stripe
Security Engineer, Bridge
About this role
Stripe is seeking a Security Engineer to design and build Bridge's security foundation from scratch, establishing the security program for a new stablecoin-based payments platform. You'll architect security systems, threat modeling, and compliance frameworks while collaborating with engineering and crypto teams to enable fast, secure global money movement.
What you'll do
- Design and implement Bridge's security roadmap from first principles through production
- Identify and rapidly address critical security risks across the platform
- Lead threat modeling and hardening for money movement systems with crypto and infrastructure teams
- Build key security capabilities including monitoring, secrets management, incident response, and access controls
- Integrate Stripe security infrastructure where applicable and develop custom solutions as needed
- Ensure compliance and audit readiness as Bridge scales to regulated markets
What they're looking for
- Security program design and scaling
- Threat modeling and risk assessment
- Backend application security (Ruby preferred)
- Incident response and monitoring
- Access control and secrets management
- CI/CD pipeline security
- Compliance and audit preparation
- Cross-functional collaboration and communication
Opens the official application on the employer’s site. No login required.
stripe
Stripe builds payment infrastructure and financial services platforms, offering APIs and tools that enable developers and businesses to process transactions, detect fraud, verify identity, and manage security at scale. The company is hiring Backend Engineers, Full Stack Engineers, ML Engineers, AI Engineers, and Security Engineers to develop core platform systems, payment intelligence, customer support infrastructure, and security data platforms.
- Website
- stripe.com
Likely interview questions
- Describe your experience building a security program from the ground up at a startup—what were your biggest priorities and how did you sequence them?
- How do you balance moving fast in a startup environment with maintaining security rigor, and can you give a specific example?