New The Skills of Tomorrow: how AI-exposed is every skill in 2026? See the data →
Stripe

Security Incident Response Manager, Abuse Operations

Stripe
Apply →
remote senior full-time Seattle, SF, NYC, Chicago, Atlanta, Remote in the US

First indexed 10 Sept 2026

Description

Job Description

Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world's largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet.

Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group neutralizes active attacks, gathers requirements for operational tooling, and leads incidents.

In this role, you will play a critical part in safeguarding our financial ecosystem by investigating high-risk accounts, identifying complex fraud patterns, performing post-incident analyses, and driving cross-functional improvements to scale fraud detection.

Responsibilities

  • Lead fraud and abuse incident response end-to-end as Incident Response Manager (IRM), coordinating workstreams, investigating high risk activity and accounts, and making actionable mitigation recommendations under pressure.
  • Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped (Fraud Taxonomy 3.0) detection and signals enrichment to reduce uncertainty and accelerate response.
  • Analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.
  • Develop, document, and execute incident response strategies, runbooks, and capabilities to continuously improve fraud and abuse detection and prevention.
  • Partner cross-functionally with security, data science, legal, and policy teams to build agentic response solutions, refine KPIs, and deliver clear incident reporting.
  • Mentor teammates, lead key incident response engineering projects, and elevate quality standards across the team.

Requirements

  • 10+ years of experience leading security or fraud incident response;
  • B.S./M.S. in Computer Science or equivalent experience.
  • Expert knowledge of Python and SQL, and familiarity with other programming languages
  • Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
  • Proven ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
  • Strong written and verbal communication skills with a track record of driving cross-functional alignment with minimal oversight.

Preferred Qualifications

  • Broad expertise across fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
  • An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
  • Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
  • Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
  • Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
  • Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting: https://job-boards.greenhouse.io/stripe/jobs/8172497