/硕士学位或同等经验。
• 精通 Python 和 SQL,并熟悉其他编程语言
• 具备日志分析(例如第一方或第三方应用、系统/数据访问、事件日志)、网络安全、数字取证和事件响应调查方面的现有经验
• 已证明有能力构建自动化响应工作流、利用威胁情报并提出风险缓解建议。
• 出色的书面和口头沟通能力,并有在极少监督下推动跨职能一致性的记录。
• 在复杂平台环境中,拥有涵盖欺诈和滥用缓解、风险管理、产品信任和威胁情报的广泛专业知识。
• 具备对抗性思维,理解威胁行为者的目标、行为和 TTP。
• 具备工程、数据处理和分析工具经验(例如 Databricks、Trino 等)
• 熟悉用于大数据处理和/或数据科学的常见开源框架(PySpark、Pandas、Sci-kit Learn 等)
• 具备在企业环境中开展战术威胁情报和/或追踪复杂威胁行为者的经验
• 有能力通过利用数据并采取以用户为中心的方法,主动挑战现状,以应对复杂的产品完整性挑战。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.
What you’ll do
In this role, you will play a critical part in safeguarding our financial ecosystem by investigating high-risk accounts, identifying complex fraud patterns, performing post-incident analyses, and driving cross-functional improvements to scale fraud detection. Building on these core operational duties, you will leverage your fraud, abuse, or product trust experience to improve incident response capabilities across Stripe by managing the entire fraud and abuse incident response process, developing response plans, leading workstreams, and serving as incident commander to ensure timely resolution. Furthermore, you will conduct gamedays to pressure-test response processes, drive proactive improvements, and help automate response workflows using agentic approaches
岗位职责
In this role, you will play a critical part in safeguarding our financial ecosystem by investigating high-risk accounts, identifying complex fraud patterns, performing post-incident analyses, and driving cross-functional improvements to scale fraud detection. Building on these core operational duties, you will leverage your fraud, abuse, or product trust experience to improve incident response capabilities across Stripe by managing the entire fraud and abuse incident response process, developing response plans, leading workstreams, and serving as incident commander to ensure timely resolution. Furthermore, you will conduct gamedays to pressure-test response processes, drive proactive improvements, and help automate response workflows using agentic approaches ensuring we neutralize threats with speed and precision while continuously elevating Stripe's fraud and abuse incident response function.
• Lead fraud and abuse incident response end-to-end as Incident Response Manager (IRM), coordinating workstreams, investigating high risk activity and accounts, and making actionable mitigation recommendations under pressure.
• Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped (Fraud Taxonomy 3.0) detection and signals enrichment to reduce uncertainty and accelerate response.
• As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.
• Develop, document, and execute incident response strategies, runbooks, and capabilities to continuously improve fraud and abuse detection and prevention.
• Partner cross-functionally with security, data science, legal, and policy teams to build agentic response solutions, refine KPIs, and deliver clear incident reporting.
• Mentor teammates, lead key incident response engineering projects, and elevate quality standards across the team.
任职要求
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
• 10+ years of experience leading security or fraud incident response;
• B.S./M.S. in Computer Science or equivalent experience.
• Expert knowledge of Python and SQL, and familiarity with other programming languages
• Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
• Proven ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
• Strong written and verbal communication skills with a track record of driving cross-functional alignment with minimal oversight.
• Broad expertise across fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
• An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
• Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
• Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
• Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
• Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges.