Stripe
Offensive Security Engineer
US - Remote
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.7M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Role family
- Engineering
- Seniority
- Mid level
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 25 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
The Proactive Threat team is responsible for identifying vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure — before adversaries do. We operate as a hybrid offensive function: conducting penetration testing, emulating real-world threat actors through red team operations, and partnering closely with our defensive security teams to validate detection capabilities and improve Stripe's overall security posture.
We are builders first. Our team develops custom tooling, automation frameworks, and internal platforms that scale our offensive capabilities and enable repeatable, high-fidelity assessments. We believe the best offensive security engineers are equal parts hacker and engineer.
The team is distributed across the United States, primarily operating in Eastern and Pacific time zones, and collaborates regularly with security, engineering, and product stakeholders across Stripe — including teams in Europe and Asia.
What you'll do
As an Offensive Security Engineer on the Proactive Threat team, you will simulate the tactics, techniques, and procedures (TTPs) of real-world adversaries to uncover security risks across Stripe's products and infrastructure. You'll conduct hands-on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities. Your work will directly influence how Stripe builds, ships, and secures financial infrastructure used by millions of businesses worldwide.
Beyond assessments, you'll design and build offensive tooling and automation that amplifies the team's impact. You'll leverage threat intelligence to prioritize testing efforts, contribute to incident investigations when needed, and act as a subject-matter expert for security initiatives across the company.
Responsibilities
Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure
Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios
Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams
Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity
Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks
Support incident investigations by providing offensive expertise, log analysis, and root cause analysis when required
Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverage
Build internal platforms and workflows that enable scalable, repeatable offensive operations
Contribute to internal security tooling repositories and champion engineering best practices within the team
Automate repetitive testing tasks, payload generation, and reporting workflows using modern development practices
Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non-technical stakeholders
Act as a subject-matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and Stripe-wide security initiatives
Lead offensive security projects end-to-end, mentor junior team members, and foster a culture of continuous learning and knowledge sharing
Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and contribute to the broader security community
Who you are
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
5+ years of experience in offensive security, penetration testing, red teaming, or a related field
Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits
Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.)
Hands-on experience with cloud platforms (AWS, Azure, or GCP), including cloud-native attack techniques and misconfigurations
Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks
Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including TTPs for initial access, privilege escalation, lateral movement, and exfiltration
Excellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk-based recommendations
Ability to think like an adversary — creative, persistent, and able to holistically assess risk in complex environments
Preferred qualifications
Experience conducting offensive security in fintech, financial services, or other highly regulated environments
Background in vulnerability research, exploit development, or CVE discovery
Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations)
Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support
Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows
Interest or experience in agentic automation — using LLMs or autonomous agents to augment reconnaissance, vulnerability discovery, or exploitation workflows
Experience testing AI/ML systems or LLM-based applications for security weaknesses (prompt injection, training data extraction, model manipulation, etc.)
Contributions to open-source security tools, published research, blog posts, or conference presentations
Relevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications
Location
This role is remote within the United States. While you are welcome to visit Stripe offices for team meetings, on-sites, and events, our expectation is that you would regularly work from home. The team primarily coordinates across Eastern and Pacific time zones, with regular collaboration with stakeholders in Europe and Asia.
Compensation & Benefits
The annual US base salary range for this role is $170,400 – $255,700. This range may span multiple career levels and will be refined during the interview process based on experience, qualifications, and location.
Additional benefits include:
Equity participation in Stripe's growth
401(k) plan with matching contributions from day one
Comprehensive medical, dental, and vision coverage
Wellness stipends
Annual budget for training, certifications, and conference attendance
Listed on hirly, a job board. hirly is not the employer: Stripe is hiring for this role.
Similar jobs
- Security Engineer II - Design Review/Threat ModelingUber · Seattle, WA, United StatesFirst seen today
- Security Engineer II - Design Review / Threat ModellingUber · San Francisco, CA, United States; Seattle, WA, United States; Sunnyvale, CA, United StatesFirst seen today
- Security Engineer, Level 4Snapchat · 3 LocationsFirst seen today
- Security Engineer, Information Systems, Full Time, DayValleyhealth · Kraft CenterFirst seen today
- Security EngineerTruist · 2 LocationsFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job