Security Engineer - Proactive Threat
Dublin, County Dublin, Ireland · Full Time
Be the first to apply
- Experience
- 5+ yrs
- Salary
- EUR 112,200 – EUR 168,200 / year
- Openings
- 1
- Posted
- 6 days ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Stripe
Stripe is a leading financial infrastructure platform used globally by millions of businesses, ranging from large enterprises to startups, to handle payments and grow revenue. Our mission is to expand internet GDP by making the global economy accessible to everyone, offering a unique chance to contribute meaningfully in your career.
About the Proactive Threat Team
This team focuses on identifying system weaknesses and vulnerabilities across Stripe’s products, infrastructure, and cloud environments before adversaries exploit them. Operating as a hybrid offensive unit, they perform penetration testing, red team activities simulating real-world threat actors, and collaborate with defensive teams to enhance detection capabilities and security posture. Their approach combines technical hacking skills with engineering, developing custom tools and automation to scale offensive security assessments. The team is distributed mainly across the US, working closely with engineering, security, and product stakeholders worldwide.
Key Responsibilities
- Carry out in-depth penetration tests on web applications, APIs, cloud environments (AWS, GCP, Azure), mobile apps, and internal systems.
- Lead red team operations modeling threat actor tactics such as initial access, lateral movement, persistence, and data exfiltration, especially those targeting financial services.
- Undertake assumed breach and goal-oriented assessments to evaluate detection and response effectiveness alongside defensive security teams.
- Collaborate with detection engineering, threat intelligence, and incident response teams to verify security controls, uncover gaps, and enhance detection precision.
- Provide intelligence on adversary techniques to support detection rule creation, threat hunting strategies, and incident handling procedures.
- Assist investigations by contributing offensive expertise, analyzing logs, and conducting root cause analysis.
- Design, build, and maintain specialized offensive tools, scripts, and automation frameworks to boost testing efficiency and scope.
- Create internal platforms and workflows facilitating scalable and repeatable offensive operations.
- Promote best engineering practices and contribute to shared security tooling resources.
- Automate routine testing processes, payload creation, and reporting using modern development techniques.
- Prepare clear and actionable reports communicating technical risks and remediation advice to both technical and non-technical audiences.
- Serve as a subject-matter expert, primary liaison for offensive security initiatives, and lead projects end-to-end while mentoring junior colleagues.
- Stay informed about emerging threats, vulnerabilities, and attack methods; share findings internally and contribute to the security community.
Who You Are
- Possess at least five years of experience in offensive security roles such as penetration testing or red teaming.
- Have strong proficiency in Python, Go, or similar languages, with proven experience developing tools, automation, or custom exploits.
- Demonstrate comprehensive knowledge of web application security concepts including OWASP Top 10, ASVS, and common vulnerabilities like injection and authentication flaws.
- Bring practical experience with cloud platforms (AWS, Azure, or GCP), specifically with cloud-focused attack techniques and misconfiguration management.
- Have familiarity with offensive security frameworks and tools such as Burp Suite, Cobalt Strike, Mythic, Sliver, or BloodHound.
- Understand adversary tactics and frameworks like MITRE ATT&CK, covering techniques for initial access through data exfiltration.
- Exhibit excellent communication skills able to translate complex findings into clear risk-based business recommendations.
- Think creatively and persistently like an attacker, capable of assessing risk comprehensively in complex environments.
Preferred Qualifications
- Experience in fintech, financial services, or regulated environments performing offensive security activities.
- Background in vulnerability research, exploit development, or CVE discovery.
- Collaborative experience with threat intelligence, detection engineering, and incident response teams (purple team collaborations).
- Knowledge of big data and log analysis tools such as Splunk, Databricks, PySpark, or osquery for threat hunting and investigations.
- Use of AI/LLM-assisted development tools like Claude Code, Cursor, or GitHub Copilot in offensive security workflows.
- Interest or expertise in agentic automation leveraging LLMs or autonomous agents to enhance reconnaissance, vulnerability discovery, or exploitation.
- Experience with testing AI/ML systems or LLM applications for security flaws, including prompt injection or model manipulation.
- Contributions to open-source security tools, publications, blog posts, or speaking at conferences.
- Relevant security certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security credentials.
Work Environment
The position is based at the Dublin office where employees are generally expected to work onsite full-time. The company encourages a balance of in-person collaboration with some flexibility as appropriate per role and location.
Compensation and Benefits
The annual salary range for this role in Dublin is between €112,200 and €168,200, subject to adjustment depending on location and candidate experience. The compensation package may include equity, bonuses, retirement plans, health benefits, and wellness stipends. Further benefits and specific compensation details can be discussed during the hiring process.
Equal Opportunity and Application Encouragement
At Stripe, diverse perspectives are valued and applicants are encouraged to apply even if their background does not exactly fit the listed criteria. Passion, grit, and integrity are core to the company culture, and career paths with unique experiences are welcomed.