CronJobs

security jobs

Offensive Security Engineer

Stripe · US - Remote

hybridunknown$170,400–$255,700Posted Sep 23, 2026AWSGCPAzure

Apply on the employer site

About this role

**Offensive Security Engineer — Proactive Threat (Stripe)** ## Who we are Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet. ### About the team The Proactive Threat team identifies vulnerabilities and security weaknesses across Stripe’s systems, applications, networks, and cloud infrastructure—before adversaries do. We operate as a hybrid offensive function, conducting penetration testing, emulating real-world threat actors through red team operations, and partnering with defensive security teams to validate detection capabilities and improve Stripe’s overall security posture. We’re builders first: the team develops custom tooling, automation frameworks, and internal platforms to scale offensive capabilities and enable repeatable, high-fidelity assessments. ## What you’ll do As an Offensive Security Engineer, you’ll simulate real-world adversary tactics, techniques, and procedures (TTPs) to uncover security risks across Stripe’s products and infrastructure. You’ll conduct hands-on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities. Beyond assessments, you’ll design and build offensive tooling and automation, leverage threat intelligence to prioritize testing, contribute to incident investigations when needed, and serve as a subject-matter expert for security initiatives across the company. ## Responsibilities - Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure - Plan and execute red team engagements emulating the TTPs of cyber and criminal threat actors targeting financial services (e.g., initial access, lateral movement, persistence, and data exfiltration) - Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams - Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord