# Abuse Research Engineer

**Company**: Stripe
**Location**: Remote from the US
**Work arrangement**: remote
**Experience**: senior
**Job type**: full-time
**Category**: Engineering
**Industry**: Finance

**Apply**: https://job-boards.greenhouse.io/stripe/jobs/8172503?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_9c7a0ed0-5a4

## Description

## Job Overview

As an Abuse Research Engineer in the Abuse Research Group at Stripe, you will play a critical role in safeguarding Stripe's financial ecosystem by proactively hunting for advanced threats, dissecting complex fraud vectors, and extracting actionable adversary intelligence.

## Responsibilities

- Proactive Threat Hunting & Kill Chain Analysis: Formulate hypotheses and conduct iterative threat hunting operations across Stripe systems and external data.

- FT3 Taxonomy: Apply and enrich the FT3 framework across empirical datasets and incidents, standardizing threat intelligence across kill chain phases and targeted API endpoints.

- Threat Intelligence & Signal Expansion: Partner with teams like Fraud Intelligence to integrate, curate, and automate threat feeds into engineering workflows.

- Cross-Functional Advisories & Strategic Controls: Translate raw research and retrospective findings into actionable threat advisories and control recommendations for stakeholders across Fraud, Risk, Onboarding, and Security.

- Agentic Testing & Adversary Simulation: Utilize agentic automated testing frameworks to simulate adversary TTPs, validate whether deployed controls interrupt empirical kill chains, and generate regression scenarios to exercise controls.

## Requirements

- 5+ years of experience conducting threat intelligence, threat hunting, or technical incident response within cyber security, product abuse, or trust domains.

- 5+ years of experience analyzing large, complex datasets using data analytics tools to identify anomalies, map behavioral trends, and solve complex fraud problems.

- B.S. or M.S. in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.

- Expert proficiency in Python and SQL, with demonstrated experience using code and scripting to automate workflows, build investigative tools, or query big data pipelines.

- Hands-on experience in log analysis, digital forensics, and cyber investigation methodologies.

- Strong communication skills with a proven ability to translate complex technical research into clear, actionable recommendations and advisories for cross-functional partners.

## Preferred Qualifications

- Deep technical understanding of threat actor motivations, infrastructure, and TTPs specific to financial fraud.

- Familiarity with standardized taxonomies such as FT3 or MITRE ATT&CK.

- Proficiency with engineering, data processing, and analysis platforms such as Databricks, Trino, PySpark, Pandas, or Scikit-Learn.

- Proven background utilizing Threat Intelligence Platforms, tactical threat feeds, OSINT, and breach intelligence.

- Demonstrated capability building or leveraging agentic LLM tools, automated testing systems, or control validation frameworks to model adversary behavior at scale.

## Skills

### Required
- Python
- SQL
- Threat Intelligence
- Data Analytics
- Cyber Investigation

### Nice to have
- Databricks
- Trino
- PySpark
- Pandas
- Scikit-Learn
- Threat Intelligence Platforms
- OSINT

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/stripe/jobs/8172503?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
