Staff Security Engineer, Abuse Control
Dublin, County Dublin, Ireland · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- EUR 132,000 – EUR 198,000 / year
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Education
- Bachelor's degree or equivalent
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Stripe
Stripe is a financial infrastructure platform that supports millions of businesses worldwide—from large enterprises to startups—enabling them to accept payments, increase revenue, and unlock new business opportunities. Our goal is to raise the GDP of the internet, presenting an unparalleled chance to impact the global economy while pursuing meaningful work.
About The Team
The Abuse Control Engineering (ACE) team at Stripe acts as a rapid-response defense force and incubator for technical safeguards. We respond swiftly to emerging abuse threats by leveraging real attacker data to design and deploy protective software before vulnerabilities can be widely exploited. By collaborating closely with Fraud, Risk, Abuse Research, and Product Engineering teams, we conduct rigorous tests that balance strong risk prevention with maintaining user conversion rates. ACE operates both as a strike team and incubator, building automated regression suites to prevent recurring threats and transferring mature defenses to product teams.
Role Overview
As an Abuse Control Engineer within ACE, you'll design, prototype, and develop technical defenses that protect Stripe's financial ecosystem against sophisticated and evolving abuse patterns. Utilizing threat insights and Stripe's Fraud Taxonomy 3.0 (FT3) framework, you will convert threat intelligence into targeted technical controls such as API rate limits, additional verification steps, input validation, and pre-debit holds.
You will conduct experiments to assess how well these controls reduce risk while preserving legitimate user conversions. Managing controls through an incubation process, you'll build automated test suites to prevent regression and collaborate with product teams to transfer ownership of mature controls.
Key Responsibilities
- Quickly prototype, design, and launch technical controls across APIs, protocols, and product surfaces to counteract high-risk abuse threats.
- Interpret attacker data and research findings into clear, precise control requirements based on the FT3 threat model.
- Work alongside teams across Stripe to co-design resilient, secure controls spanning payments, onboarding, identity verification, and Connect platform elements.
- Conduct rigorous A/B tests and experiments to balance effective threat mitigation with minimal impact on user experience.
- Create extensive regression tests and automated attack simulations with Abuse Research to ensure threats do not reoccur.
- Manage the ACE incubation workflow by defining handoff criteria, preparing operational documentation, setting timelines, and transferring controls to product teams.
Required Qualifications
- At least 10 years of experience in security engineering, software engineering, application security, or anti-abuse roles within high-scale production environments.
- A bachelor’s or master’s degree in computer science, cybersecurity, software engineering, or related technical disciplines, or equivalent experience.
- Proficient software development skills in languages such as Python, Go, or Java, along with advanced SQL expertise for analyzing telemetry data.
- Experience leveraging cutting-edge AI models to support software development, learning, and analytical tasks.
- Hands-on experience implementing API-level safeguards, rate-limiting, authentication, authorization, and input validation controls.
- Familiarity with automated testing frameworks covering unit, integration, and regression tests for essential backend systems.
- Strong ability to collaborate across teams and communicate effectively with security, product, and platform stakeholders to achieve technical goals.
Preferred Qualifications
- Proven experience designing and running A/B tests to evaluate control effectiveness and balance security against user conversion challenges.
- Expertise in threat modeling, secure system architecture, and application security best practices.
- Knowledge of threat frameworks such as FT3 or MITRE ATT&CK and applying adversary kill-chain analysis to build strong defenses.
- Understanding of financial fraud tactics and attacker techniques including account takeovers, card testing, and credential stuffing.
- Experience with large-scale data platforms like Databricks, Trino, or PySpark to monitor and measure control performance across distributed systems.
- History of incubating software features with clear operational handoff criteria and transitioning ownership to engineering teams.
Workplace Expectations
Employees in Dublin are expected to work from the office 100% of the time to support local users and workflows. Generally, Stripe requires office presence at least 50% monthly, though this varies by team and location to balance in-person collaboration and flexibility.
Compensation and Benefits
The annual salary range for this position in Dublin is €132,000 to €198,000, which may vary for other locations. This includes base salary and may incorporate various career levels. Additional benefits include equity, bonuses, retirement plans, health coverage, and wellness stipends. Final compensation depends on experience, qualifications, and location.
Invitation to Apply
Stripe values passion, resilience, and integrity. Candidates are encouraged to apply even if their experience does not fully match the requirements. Diverse perspectives and rigorous thinking are welcomed, and we value those who challenge assumptions.
Minimum education
Bachelor's Degree