安全工程师
查看雇主原标题
Security EngineerStripe · US Remote
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 50/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 远程职位
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 远程职位+8
- 稀有职位+1
- 公司来源健康度+8
该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译我们是谁
关于 Stripe
Stripe 是一个面向企业的金融基础设施平台。数百万家公司——从全球最大的企业到最有雄心的初创公司——都在使用 Stripe 来接受付款、增长收入并加速新的商业机会。我们的使命是提升互联网的 GDP,而我们面前还有大量工作要做。这意味着,你拥有一个前所未有的机会,在从事你职业生涯中最重要工作的同时,让全球经济触手可及。
关于团队
滥用控制工程(ACE)是 Stripe 的快速响应技术防御与控制孵化器。当紧急滥用向量出现时,ACE 利用真实攻击者遥测来弥合缺口,在漏洞被大规模利用之前对软件防护措施进行原型设计、测试和部署。我们与欺诈、风险和产品工程团队紧密合作,开展严格实验,在积极降低风险与合法用户转化之间取得平衡。ACE 既作为突击团队,也作为孵化器运作,与滥用研究团队合作构建自动化回归测试套件,以永久阻止威胁复发,并将成熟的控制措施无缝移交给 Stripe 各处的长期产品负责人。
你将做什么
作为滥用控制工程(ACE)团队的滥用控制工程师,你将设计、原型化并孵化技术防御措施,保护 Stripe 的金融生态系统免受复杂、跨领域的滥用向量侵害。
当新兴威胁模式识别出 Stripe 产品弱点时,ACE 会介入,快速构建并试验技术防护措施。在实证证据和 Stripe 的 FT3(欺诈分类法 3.0)框架驱动下,你将把威胁情报转化为硬性技术控制要求(例如 API 限流、升级验证挑战、参数校验、扣款前冻结)。你将谨慎平衡安全与产品速度,通过运行实验来评估风险降低与用户转化影响。通过严格的孵化生命周期管理控制措施,你将构建自动化回归测试套件以防止复发,并与原生产品团队合作,移交成熟的长期防御措施。
岗位职责
作为滥用控制工程(ACE)团队的滥用控制工程师,你将设计、原型化并孵化技术防御措施,保护 Stripe 的金融生态系统免受复杂、跨领域的滥用向量侵害。
当新兴威胁模式识别出 Stripe 产品弱点时,ACE 会介入,快速构建并试验技术防护措施。在实证证据和 Stripe 的 FT3(欺诈分类法 3.0)框架驱动下,你将把威胁情报转化为硬性技术控制要求(例如 API 限流、升级验证挑战、参数校验、扣款前冻结)。你将谨慎平衡安全与产品速度,通过运行实验来评估风险降低与用户转化影响。通过严格的孵化生命周期管理控制措施,你将构建自动化回归测试套件以防止复发,并与原生产品团队合作,移交成熟的长期防御措施。
• 快速控制原型设计:跨 API、协议和产品边界设计、原型化并部署技术控制措施,以立即关闭高影响滥用向量。基于证据的技术要求:将实证攻击者证据以及 FT3 威胁研究、滥用研究、欺诈与安全转化为精确的技术滥用要求和控制规范。
• 控制协同设计:与 Stripe 各团队紧密合作,在支付、入驻、身份和 Connect 界面中协同设计具备韧性且安全的控制措施。
• 风险实验:运行严格实验和 A/B 测试,衡量风险降低与合法用户转化影响,优化控制措施以在消除威胁的同时尽量减少摩擦。
• 回归测试:与滥用研究团队一起构建全面的回归测试套件和自动化攻击模拟,确保已缓解的滥用向量不会复发。
• 利益相关方管理:通过定义交接标准、运营文档和目标日期来执行 ACE 的孵化模式,将成功的控制措施移交给产品团队。
任职要求
我们正在寻找满足该职位最低要求的人选。如果你满足这些要求,鼓励你申请。优先资格是加分项,而非要求。
最低要求
• 在高规模生产环境中拥有 3 年以上安全工程、软件工程、应用安全或反滥用工程经验。
• 计算机科学、网络安全、软件工程或相关技术领域的学士或硕士学位,或同等实践经验。
• 具备扎实的软件开发背景,精通 Python、Go、Java 或类似生产语言,并具备用于分析系统遥测的专家级 SQL 技能。
• 具备构建 API 级防护措施、限流框架、身份验证/授权检查或输入校验控制措施的实操工程经验。
• 具备自动化测试框架的实践经验,包括为关键后端软件编写单元测试、集成测试和回归测试。
• 具备出色的跨职能协作和沟通能力,并有与安全、产品和平台团队合作推动技术成果的记录。
• 具备设计和执行 A/B 测试、评估控制效果,并在安全防护与用户转化摩擦之间取得平衡的可靠记录。
• 在威胁建模、安全系统架构和现代应用安全设计原则方面具备深厚专业知识。
• 熟悉既有威胁框架(例如 FT3、MITRE ATT&CK),并能应用对手杀伤链分析来构建具备韧性的防御措施。
• 对金融欺诈向量、威胁行为者 TTP 和攻击者基础设施(例如账户接管、卡片测试、凭据填充)具备扎实的领域知识。
• 具备大规模数据处理平台(例如 Databricks、Trino、PySpark)的实操经验,用于监控和衡量分布式系统中的控制表现。
• 具备孵化软件功能、建立清晰运营交接标准,并将所有权无缝移交给合作工程团队的能力。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE bridges the gap using real attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale. We partner closely with Fraud, Risk and Product Engineering to run rigorous experiments, balancing aggressive risk mitigation against legitimate user conversion. Operating as both a strike team and an incubator, ACE builds automated regression suites in partnership with Abuse Research to permanently block threat recurrence and seamlessly transfers mature controls to long-term product owners across Stripe.
What you’ll do
As an Abuse Control Engineer on the Abuse Control Engineering (ACE) team, you will design, prototype, and incubate technical defenses that safeguard Stripe’s financial ecosystem against complex, cross-cutting abuse vectors.
Where emerging threat patterns identify Stripe product weaknesses, ACE steps in to rapidly build and experiment with technical safeguards. Driven by empirical evidence and Stripe’s FT3 (Fraud Taxonomy 3.0) framework, you will translate threat intelligence into hard technical control requirements (e.g., API rate-limiting, step-up challenges, parameter validation, pre-debit holds). You will carefully balance security and product velocity, running experiments to evaluate risk reduction against user conversion impact. Managing controls through a strict incubation lifecycle, you will build automated regression suites to prevent recurrence and partner with native product teams to hand off mature, long-term defenses.
岗位职责
As an Abuse Control Engineer on the Abuse Control Engineering (ACE) team, you will design, prototype, and incubate technical defenses that safeguard Stripe’s financial ecosystem against complex, cross-cutting abuse vectors.
Where emerging threat patterns identify Stripe product weaknesses, ACE steps in to rapidly build and experiment with technical safeguards. Driven by empirical evidence and Stripe’s FT3 (Fraud Taxonomy 3.0) framework, you will translate threat intelligence into hard technical control requirements (e.g., API rate-limiting, step-up challenges, parameter validation, pre-debit holds). You will carefully balance security and product velocity, running experiments to evaluate risk reduction against user conversion impact. Managing controls through a strict incubation lifecycle, you will build automated regression suites to prevent recurrence and partner with native product teams to hand off mature, long-term defenses.
• Rapid Control Prototyping: Design, prototype, and deploy technical controls across API, protocol, and product boundaries to immediately close high-impact abuse vectors. Evidence-Based Technical Requirements: Translate empirical attacker evidence and FT3 threat research Abuse Research, Fraud and Security into precise technical abuse requirements and control specifications.
• Control Co-Design: Collaborate closely with teams across Stripe to co-design resilient, secure controls across payment, onboarding, identity, and Connect surfaces.
• Risk Experimentation: Run rigorous experiments and A/B tests to measure risk reduction against legitimate user conversion impact, optimizing controls to minimize friction while neutralizing threats.
• Regression Testing: Build comprehensive regression testing suites and automated attack simulations with Abuse Research to ensure mitigated abuse vectors do not recur.
• Stakeholder Management: Execute ACE’s incubation model by defining handoff criteria, operational documentation, and target dates to transfer successful controls to product teams.
任职要求
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
• 3+ years of experience in Security Engineering, Software Engineering, Application Security, or Anti-Abuse Engineering in a high-scale production environment.
• B.S. or M.S. in Computer Science, Cybersecurity, Software Engineering, or a related technical field, or equivalent practical experience.
• Strong software development background with expert proficiency in Python, Go, Java, or similar production languages, alongside expert SQL skills for analyzing system telemetry.
• Hands-on engineering experience building API-level safeguards, rate-limiting frameworks, authentication/authorization checks, or input validation controls.
• Demonstrated experience with automated testing frameworks, including writing unit, integration, and regression tests for critical backend software.
• Strong cross-functional collaboration and communication skills, with a track record of partnering across security, product, and platform teams to drive technical outcomes.
• Proven track record of designing and executing A/B tests, evaluating control efficacy, and balancing security safeguards against user conversion friction.
• Deep expertise in threat modeling, secure system architecture, and modern application security design principles.
• Familiarity with established threat frameworks (e.g., FT3, MITRE ATT&CK) and applying adversary kill chain analysis to build resilient defenses.
• Strong domain knowledge of financial fraud vectors, threat actor TTPs, and attacker infrastructure (e.g., Account Takeover, Card Testing, Credential Stuffing).
• Hands-on experience with large-scale data processing platforms (e.g., Databricks, Trino, PySpark) to monitor and measure control performance across distributed systems.
• Demonstrated capability in incubating software features, establishing clear operational handoff criteria, and seamlessly transitioning ownership to partner engineering teams.