Role in brief
Stripe seeks a Security Engineer to secure its financial infrastructure platform. This role involves developing security solutions for AI/LLM integrations, building automated threat modeling tools, and reducing security debt across products. Candidates with a strong background in security engineering, cloud platforms, and containerization, who can also mentor others and drive cross-team initiatives, will find this role a good fit.
About the role
This role focuses on enhancing the security posture of Stripe's financial infrastructure. A key responsibility involves developing secure integrations for AI and LLM technologies within products and for internal security use. The engineer will also contribute to securing core products like Connect and Radar, ensuring the platform remains robust for accepting payments and moving funds.
A significant part of the work involves proactive security measures, such as building and improving automated threat modeling tools. The successful candidate will identify and help reduce security vulnerabilities across the product portfolio, working closely with product engineering teams to design solutions that are secure from the outset. This includes tailoring security guidance for both technical and non-technical audiences.
Success in this position means scaling security efforts by empowering engineering teams. This is achieved through providing automation, clear security guidance, effective tooling, established patterns, and training. The role also requires driving impactful, cross-team security initiatives and mentoring colleagues, balancing security requirements with user experience and product innovation.
The salary for this position ranges from $80,500 to $138,000 annually, with additional benefits including equity, bonuses, 401(k), and health benefits.
Skills that matter here
- Computer Science: A foundational degree in Computer Science or a related field is required for this security engineering role.
- Security Informatics: A degree in Security Informatics or a related field is a prerequisite for this position.
- AWS: Five years of experience with AWS is required, alongside other cloud service providers.
- GCP: Five years of experience with either GCP or Azure is required, in addition to AWS.
- application security: Five years of experience in application security is necessary to secure Stripe's products.
- threat modeling: Five years of experience developing threat models and guiding teams in risk reduction is essential for this role.
Who this role suits
- A candidate with five years of security engineering experience in a production environment.
- Someone who has worked with multiple cloud service providers, including AWS and either GCP or Azure, for at least five years.
- An individual with five years of experience in both application and infrastructure security.
- A person with four years of experience using containerization and orchestration technologies like Docker or Kubernetes.
From the employer
What you’ll do
- Develop and work with supporting secure AI and LLM usage/integration both in products and within Security
- Develop building blocks to accept payments and move funds
- Stripes Core Products including Connect, Subscriptions, Checkout, RADAR, and Issuing
- Build/Enhance automated threat modeling tooling
- Identify and help reduce security debt across our product portfolio
- Work closely with product engineering teams to design solutions that are secure by default
- Tailor answers to security questions from non-engineers and engineers
- Lead threat modeling discussions and help teams strike the right balance between security, user experience and product advancement
- Scale security effort by empowering engineering teams with automation, security guidance, tooling, patterns and training
- Drive high impact, cross-team security initiatives
- Mentor teammates and others across the organization
Who you are
- Bachelor’s degree or foreign equivalent in Computer Science, Security Informatics, or related followed by 5 years of security engineering experience in a production environment.
- 5 years of experience with multiple CSPs, including AWS and either GCP or Azure
- 5 years of experience with application and infrastructure security
- 5 years of experience developing threat models and helping teams reason through different approaches to reduce security risk
- 4 years of experience with containerization and orchestration technologies including Docker or Kubernetes
Additional benefits
- Equity, company bonus or sales commissions/bonuses
- 401(k) plan
- Medical, dental, and vision benefits
- Wellness stipends
Questions about this role
What is the remote work policy for this role?
This is a fully remote position with no specified location restrictions.
What is the required seniority level for this position?
This is a middle-seniority level role.
What skills are required for this role?
Candidates need a background in Computer Science or Security Informatics, with experience in AWS, GCP or Azure, application and infrastructure security, threat modeling, Docker, and Kubernetes.