# Incident Response Manager - Abuse Operations

**Company**: Stripe
**Location**: Dublin
**Experience**: senior
**Job type**: full-time
**Category**: IT
**Industry**: Finance

**Apply**: https://job-boards.greenhouse.io/stripe/jobs/8172493?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_07ee7177-50a

## Description

## Job Overview

As an Incident Response Manager - Abuse Operations at Stripe, you will play a critical part in safeguarding the company's financial ecosystem by investigating high-risk accounts, identifying complex fraud patterns, performing post-incident analyses, and driving cross-functional improvements to scale fraud detection.

## Responsibilities

- Lead fraud and abuse incident response end-to-end as Incident Response Manager (IRM), coordinating workstreams, investigating high-risk activity and accounts, and making actionable mitigation recommendations under pressure.

- Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped (Fraud Taxonomy 3.0) detection and signals enrichment to reduce uncertainty and accelerate response.

- Analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.

- Develop, document, and execute incident response strategies, runbooks, and capabilities to continuously improve fraud and abuse detection and prevention.

- Partner cross-functionally with security, data science, legal, and policy teams to build agentic response solutions, refine KPIs, and deliver clear incident reporting.

- Mentor teammates, lead key incident response engineering projects, and elevate quality standards across the team.

## Requirements

- 10+ years of experience leading security or fraud incident response;

- B.S./M.S. in Computer Science or equivalent experience;

- Expert knowledge of Python and SQL, and familiarity with other programming languages;

- Existing experience with log analysis, network security, digital forensics, and incident response investigations;

- Proven ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations;

- Strong written and verbal communication skills with a track record of driving cross-functional alignment with minimal oversight.

## Preferred Qualifications

- Broad expertise across fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment;

- An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors;

- Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.);

- Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.);

- Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment;

- Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges.

## Skills

### Required
- Python
- SQL
- log analysis
- network security
- digital forensics
- incident response

### Nice to have
- Databricks
- Trino
- PySpark
- Pandas
- Sci-kit Learn
- threat intelligence

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/stripe/jobs/8172493?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
