Get AI match insights
See your fit score & personalized tips.
Design, prototype, and deploy rapid technical abuse controls (e.g., rate limits, validation, step‑up challenges) and build automated regression suites to keep mitigated threats from recurring.
10+ years in security or anti‑abuse engineering, strong software development skills in Python/Go/Java and SQL, experience building API‑level safeguards and automated tests, plus solid cross‑functional collaboration.
The role protects Stripe’s financial ecosystem by turning emerging threat intelligence into actionable defenses, balancing risk reduction with user conversion, and ensuring long‑term security across payments and onboarding.
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE uses real-world attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale.
We partner closely with Fraud, Risk, Abuse Research, and Product Engineering to run rigorous experiments that balance effective risk mitigation with legitimate user activity and conversion. Operating as both a strike team and an incubator, ACE builds automated regression suites to prevent threats from recurring and transfers mature controls to long-term product owners across Stripe.
As an Abuse Control Engineer on the ACE team, you will design, prototype, and incubate technical defenses that safeguard Stripe’s financial ecosystem against complex, cross-cutting abuse vectors.
When emerging threat patterns reveal weaknesses in Stripe products, ACE rapidly builds and experiments with technical safeguards. Guided by empirical evidence and Stripe’s Fraud Taxonomy 3.0 (FT3) framework, you will translate threat intelligence into precise technical control requirements, such as API rate limits, step-up challenges, parameter validation, and pre-debit holds.
You will run experiments to evaluate risk reduction against the impact on legitimate user conversion, carefully balancing security and product velocity. You will manage controls through a structured incubation lifecycle, build automated regression suites to prevent threats from recurring, and partner with product engineering teams to transfer mature, long-term defenses.
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.