CHILD CONTENT-SINGLE LOADED
Stripe Offensive Security Engineer Recruitment 2026: Apply Online | jobscheck.in

⏳ Last Date to Apply:

💼
Stripe

Stripe Offensive Security Engineer Recruitment 2026: Apply Online

Offensive Security Engineer

📍 Location: Remote (United States)
💼 Type: Private
💻 Work Mode: Remote
Experience Required
5+ years
Salary / Package
$170,400 – $255,700 annually
Work Mode
Remote
Openings

Job Overview

About Stripe

Stripe is a financial infrastructure platform empowering millions of businesses worldwide, from global enterprises to ambitious startups, to manage payments, boost revenue, and unlock new growth opportunities. Our core mission is to increase the GDP of the internet, presenting an unparalleled chance to shape the global economy and undertake career-defining work.

About the Team

The Proactive Threat team operates at the forefront of security, dedicated to identifying and mitigating vulnerabilities across Stripe’s extensive systems, applications, networks, and cloud infrastructure before malicious actors can exploit them. We function as a hybrid offensive unit, conducting rigorous penetration tests, emulating sophisticated threat actors through red team operations, and collaborating closely with our defensive security counterparts to validate detection mechanisms and enhance Stripe’s overall security posture.

We are fundamentally builders. Our team thrives on developing custom tooling, advanced automation frameworks, and internal platforms that scale our offensive capabilities, ensuring repeatable and high-fidelity assessments. We firmly believe that the most effective offensive security engineers possess a dual nature: they are both skilled hackers and proficient engineers.

The team is geographically distributed across the United States, primarily aligning with Eastern and Pacific time zones. We maintain regular collaboration with security, engineering, and product stakeholders throughout Stripe, including teams based in Europe and Asia.

What You’ll Do

As an Offensive Security Engineer on the Proactive Threat team, your primary responsibility will be to simulate the tactics, techniques, and procedures (TTPs) employed by real-world adversaries. You will meticulously uncover security risks embedded within Stripe’s diverse range of products and infrastructure. This involves conducting hands-on penetration testing, spearheading red team engagements, and fostering close collaboration with our blue team colleagues to validate and refine detection and response capabilities. Your contributions will directly influence the secure development, deployment, and ongoing protection of financial infrastructure utilized by millions of businesses globally.

Beyond assessment activities, you will play a key role in designing and constructing cutting-edge offensive tooling and automation solutions that significantly amplify the team’s operational impact. You will leverage threat intelligence to strategically prioritize testing efforts, provide critical support during incident investigations when necessary, and serve as a subject-matter expert for security initiatives across the entire organization.

Responsibilities:

  • Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure.
  • Plan and execute sophisticated red team engagements that accurately emulate the TTPs of cyber and criminal threat actors targeting the financial services sector, encompassing initial access, lateral movement, persistence, and data exfiltration scenarios.
  • Perform assumed-breach and objective-based assessments to rigorously test detection and response capabilities in close coordination with defensive teams.
  • Actively partner with detection engineering, threat intelligence, and incident response teams to validate the effectiveness of security controls, identify critical coverage gaps, and enhance overall detection fidelity.
  • Contribute valuable adversary tradecraft insights to inform the development of detection rules, guide threat hunting hypotheses, and refine incident response playbooks.
  • Provide essential offensive expertise, log analysis support, and root cause analysis during incident investigations when required.
  • Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to significantly improve assessment efficiency and coverage.
  • Build internal platforms and workflows that enable scalable, repeatable, and high-fidelity offensive operations.
  • Contribute to internal security tooling repositories and champion engineering best practices within the team.
  • Automate repetitive testing tasks, payload generation, and reporting workflows utilizing modern development practices.
  • Produce clear, actionable reports that effectively communicate technical findings, associated business risks, and practical remediation guidance to both technical and non-technical stakeholders.
  • Serve as a subject-matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and company-wide security initiatives.
  • Lead offensive security projects from inception to completion, mentor junior team members, and foster a culture of continuous learning and knowledge sharing.
  • Maintain up-to-date knowledge of emerging threats, vulnerabilities, and attack techniques; share research internally and contribute to the broader security community.

Key Job Details

Company NameStripe
Job RoleOffensive Security Engineer
Experience5+ years
Salary Range$170,400 – $255,700 annually
Job TypePrivate
Work ModeRemote
Openings
Job LocationRemote (United States)

Key Responsibilities

  • Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure.
  • Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios.
  • Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams.
  • Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity.
  • Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks.
  • Support incident investigations by providing offensive expertise, log analysis, and root cause analysis when required.
  • Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverage.
  • Build internal platforms and workflows that enable scalable, repeatable offensive operations.
  • Contribute to internal security tooling repositories and champion engineering best practices within the team.
  • Automate repetitive testing tasks, payload generation, and reporting workflows using modern development practices.
  • Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non-technical stakeholders.
  • Act as a subject-matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and Stripe-wide security initiatives.
  • Lead offensive security projects end-to-end, mentor junior team members, and foster a culture of continuous learning and knowledge sharing.
  • Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and contribute to the broader security community.

Requirements & Qualifications

  • 5+ years of experience in offensive security, penetration testing, red teaming, or a related field.
  • Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits.
  • Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.).
  • Hands-on experience with cloud platforms (AWS, Azure, or GCP), including cloud-native attack techniques and misconfigurations.
  • Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks.
  • Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including TTPs for initial access, privilege escalation, lateral movement, and exfiltration.
  • Excellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk-based recommendations.
  • Ability to think like an adversary — creative, persistent, and able to holistically assess risk in complex environments.
  • Preferred: Experience in fintech, financial services, or other highly regulated environments.
  • Preferred: Background in vulnerability research, exploit development, or CVE discovery.
  • Preferred: Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations).
  • Preferred: Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support.
  • Preferred: Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows.
  • Preferred: Interest or experience in agentic automation — using LLMs or autonomous agents to augment reconnaissance, vulnerability discovery, or exploitation workflows.
  • Preferred: Experience testing AI/ML systems or LLM-based applications for security weaknesses (prompt injection, training data extraction, model manipulation, etc.).
  • Preferred: Contributions to open-source security tools, published research, blog posts, or conference presentations.
  • Preferred: Relevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications.

Required Skills

  • Python
  • Go
  • Web Application Security
  • Penetration Testing
  • Red Teaming
  • Cloud Security (AWS, Azure, GCP)
  • Burp Suite
  • Cobalt Strike
  • MITRE ATT&CK Framework
  • Adversary Emulation
  • Tool Development
  • Automation
  • Vulnerability Assessment
  • Exploit Development
  • Risk Assessment
  • Threat Intelligence
  • Incident Response Support
  • Communication Skills
  • Problem-Solving
  • AI/LLM Security (Preferred)

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

⚠️ Safety Advisory for Candidates
  • This is a private corporate career listing collected from official channels.
  • We do not charge any money for job alerts, scheduling, or application processes.
  • If a recruiter demands any payment or “security deposit” in exchange for a job offer, it is a scam.
  • Verify details on the official company portal before sharing sensitive personal details.

Frequently Asked Questions

Disclaimer: This job post is prepared by collecting data from the official career page of Stripe. We are not direct recruiters or representatives. Candidates should carefully review the requirements and policies on the company’s portal before initiating an application.
{}