growthroles

Forward Deployed Security Engineer

Stripe Open · verified Sep 24, 2026
Dublin Mid-level Solutions & Sales Engineering

At a glance

Mid-level Solutions & Sales Engineering role at Stripe. Dublin.

Pay not stated

RoleSolutions & Sales Engineering
SeniorityMid-level
LocationDublin
PostedSep 6, 2026 · 2w ago
Role brief

Growth Roles summary, based on the employer's posting.

What you'll do

  • Respond to live fraud and abuse cases, examining high-risk activity and stopping active attacks
  • Use FT3 signals to investigate urgent ATO and card-testing incidents and classify affected accounts
  • Create and run response playbooks that strengthen fraud and abuse detection and prevention
  • Guide impacted merchants through root-cause analysis, vulnerability fixes, and account security
  • Coordinate technical work with legal, policy, threat intelligence, and law enforcement contacts

What you bring

  • At least ten years leading security or fraud incident response
  • A computer science bachelor’s or master’s degree, or equivalent experience
  • Expert Python and SQL skills plus experience with logs, network security, forensics, and investigations
  • A record of automating response workflows, applying threat intelligence, and recommending risk reductions
  • Clear written and verbal communication with experience aligning cross-functional teams independently

Who this fits

You’ll suit a senior hands-on incident responder who can investigate fraud, communicate directly with merchants, and translate incidents into operational improvements. The role involves collaboration with global stakeholders and operates primarily across Eastern, Pacific, and Western European time zones. Previous law-enforcement work and participation in threat-intelligence sharing communities are required.

From the employer

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.

What you’ll do

In this role, you will play a critical part in safeguarding our financial ecosystem through two main pillars: actively responding to live fraud and abuse incidents as a hands-on security engineer, and serving as a key bridge between incidents and merchants to help them remediate threats, improve security posture, and protect their accounts. Leveraging your technical depth in fraud, abuse, and security engineering, you will investigate high-risk accounts, perform post-incident analyses, gather operational requirements, and drive agentic response capabilities ensuring we neutralize threats with speed and precision while elevating Stripe's product integrity function.

Responsibilities

  • Respond to live fraud and abuse incidents as a Forward Deployed Security Engineer, investigating high-risk activity, neutralizing active attacks, and mitigating security risks across the ecosystem.
  • Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped (Fraud Taxonomy 3.0) detection and signals enrichment to reduce uncertainty and accelerate response.
  • As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.
  • Develop, document, and execute incident response strategies, runbooks, and capabilities to continuously improve fraud and abuse detection and prevention.
  • Act as a dedicated technical bridge during and after incidents to work directly with impacted merchants and customers, helping them investigate root causes, remediate vulnerabilities, and secure their accounts.
  • Serve as an operational and technical liaison for legal teams, policy partners, and threat intelligence communities.
  • Build and nurture strong strategic relationships across external threat intelligence communities, peer working groups, and law enforcement agencies.

Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • 10+ years of experience leading security or fraud incident response;
  • B.S./M.S. in Computer Science or equivalent experience.
  • Expert knowledge of Python and SQL, and familiarity with other programming languages
  • Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
  • Proven ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
  • Strong written and verbal communication skills with a track record of driving cross-functional alignment with minimal oversight.
  • Previous work with law enforcement
  • Engagement in threat intelligence sharing communities

Preferred qualifications

  • Broad expertise across fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
  • An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
  • Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
  • Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
  • Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
  • Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges.
  • Speaker or participant in external conferences or similar industry engagements

Not this one either?

Claude or ChatGPT reads the other 90,537 for you.

Get better matches →

Same team as Marketing Monk

What's happening in AI marketing. Daily.

Biggest story, quick hits, a prompt, one action.

7 minutes. 71,000 readers. Unsubscribe anytime.