Description
About the Role
You will join Stripe's Security Incident Response team as a Security Incident Response Engineer. Your primary focus will be to analyze, investigate, and respond to threats before they impact Stripe's business or users.
Responsibilities
- Analyze and investigate a broad range of threats or activities occurring on client devices
- Develop requirements for detection models and enhancements to existing systems
- Collect, transform, and ingest raw data from disparate sources into threat detection pipelines
- Streamline incident response capabilities, ensuring the tooling and processes are clear
- Work cross-functionally with security engineering and data science teams to build solutions for analyzing security events data at scale and protecting Stripe networks, systems, and data from threats
- Provide actionable insights to help identify, prevent, detect, and respond to anomalous or potentially malicious user and entity activity
- Act as the subject-matter expert and primary contact for stakeholder teams invested in Security Analytics and Detection programs as well as Stripe-wide security initiatives
- Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team
Requirements
- 3+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to security
- B.S. or M.S. Computer Science or related field, or equivalent experience
- Expert knowledge of Python and SQL, and familiarity with other programming languages
- Existing experience with log analysis, network security, digital forensics, and incident response investigations
- Proficiency with developing and using novel analytical methods to build, automate, and improve detection and response systems
- Ability to communicate results clearly and focus on impact
- Ability to think creatively and holistically about reducing risk in a complex environment
Preferred Qualifications
- An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors
- Experience with software engineering, data processing and analysis tools (e.g. Databricks/Jupyter, Trino, etc.)
- Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
- Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
- Familiarity with network observability, security software, or data engineering solutions (osquery, Splunk/LogScale, etc.)
- Experience in one or more of the following areas: user and entity behavior analytics (UEBA), security information event management (SIEM), security orchestration automation and response (SOAR), or data loss prevention (DLP)
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/stripe/jobs/8142302