Security Incident Response Engineer
Stripe · US Remote
About this role
**About Stripe** Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet. **About the team** The Security Incident Response team analyzes, investigates, and responds to threats before they impact Stripe’s business or users. From external attacks to insider threats, the team responds with speed and precision, remediates, and supports the incident postmortem process. The team is distributed across multiple AMER time zones and regularly coordinates with stakeholders in EMEA and APAC. **What you’ll do** - Use your security engineering experience to improve incident response capabilities at Stripe. - Focus on user and entity behavior analytics and endpoint hardening to distinguish legitimate from malicious activity. - Use threat intelligence and collected telemetry to build Stripe-specific signal enrichment logic and incident response solutions that scale. - Apply analytics during security incidents to reduce uncertainty, uncover root causes, and inform future prevention and detection. **Responsibilities** - Analyze and investigate a broad range of threats or activities occurring on client devices. - Develop requirements for detection models and enhancements to existing systems. - Collect, transform, and ingest raw data from disparate sources into threat detection pipelines. - Streamline incident response capabilities so tooling and processes are clear. - Work cross-functionally with security engineering and data science teams to analyze security events data at scale and protect Stripe networks, systems, and data. - Provide actionable insights to identify, prevent, detect, and respond to anomalous or potentially malicious user and entity activity. - Serve as a subject-matter expert and primary contact for stakeholder teams invested in Security Analytics and Detection programs and broader security initiatives. - Collaborate effectively, lead projects, mentor others, and develop and champion quality standards. **Who you are** We’re looking for candidates who meet the minimum requirements; preferred qualifications are a bonus. **Minimum requirements** - 3+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to security. - B.S. or M.S. Computer Science (or related field), or equivalent experience. - Expert knowledge of Python and SQL, and familiarity with other programming languages. - Experience with log analysis (e.g., first/third-party applications, system/data access, event logs), network security, digital forensics, and incident response investigations. - Proficiency developing and using novel analytical methods to build, automate, and improve detection and response systems. - Ability to communicate results clearly and focus on impact. - Ability to think creatively and holistically about reducing risk in a complex environment. **Preferred qualifications** - Adversarial mindset; understanding threat actor goals, behaviors, and TTPs. - Experience with software engineering and data processing/analysis tools (e.g., Databricks/Jupyter, Trino). - Familiarity with open-source frameworks for big data processing and/or data science (e.g., PySpark, Pandas, Sci-kit Learn). - Experience with tactical threat intelligence and/or hunting sophisticated thr
Listing freshness
CronJobs last confirmed this listing 23h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.