Location
London
Hours
Full Time
Salary
Negotiable
About the Role
Stripe is a financial infrastructure platform used by millions of companies worldwide, from large enterprises to ambitious startups. Our mission is to increase the GDP of the internet, offering a unique opportunity to impact the global economy while working on meaningful challenges.
The Abuse Control Engineering (ACE) team at Stripe is a rapid-response technical defense and control incubator focused on combating emerging abuse threats. ACE uses real-world attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale. The team partners closely with Fraud, Risk, Abuse Research, and Product Engineering to run rigorous experiments balancing risk mitigation with legitimate user activity and conversion.
As a Staff Security Engineer on the ACE team, you will design, prototype, and incubate technical defenses that protect Stripe’s financial ecosystem from complex abuse vectors. You will translate threat intelligence into precise technical control requirements such as API rate limits, step-up challenges, parameter validation, and pre-debit holds. You will run experiments to evaluate risk reduction against user impact, manage controls through an incubation lifecycle, build automated regression suites, and collaborate with product teams to transfer mature controls.
Responsibilities include:
- Rapid control prototyping across API, protocol, and product boundaries
- Translating empirical attacker evidence and threat research into technical abuse requirements
- Collaborating with cross-functional teams to design resilient controls
- Running experiments and A/B tests to optimize controls balancing security and user conversion
- Building regression test suites and automated attack simulations
- Managing stakeholder communication and executing ACE’s incubation model for control handoff
Experience
10+ years in security engineering, software engineering, application security, or anti-abuse engineering in high-scale production environments. Proven experience building API-level safeguards, rate-limiting frameworks, authentication or authorization checks, and input-validation controls. Proficiency in Python, Go, Java, or similar languages and advanced SQL skills. Experience with automated testing frameworks and writing unit, integration, and regression tests. Familiarity with frontier AI models for software development and analysis. Strong cross-functional collaboration and communication skills.
About you
You are a proactive engineer with a strong software development background and a passion for designing secure, scalable systems. You thrive in fast-paced environments, enjoy working collaboratively across teams, and have a data-driven approach to balancing security and user experience. You are comfortable running experiments and interpreting complex telemetry data to inform technical decisions.
Qualifications
A bachelor’s or master’s degree in computer science, cybersecurity, software engineering, or a related technical field, or equivalent practical experience. Preferred qualifications include experience designing and executing A/B tests, expertise in threat modeling and secure systems architecture, familiarity with threat frameworks such as FT3 or MITRE ATT&CK, knowledge of financial fraud vectors and attacker tactics, and hands-on experience with large-scale data-processing platforms like Databricks, Trino, or PySpark. Experience incubating software features and managing operational handoff to partner teams is a plus.
Stripe










