Skip to Main Content
Location icon
London

Staff Security Engineer, Abuse Control

Stripe
Office & Professional
Office & Professional
Company logo image
Description

Location
London

Hours
Full Time

Salary
Negotiable

About the Role
Stripe is a financial infrastructure platform used by millions of companies worldwide, from large enterprises to ambitious startups. Our mission is to increase the GDP of the internet, offering a unique opportunity to impact the global economy while working on meaningful challenges.

The Abuse Control Engineering (ACE) team at Stripe is a rapid-response technical defense and control incubator focused on combating emerging abuse threats. ACE uses real-world attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale. The team partners closely with Fraud, Risk, Abuse Research, and Product Engineering to run rigorous experiments balancing risk mitigation with legitimate user activity and conversion.

As a Staff Security Engineer on the ACE team, you will design, prototype, and incubate technical defenses that protect Stripe’s financial ecosystem from complex abuse vectors. You will translate threat intelligence into precise technical control requirements such as API rate limits, step-up challenges, parameter validation, and pre-debit holds. You will run experiments to evaluate risk reduction against user impact, manage controls through an incubation lifecycle, build automated regression suites, and collaborate with product teams to transfer mature controls.

Responsibilities include:
- Rapid control prototyping across API, protocol, and product boundaries
- Translating empirical attacker evidence and threat research into technical abuse requirements
- Collaborating with cross-functional teams to design resilient controls
- Running experiments and A/B tests to optimize controls balancing security and user conversion
- Building regression test suites and automated attack simulations
- Managing stakeholder communication and executing ACE’s incubation model for control handoff

Requirements

Experience
10+ years in security engineering, software engineering, application security, or anti-abuse engineering in high-scale production environments. Proven experience building API-level safeguards, rate-limiting frameworks, authentication or authorization checks, and input-validation controls. Proficiency in Python, Go, Java, or similar languages and advanced SQL skills. Experience with automated testing frameworks and writing unit, integration, and regression tests. Familiarity with frontier AI models for software development and analysis. Strong cross-functional collaboration and communication skills.

About you
You are a proactive engineer with a strong software development background and a passion for designing secure, scalable systems. You thrive in fast-paced environments, enjoy working collaboratively across teams, and have a data-driven approach to balancing security and user experience. You are comfortable running experiments and interpreting complex telemetry data to inform technical decisions.

Qualifications
A bachelor’s or master’s degree in computer science, cybersecurity, software engineering, or a related technical field, or equivalent practical experience. Preferred qualifications include experience designing and executing A/B tests, expertise in threat modeling and secure systems architecture, familiarity with threat frameworks such as FT3 or MITRE ATT&CK, knowledge of financial fraud vectors and attacker tactics, and hands-on experience with large-scale data-processing platforms like Databricks, Trino, or PySpark. Experience incubating software features and managing operational handoff to partner teams is a plus.

Expiry date: 22/10/2026
Staff Security Engineer, Abuse Control
Company:
Stripe
Job Type:
Full-time
Location:
London