[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![Stripe logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/WRILS-201011073943-272457.png)](https://jobicy.com/company/stripe.md)Remote opportunity at[Stripe](https://jobicy.com/company/stripe.md)

# Abuse Research Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/stripe.md)Share11 Sep 2026Published41Listing views1Application actions11 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryStripe is seeking a senior Abuse Research Engineer to proactively identify and disrupt fraud and product-abuse threats across its financial platform. The role centers on hypothesis-driven threat hunting, adversary kill-chain analysis, threat-intelligence integration, and application of Stripe's FT3 fraud taxonomy. The engineer will use Python, SQL, large-scale telemetry, forensic methods, and agentic testing workflows to validate controls and generate regression scenarios. Close collaboration with Fraud Operations, Risk, Onboarding, Strategy, and Security is required to convert technical research into practical controls and advisories.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

4/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a highly specialized senior role requiring deep experience in cyber threat hunting, financial-fraud TTPs, large-scale data analysis, and automated adversary simulation. Success depends on independently developing research hypotheses while influencing multiple technical and operational teams.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$185,000US market range$155k–$225k0$248k

AI insightNo actual salary, pay range, or compensation amount is disclosed in the posting. The figures are estimated annual USD base-pay market ranges for a US-remote senior cybersecurity and fraud-threat research engineer, reflecting the role's 5+ years of specialized experience, Python/SQL requirements, and fintech security scope; actual Stripe compensation may also include bonus and equity.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Threat Hunting](https://jobicy.com/jobs?search_keywords=Threat%20Hunting.md)[Fraud Prevention](https://jobicy.com/jobs?search_keywords=Fraud%20Prevention.md)[Threat Intelligence](https://jobicy.com/jobs?search_keywords=Threat%20Intelligence.md)[Python](https://jobicy.com/jobs?search_keywords=Python.md)[SQL](https://jobicy.com/jobs?search_keywords=SQL.md)[Log Analysis](https://jobicy.com/jobs?search_keywords=Log%20Analysis.md)[Digital Forensics](https://jobicy.com/jobs?search_keywords=Digital%20Forensics.md)[Adversary Simulation](https://jobicy.com/jobs?search_keywords=Adversary%20Simulation.md)[Financial Crime](https://jobicy.com/jobs?search_keywords=Financial%20Crime.md)[MITRE ATT&CK](https://jobicy.com/jobs?search_keywords=MITRE%20ATTCK.md)

Sample interview questionsDescribe how you would investigate a suspected credential-stuffing campaign affecting an API platform.I would first define measurable hypotheses around authentication failures, IP and device reuse, credential velocity, endpoint sequences, and downstream account activity. I would query relevant authentication and API telemetry, cluster suspicious behavior, enrich indicators with internal and external intelligence, then map the observed activity to a kill chain. Finally, I would recommend and test layered controls such as rate limits, risk-based challenges, fingerprinting, and detection rules, measuring whether they interrupt the behavior without materially harming legitimate users.

How have you used Python and SQL to improve a threat-hunting or fraud-investigation workflow?

I use SQL to efficiently isolate behavioral patterns in large event datasets and Python to automate enrichment, entity resolution, scoring, and repeatable reporting. For example, I would build a pipeline that identifies anomalous API sequences, joins them to account and payment outcomes, enriches associated infrastructure, and produces prioritized investigation cases. I emphasize versioned logic, clear validation criteria, and monitoring so that successful research can become durable detection or control coverage.

How would you translate a complex fraud investigation into an advisory for nontechnical stakeholders?

I would begin with the business impact, affected workflow, confidence level, and the attacker path in plain language. I would then provide evidence-backed findings, identify the specific product conditions enabling the behavior, and separate immediate mitigations from longer-term control recommendations. The advisory would assign clear owners, explain expected tradeoffs such as user friction or false positives, and define metrics for validating effectiveness.

What makes an adversary simulation useful for validating anti-abuse controls?

A useful simulation reproduces realistic attacker goals, sequences, constraints, and evasive behaviors rather than merely generating synthetic volume. I would define expected control-interruption points across the kill chain, execute safe and authorized test scenarios, and capture telemetry to verify both prevention and detection. The outcome should become a repeatable regression scenario that detects control degradation as products and attacker techniques evolve.

How would you apply a taxonomy such as FT3 or MITRE ATT&CK during an investigation?

I would use the taxonomy to normalize raw observations into consistent phases, techniques, targets, and indicators so patterns can be compared across incidents and teams. This improves coverage analysis by showing where controls, telemetry, or ownership are missing along the adversary path. I would also enrich the taxonomy with empirical findings so it remains operationally useful for detections, simulations, reporting, and strategic control planning.

### Who we are

### About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

### About the team

Abuse Research Group (ARG) handles proactive threat hunting and adversary behavior analysis across Stripe products. Rather than reacting to alerts, the team maps end-to-end fraud and abuse paths, validates novel attack vectors, and identifies product conditions that enable fraud. Using agentic automated testing and simulation tools, ARG translates research into actionable threat advisories, strategic control recommendations, and regression scenarios to systematically eliminate vulnerabilities.

### What you’ll do

As an Abuse Research Engineer in the Abuse Research Group, you will play a critical role in safeguarding Stripe’s financial ecosystem by proactively hunting for advanced threats, dissecting complex fraud vectors, and extracting actionable adversary intelligence. Rather than relying solely on reactive alerts, you will develop and execute hypothesis-driven threat hunting operations across internal telemetry and external sources to uncover fraudulent tools, tactics, and techniques (TTPs) before they impact Stripe’s platform. Central to this work is FT3 (Fraud Taxonomy 3.0), Stripe’s multi-layered taxonomy that decomposes monolithic fraud into structured kill chains. Collaborating cross-functionally with Fraud Ops, Strategy, Risk, Onboarding, and Security, you will integrate threat intelligence, build agentic simulation workflows, and systematically eliminate product vulnerabilities.

### Responsibilities

* Proactive Threat Hunting & Kill Chain Analysis: Formulate hypotheses and conduct iterative threat hunting operations across Stripe systems and external data.
* FT3 Taxonomy: Apply and enrich the FT3 framework across empirical datasets and incidents, standardizing threat intelligence across kill chain phases and targeted API endpoints.
* Threat Intelligence & Signal Expansion: Partner with teams like Fraud Intelligence to integrate, curate, and automate threat feeds into engineering workflows.
* Cross-Functional Advisories & Strategic Controls: Translate raw research and retrospective findings into actionable threat advisories and control recommendations (policy, technical systems, support workflows, and detection mechanisms) for stakeholders across Fraud, Risk, Onboarding, and Security.
* Agentic Testing & Adversary Simulation: Utilize agentic automated testing frameworks to simulate adversary TTPs, validate whether deployed controls interrupt empirical kill chains, and generate regression scenarios to exercise controls.

### Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

### Minimum requirements

* 5+ years of experience conducting threat intelligence, threat hunting, or technical incident response within cyber security, product abuse, or trust domains.
* 5+ years of experience analyzing large, complex datasets using data analytics tools to identify anomalies, map behavioral trends, and solve complex fraud problems.
* B.S. or M.S. in Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience.
* Expert proficiency in Python and SQL, with demonstrated experience using code and scripting to automate workflows, build investigative tools, or query big data pipelines.
* Hands-on experience in log analysis (e.g., application logs, API route telemetry, network security events), digital forensics, and cyber investigation methodologies.
* Strong communication skills with a proven ability to translate complex technical research into clear, actionable recommendations and advisories for cross-functional partners.

### Preferred qualifications

* Deep technical understanding of threat actor motivations, infrastructure, and TTPs specific to financial fraud (e.g., ATO, Card Testing, Credential Stuffing).
* Familiarity with standardized taxonomies such as FT3 or MITRE ATT&CK.
* Proficiency with engineering, data processing, and analysis platforms such as Databricks, Trino, PySpark, Pandas, or Scikit-Learn.
* Proven background utilizing Threat Intelligence Platforms (TIPs), tactical threat feeds, OSINT, and breach intelligence.
* Demonstrated capability building or leveraging agentic LLM tools, automated testing systems, or control validation frameworks to model adversary behavior at scale.

Show more

[Apply now >](https://jobicy.com/jobs/153053-abuse-research-engineer.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Ping Identity logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/09/63e8d5a6-221.png)
Ping Identity  Sep 11

### [Cyber Security Engineer II](https://jobicy.com/jobs/153056-cyber-security-engineer-ii.md)

About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it’s not just…

*
![Luna Physical Therapy logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/07/fcb34e841928-221.webp)
Luna Physical Therapy  Sep 11

### [Director , Information Security and IT](https://jobicy.com/jobs/153041-director-information-security-and-it.md)

Luna is seeking a Director of Information Security & IT to lead the strategy, execution, and continuous evolution of the company’s enterprise technology and information security programs. Reporting to the…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert Intern – AI Track](https://jobicy.com/jobs/152979-blockchain-security-expert-intern-ai-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Security Audit Track](https://jobicy.com/jobs/152975-blockchain-security-expert-security-audit-track.md)

About You You’re a self-starter. You believe in tackling the most important problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand that #startuplife…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Chain Security Evaluation Track](https://jobicy.com/jobs/152970-blockchain-security-expert-chain-security-evaluation-track.md)

About You You’re a self-starter who thrives on tackling the toughest and most meaningful problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand…

*
![Synthesia logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/c69aad11-221.webp)
Synthesia  Sep 10

### [SecOps Security Engineer (Staff-level, L6)](https://jobicy.com/jobs/152968-secops-security-engineer-staff-level-l6.md)

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Anti Defect Track](https://jobicy.com/jobs/152966-blockchain-security-expert-anti-defect-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![Fortive logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/08ee6cc3-221.webp)
Fortive  Sep 10

### [Chief Information Security Officer](https://jobicy.com/jobs/149008-chief-information-security-officer.md)

Position Summary The Chief Information Security Officer (CISO) owns enterprise security strategy, risk management, and compliance for the FAL Group of companies under Fortive (Accruent, Gordian, and ServiceChannel) all of…

*
![Vercel logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/a6aded72-221.png)
Vercel  Sep 9

### [Security Engineer, Cloud](https://jobicy.com/jobs/152929-security-engineer-cloud.md)

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built….

*
![Tremendous logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/01/c2bd8be5-221.jpeg)
Tremendous  Sep 9

### [Head of Security](https://jobicy.com/jobs/152862-head-of-security.md)

Tremendous is the global platform built for businesses to send payouts—gift cards and money—to anyone, anywhere, instantly. We’re trusted by 20,000+ organizations, from startups to giants like Atlassian, MIT, and…