Suggested rewrite: Led a cross-functional initiative that improved [business outcome] by [measurable result], demonstrating experience relevant to this role...
ARG Engineering Manager
Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.
- Remote from
- USA
- Salary
- Undisclosed
- Department
- Cybersecurity
- Employment
- Full Time
- Experience
- Senior
- Published
- Apply before
- 5 Nov 2026
- Listing views
- 39
- Application actions
- 3
Make your next move.
Prepare your resume, explore your fit, and draft a cover letter for this opportunity.
The role, at a glance.
Stripe is seeking an experienced Engineering Manager to lead its Abuse Research Group, which investigates emerging fraud and abuse threats across Stripe products and merchant ecosystems. The leader will manage threat intelligence analysts, fraud researchers, and detection engineers while setting a proactive research agenda. Core work includes threat-actor tracking, fraud investigations, OSINT, detection engineering, and converting findings into production protections. The role requires close partnership with Risk, Trust & Safety, Fraud Platform, Security Engineering, and external stakeholders such as law enforcement. It is a senior people-management position requiring strong security-research depth and fintech fraud expertise.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Pace & Pressure
5/5Autonomy Level
5/5Communication Load
5/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would begin with a threat and control landscape review, combining recent loss events, investigative backlogs, merchant abuse trends, intelligence reporting, and gaps in existing detections. I would prioritize initiatives by customer harm, platform exposure, adversary capability, and feasibility of converting research into preventive controls. The roadmap would include a balanced portfolio of urgent investigations, strategic actor tracking, reusable detection capabilities, and measurable regression testing.
I would validate the finding through repeatable evidence, define the relevant attack path and indicators, and assess false-positive and customer-impact risks with partner teams. Next, I would work with detection engineering and platform owners to implement telemetry, rules, risk signals, or automated response actions. I would document assumptions, establish monitoring and rollback criteria, and create regression scenarios so the control remains effective as attacker behavior evolves.
I set clear outcomes rather than measuring activity alone: validated threat hypotheses, actionable intelligence, detection coverage, reduced time to operationalization, and improved resilience against known abuse paths. I use regular research reviews to challenge evidence quality, unblock investigations, and connect work to business risk. For career growth, I create expectations for technical depth, influence, writing quality, and mentorship while preserving room for exploratory work.
I would establish an incident structure quickly, confirm scope and attacker behavior, and coordinate containment with security, risk, and affected product teams. The investigation would examine credential acquisition paths, anomalous API activity, account recovery signals, linked infrastructure, and opportunities for immediate detection or enforcement. After containment, I would drive a root-cause review, prioritize systemic control improvements, and ensure lessons are translated into durable monitoring and test cases.
Threat intelligence is valuable when it improves decisions and defenses rather than remaining descriptive reporting. In fintech, it should connect adversary infrastructure, TTPs, fraud patterns, and ecosystem signals to concrete actions such as risk rules, merchant protections, investigation prioritization, and disruption opportunities. Effective programs also communicate confidence, limitations, and expected impact clearly to technical and executive stakeholders.
About this role.
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies – from the world’s largest enterprises to the most ambitious startups – use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
The Abuse Research team is dedicated to proactively hunting for emerging abuse vectors and studying complex attacker behaviors. Rather than just reacting to alerts, the team maps complete abuse paths across Stripe products and external systems to validate novel findings and explain the underlying product conditions that enable fraud. By building continuous abuse tests with agentic testing and related systems, they translate their deep research into actionable threat advisories, strategic control recommendations, and regression scenarios that fortify Stripe’s defenses.
What you’ll do
You will lead the Abuse Research Group (ARG)—a team of threat intelligence analysts, fraud researchers, and detection engineers focused on proactively identifying and mitigating threats to Stripe and our merchants. You will set the research agenda, guiding work across threat actor tracking, hands-on fraud investigations, merchant ecosystem defense, and the detection pipelines that turn findings into production enforcement. You will scale the team through hiring, coaching, and talent development, while serving as a technical advisor on complex investigations. You will also own ARG’s relationships with key partners—including Risk, Trust & Safety, Fraud Platform, and Security Engineering.
- Lead, develop, and retain a team of threat intelligence analysts, fraud researchers, and detection engineers who thrive at the intersection of adversarial research and engineering
- Set and execute the research agenda across threat actor tracking, fraud investigation, merchant ecosystem defense, and automated detection engineering
- Provide technical depth and analytical judgment on complex investigations, including API key takeovers, account compromise campaigns, and KYC bypass techniques
- Operationalize research findings into production-level detection rules, automated response mechanisms, and cross-functional escalations
- Collaborate with Risk, Trust & Safety, Fraud Platform, and Security Engineering to translate abuse research into proactive platform protections
- Coordinate with external stakeholders, including law enforcement, to disrupt and attribute high-impact threat actors
- Coach and mentor individual contributors to support their career development while maintaining high technical standards
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 10+ years of experience leading security engineering or research teams, with a track record of managing technical ICs doing investigative, intelligence, or detection work.
- B.S. or M.S. Computer Science or related field, or equivalent experience in Security
- Experience recruiting, growing, and leading technical teams, including performance management
- Excellent written and verbal communication skills, including the ability to develop and deliver operational or incident-related information to leadership
- Familiarity with fraud and abuse patterns specific to payments and fintech
- Hands-on experience with threat intelligence tradecraft: OSINT, dark web collection, actor attribution, and working with structured intelligence frameworks (ATT&CK, STIX/TAXII, or equivalent)
- Strong understanding of threat actor tactics, techniques, and procedures (TTPs)
Preferred qualifications
- Background in security research, threat intelligence, or fraud detection engineering — prior experience leading or working in teams that study adversary behavior, build detection systems, or operate intelligence programs; experience in payments, fintech, or financial crime is a strong plus.
- Technical fluency across the domains ARG works in — threat intelligence, fraud signal development, detection engineering, and OSINT.
- Experience managing or growing technical research teams, ideally in a domain where the work is investigative, ambiguous, and doesn’t map cleanly to sprint velocity.
Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.
Apply now.
Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.
Continue on the employer website
Protect your personal information and never pay to secure an interview or job offer. .
