[All remote jobs](https://jobicy.com/jobs.md)[![Stripe logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/WRILS-201011073943-272457.png)](https://jobicy.com/company/stripe.md)[Stripe](https://jobicy.com/company/stripe.md)

# ARG Engineering Manager

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/stripe.md)ShareRemote from[USA](https://jobicy.com/job-region/usa.md)SalaryUndisclosedDepartment[Cybersecurity](https://jobicy.com/categories/cybersecurity.md)EmploymentFull TimeExperienceSeniorPublished6 Oct 2026Apply before5 Nov 2026Listing views46Application actions3Application toolkit

## Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

## The role, at a glance.

Stripe is seeking an experienced Engineering Manager to lead its Abuse Research Group, which investigates emerging fraud and abuse threats across Stripe products and merchant ecosystems. The leader will manage threat intelligence analysts, fraud researchers, and detection engineers while setting a proactive research agenda. Core work includes threat-actor tracking, fraud investigations, OSINT, detection engineering, and converting findings into production protections. The role requires close partnership with Risk, Trust & Safety, Fraud Platform, Security Engineering, and external stakeholders such as law enforcement. It is a senior people-management position requiring strong security-research depth and fintech fraud expertise.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a highly senior leadership role requiring more than 10 years of security leadership experience, technical credibility in adversarial research, and the ability to operationalize ambiguous investigations into scalable controls. The role combines people management, fraud and threat-intelligence expertise, cross-functional influence, and incident-level judgment in a high-impact payments environment.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$250,000US market range$210k–$300k0$330k

AI insightNo actual salary or compensation range is disclosed in the posting. These are estimated annual US-market base-salary figures in USD for a senior cybersecurity engineering manager leading threat intelligence, fraud research, and detection engineering at a major fintech company; total compensation may be materially higher with bonus and equity.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Threat Intelligence](https://jobicy.com/jobs?search_keywords=Threat%20Intelligence.md)[Fraud Detection](https://jobicy.com/jobs?search_keywords=Fraud%20Detection.md)[Detection Engineering](https://jobicy.com/jobs?search_keywords=Detection%20Engineering.md)[Security Research](https://jobicy.com/jobs?search_keywords=Security%20Research.md)[OSINT](https://jobicy.com/jobs?search_keywords=OSINT.md)[Threat Hunting](https://jobicy.com/jobs?search_keywords=Threat%20Hunting.md)[Fintech Security](https://jobicy.com/jobs?search_keywords=Fintech%20Security.md)[People Management](https://jobicy.com/jobs?search_keywords=People%20Management.md)[Incident Response](https://jobicy.com/jobs?search_keywords=Incident%20Response.md)[Cross-Functional Leadership](https://jobicy.com/jobs?search_keywords=Cross-Functional%20Leadership.md)

Sample interview questionsHow would you set the first-year research agenda for the Abuse Research Group?I would begin with a threat and control landscape review, combining recent loss events, investigative backlogs, merchant abuse trends, intelligence reporting, and gaps in existing detections. I would prioritize initiatives by customer harm, platform exposure, adversary capability, and feasibility of converting research into preventive controls. The roadmap would include a balanced portfolio of urgent investigations, strategic actor tracking, reusable detection capabilities, and measurable regression testing.

Describe how you would turn a novel fraud finding into a production defense.

I would validate the finding through repeatable evidence, define the relevant attack path and indicators, and assess false-positive and customer-impact risks with partner teams. Next, I would work with detection engineering and platform owners to implement telemetry, rules, risk signals, or automated response actions. I would document assumptions, establish monitoring and rollback criteria, and create regression scenarios so the control remains effective as attacker behavior evolves.

How do you lead technical researchers whose work is ambiguous and does not fit traditional sprint metrics?

I set clear outcomes rather than measuring activity alone: validated threat hypotheses, actionable intelligence, detection coverage, reduced time to operationalization, and improved resilience against known abuse paths. I use regular research reviews to challenge evidence quality, unblock investigations, and connect work to business risk. For career growth, I create expectations for technical depth, influence, writing quality, and mentorship while preserving room for exploratory work.

How would you manage an investigation involving API key takeovers affecting multiple merchants?

I would establish an incident structure quickly, confirm scope and attacker behavior, and coordinate containment with security, risk, and affected product teams. The investigation would examine credential acquisition paths, anomalous API activity, account recovery signals, linked infrastructure, and opportunities for immediate detection or enforcement. After containment, I would drive a root-cause review, prioritize systemic control improvements, and ensure lessons are translated into durable monitoring and test cases.

What makes threat intelligence valuable in a payments and fintech environment?

Threat intelligence is valuable when it improves decisions and defenses rather than remaining descriptive reporting. In fintech, it should connect adversary infrastructure, TTPs, fraud patterns, and ecosystem signals to concrete actions such as risk rules, merchant protections, investigation prioritization, and disruption opportunities. Effective programs also communicate confidence, limitations, and expected impact clearly to technical and executive stakeholders.

Opportunity details

## About this role.

### Who we are

### About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies – from the world’s largest enterprises to the most ambitious startups – use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

### About the team

The Abuse Research team is dedicated to proactively hunting for emerging abuse vectors and studying complex attacker behaviors. Rather than just reacting to alerts, the team maps complete abuse paths across Stripe products and external systems to validate novel findings and explain the underlying product conditions that enable fraud. By building continuous abuse tests with agentic testing and related systems, they translate their deep research into actionable threat advisories, strategic control recommendations, and regression scenarios that fortify Stripe’s defenses.

### What you’ll do

You will lead the Abuse Research Group (ARG)—a team of threat intelligence analysts, fraud researchers, and detection engineers focused on proactively identifying and mitigating threats to Stripe and our merchants. You will set the research agenda, guiding work across threat actor tracking, hands-on fraud investigations, merchant ecosystem defense, and the detection pipelines that turn findings into production enforcement. You will scale the team through hiring, coaching, and talent development, while serving as a technical advisor on complex investigations. You will also own ARG’s relationships with key partners—including Risk, Trust & Safety, Fraud Platform, and Security Engineering.

* Lead, develop, and retain a team of threat intelligence analysts, fraud researchers, and detection engineers who thrive at the intersection of adversarial research and engineering
* Set and execute the research agenda across threat actor tracking, fraud investigation, merchant ecosystem defense, and automated detection engineering
* Provide technical depth and analytical judgment on complex investigations, including API key takeovers, account compromise campaigns, and KYC bypass techniques
* Operationalize research findings into production-level detection rules, automated response mechanisms, and cross-functional escalations
* Collaborate with Risk, Trust & Safety, Fraud Platform, and Security Engineering to translate abuse research into proactive platform protections
* Coordinate with external stakeholders, including law enforcement, to disrupt and attribute high-impact threat actors
* Coach and mentor individual contributors to support their career development while maintaining high technical standards

### Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

### Minimum requirements

* 10+ years of experience leading security engineering or research teams, with a track record of managing technical ICs doing investigative, intelligence, or detection work.
* B.S. or M.S. Computer Science or related field, or equivalent experience in Security
* Experience recruiting, growing, and leading technical teams, including performance management
* Excellent written and verbal communication skills, including the ability to develop and deliver operational or incident-related information to leadership
* Familiarity with fraud and abuse patterns specific to payments and fintech
* Hands-on experience with threat intelligence tradecraft: OSINT, dark web collection, actor attribution, and working with structured intelligence frameworks (ATT&CK, STIX/TAXII, or equivalent)
* Strong understanding of threat actor tactics, techniques, and procedures (TTPs)

### Preferred qualifications

* Background in security research, threat intelligence, or fraud detection engineering — prior experience leading or working in teams that study adversary behavior, build detection systems, or operate intelligence programs; experience in payments, fintech, or financial crime is a strong plus.

* Technical fluency across the domains ARG works in — threat intelligence, fraud signal development, detection engineering, and OSINT.

* Experience managing or growing technical research teams, ideally in a domain where the work is investigative, ambiguous, and doesn’t map cleanly to sprint velocity.

Show more

[Apply now >](https://jobicy.com/jobs/154725-arg-engineering-manager.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

*
![ecosio logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/eec17a98-221.png)
ecosio Oct 6  New

### [Senior Cloud Security Engineer (f/m/d)](https://jobicy.com/jobs/154752-senior-cloud-security-engineer-f-m-d.md)

Company Description ecosio is a fast-growing, innovative service company and a leading provider of B2B integration, specialising in electronic data interchange (EDI), Web EDI and e-invoicing. ecosio is part of…

*
![Recorded Future, Inc. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/2467e1d2-221.png)
Recorded Future, Inc. Oct 6  New

### [EDR Engineer / Senior EDR Engineer](https://jobicy.com/jobs/154699-edr-engineer-senior-edr-engineer.md)

With 1,000+ intelligence professionals serving over 1,900 clients worldwide, Recorded Future is the world’s most advanced, and largest, intelligence company! The EDR Security Engineer is responsible for the technical administration,…

*
![Recorded Future, Inc. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/2467e1d2-221.png)
Recorded Future, Inc. Oct 6  New

### [Principal Dark Web Collection Analyst](https://jobicy.com/jobs/154704-principal-dark-web-collection-analyst.md)

With 1,000+ intelligence professionals serving over 1,900 clients worldwide, Recorded Future is the world’s most advanced, and largest, intelligence company! Recorded Future is expanding its dark web collection capability with…

*
![Abby Care logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/3d3ea8fe-221.jpeg)
Abby Care Oct 6  New

### [Senior Security Analyst](https://jobicy.com/jobs/154692-senior-security-analyst.md)

About Abby Care: Powering the future of care at home for all of America. Abby Care is building the leading AI-native platform for family-led care. America is facing a growing…

*
![Five9 logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/7c3d754e-221.png)
Five9 Oct 6  New

### [Senior Information Security Engineer](https://jobicy.com/jobs/154681-senior-information-security-engineer.md)

Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide. Living our values…

*
![Beyond Finance logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/68cd015e123539d873279c7b82f1ca6a.jpg)
Beyond Finance Oct 6  New

### [Senior Application Security Engineer](https://jobicy.com/jobs/154682-senior-application-security-engineer-3.md)

At Beyond Finance, we’ve made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care,…

*
![Five9 logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/7c3d754e-221.png)
Five9 Oct 6  New

### [Cloud Governance Engineer](https://jobicy.com/jobs/154675-cloud-governance-engineer.md)

Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide. Living our values…

*
![Collibra logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/25583c1c-221.jpg)
Collibra Oct 5  New

### [Engineer, Security Operations & Engineering](https://jobicy.com/jobs/154592-engineer-security-operations-engineering.md)

Joining Collibra’s Security Operations & Engineering team This is an opportunity to work in the Security Operations & Engineering team within the growing Collibra Security Organization.Security Engineers at Collibra design,…

*
![HackerOne logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8937d355-221.png)
HackerOne Oct 5  New

### [Senior Director, Community](https://jobicy.com/jobs/152527-senior-director-community.md)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to…

*
![HackerOne logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8937d355-221.png)
HackerOne Oct 5  New

### [Product Security Analyst](https://jobicy.com/jobs/152523-product-security-analyst.md)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to…

[Browse all jobs](https://jobicy.com/jobs.md)