stripe
Offensive Security Engineer
About this role
Stripe seeks an experienced Offensive Security Engineer to identify vulnerabilities across its financial infrastructure through penetration testing, red team operations, and custom tooling development. You'll simulate real-world adversary tactics, collaborate with defensive teams to validate security controls, and build automation platforms that scale offensive capabilities.
What you'll do
- Conduct penetration tests on web applications, APIs, cloud environments, mobile apps, and internal infrastructure
- Plan and execute red team engagements emulating financial threat actor tactics including initial access, lateral movement, and data exfiltration
- Perform assumed-breach assessments to test detection and response capabilities with defensive teams
- Design and develop custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency
- Produce clear, actionable reports translating technical findings into risk-based recommendations for technical and non-technical stakeholders
- Stay current with emerging threats and vulnerabilities; contribute research and knowledge sharing internally
What they're looking for
- Penetration testing and red teaming
- Python, Go, or similar programming languages
- Web application security (OWASP Top 10, ASVS)
- Cloud platforms (AWS, Azure, GCP) and cloud-native attacks
- Offensive tools (Burp Suite, Cobalt Strike, Mythic, BloodHound)
- MITRE ATT&CK framework and adversary tradecraft
- Incident investigation and log analysis
- Tool development and automation engineering
Opens the official application on the employer’s site. No login required.
stripe
Stripe builds payment infrastructure and financial services platforms, offering APIs and tools that enable developers and businesses to process transactions, detect fraud, verify identity, and manage security at scale. The company is hiring Backend Engineers, Full Stack Engineers, ML Engineers, AI Engineers, and Security Engineers to develop core platform systems, payment intelligence, customer support infrastructure, and security data platforms.
- Website
- stripe.com
Likely interview questions
- Describe a complex penetration test you led—what was your methodology for discovering critical vulnerabilities others missed?
- How do you approach designing red team engagements that effectively test both detection capabilities and incident response procedures?