Security Engineer - Offensive Security
Role details
Job location
Tech stack
Job description
OverviewStripe is a financial infrastructure platform for businesses. Our mission is to increase the GDP of the internet, and we have a substantial amount of work ahead. The Proactive Threat team identifies vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure - before adversaries do. We operate as a hybrid offensive function, conducting penetration testing, emulating real-world threat actors through red team operations, and partnering with defensive security teams to validate detection capabilities and improve Stripe's overall security posture.We are builders first. The team develops custom tooling, automation frameworks, and internal platforms that scale our offensive capabilities and enable repeatable, high-fidelity assessments. The team is distributed across the United States, primarily operating in Eastern and Pacific time zones, and collaborates with security, engineering, and product stakeholders across Stripe, including teams in Europe and Asia.ResponsibilitiesConduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructurePlan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenariosPerform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teamsPartner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelityContribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooksSupport incident investigations by providing offensive expertise, log analysis, and root cause analysis when requiredDesign, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverageBuild internal platforms and workflows that enable scalable, repeatable offensive operationsContribute to internal security tooling repositories and champion engineering best practices within the teamAutomate repetitive testing tasks, payload generation, and reporting workflows using modern development practicesProduce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non-technical stakeholdersAct as a subject-matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and Stripe-wide security initiativesLead offensive security projects end-to-end, mentor junior team members, and foster a culture of continuous learning and knowledge sharingStay current with emerging threats, vulnerabilities, and attack techniques; share research internally and contribute to the broader security communityWho you areMinimum requirements5+ years of experience in offensive security, penetration testing, red teaming, or a related fieldStrong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploitsDeep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.)Hands-on experience with cloud platforms (AWS, Azure, or GCP), including cloud-native attack techniques and misconfigurationsProficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworksFamiliarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including TTPs for initial access, privilege escalation, lateral movement, and exfiltrationExcellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk-based recommendationsAbility to think like an adversary - creative, persistent, and able to holistically assess risk in complex environmentsPreferred qualificationsExperience conducting offensive security in fintech, financial services, or other highly regulated environmentsBackground in vulnerability research, exploit development, or CVE discoveryExperience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations)Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative supportProficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflowsInterest or experience in agentic automation - using LLMs or autonomous agents to augment reconnaissance, vulnerability discovery, or exploitation workflowsExperience testing AI/ML systems or LLM-based applications for security weaknesses (prompt injection, training data extraction, model manipulation, etc.)Contributions to open-source security tools, published research, blog posts, or conference presentationsRelevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications#J-*****-Ljbffr
Requirements
5+ years of experience in offensive security, penetration testing, red teaming, or a related field Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.) Hands-on experience with cloud platforms (AWS, Azure, or GCP), including cloud-native attack techniques and misconfigurations Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including TTPs for initial access, privilege escalation, lateral movement, and exfiltration Excellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk-based recommendations Ability to think like an adversary - creative, persistent, and able to holistically assess risk in complex environments Preferred qualifications Experience conducting offensive security in fintech, financial services, or other highly regulated environments Background in vulnerability research, exploit development, or CVE discovery Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations) Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows Interest or experience in agentic automation - using LLMs or autonomous agents to augment reconnaissance, vulnerability discovery, or exploitation workflows Experience testing AI/ML systems or LLM-based applications for security weaknesses (prompt injection, training data extraction, model manipulation, etc.) Contributions to open-source security tools, published research, blog posts, or conference presentations Relevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications #J-*****-Ljbffr