On this page
TechJobs.ie Job Insights
At a glance
- Employment type
- Full-time
- Location
- Dublin, Ireland
- Workplace
- On-site
- Category
- Security
Technologies & skills
Primary technologies
Other technical skills
What you'll be doing
As a Forward Deployed Security Engineer at Stripe in Dublin, you'll respond to live fraud and abuse incidents, investigate high-risk accounts, develop incident response strategies, and act as a technical bridge between incidents and merchants. You'll leverage expertise in Python, SQL, and threat intelligence to safeguard Stripe's financial ecosystem.
- Respond to live fraud and abuse incidents, investigating high-risk activity and mitigating security risks
- Investigate, mitigate, and remediate urgent fraud incidents using FT3-mapped detection and signals enrichment
- Analyze high-risk accounts to identify and classify fraud vectors using FT3
- Develop, document, and execute incident response strategies and runbooks
- Act as a technical bridge with impacted merchants and customers to remediate vulnerabilities
- Serve as an operational and technical liaison for legal teams, policy partners, and threat intelligence communities
- Build and nurture relationships with external threat intelligence communities, peer groups, and law enforcement
Key requirements
Must-have
- 10+ years of experience leading security or fraud incident response
- B.S./M.S. in Computer Science or equivalent experience
- Expert knowledge of Python and SQL
- Familiarity with other programming languages
- Experience with log analysis, network security, digital forensics, and incident response investigations
- Ability to build automated response workflows and leverage threat intelligence
- Strong written and verbal communication skills
- Previous work with law enforcement
Nice-to-have
- Expertise in fraud and abuse mitigation, risk management, product trust, and threat intelligence
- Adversarial mindset and understanding of threat actors
- Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino)
- Familiarity with open-source frameworks for big data processing/data science (PySpark, Pandas, Sci-kit Learn)
- Experience with tactical threat intelligence and hunting for sophisticated threat actors
- Ability to challenge the status quo using data and a user-centric approach
Experience: 10+ years leading security or fraud incident response
Role signals
- Technical focus
- security incident response, fraud detection, threat intelligence
- Hands-on vs management
- Hands-on
Similar jobs
Check your CV against this job
Get a certified technical review aimed at this role.
Full job description
**Who we are **
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.
What you’ll do
In this role, you will play a critical part in safeguarding our financial ecosystem through two main pillars: actively responding to live fraud and abuse incidents as a hands-on security engineer, and serving as a key bridge between incidents and merchants to help them remediate threats, improve security posture, and protect their accounts. Leveraging your technical depth in fraud, abuse, and security engineering, you will investigate high-risk accounts, perform post-incident analyses, gather operational requirements, and drive agentic response capabilities ensuring we neutralize threats with speed and precision while elevating Stripe's product integrity function.
Responsibilities
-
Respond to live fraud and abuse incidents as a Forward Deployed Security Engineer, investigating high-risk activity, neutralizing active attacks, and mitigating security risks across the ecosystem.
-
Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped (Fraud Taxonomy 3.0) detection and signals enrichment to reduce uncertainty and accelerate response.
-
As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.
-
Develop, document, and execute incident response strategies, runbooks, and capabilities to continuously improve fraud and abuse detection and prevention.
-
Act as a dedicated technical bridge during and after incidents to work directly with impacted merchants and customers, helping them investigate root causes, remediate vulnerabilities, and secure their accounts.
-
Serve as an operational and technical liaison for legal teams, policy partners, and threat intelligence communities.
-
Build and nurture strong strategic relationships across external threat intelligence communities, peer working groups, and law enforcement agencies.
Who you are
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
-
10+ years of experience leading security or fraud incident response;
-
B.S./M.S. in Computer Science or equivalent experience.
-
Expert knowledge of Python and SQL, and familiarity with other programming languages
-
Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
-
Proven ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
-
Strong written and verbal communication skills with a track record of driving cross-functional alignment with minimal oversight.
-
Previous work with law enforcement
-
Engagement in threat intelligence sharing communities
Preferred qualifications
-
Broad expertise across fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
-
An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
-
Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
-
Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
-
Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
-
Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges.
-
Speaker or participant in external conferences or similar industry engagements
Interview prep pack
Grounded in this listing. Use it to prepare examples before you apply.
Your interview focus
Based on this listing, the Forward Deployed Security Engineer role at Stripe focuses on hands-on incident response to fraud and abuse, technical investigation, and cross-functional collaboration with merchants, legal, and threat intelligence communities.
- Hands-on incident response expertise·High
- Technical automation and data analysis·High
- External collaboration and communication·Medium
Only have 30 minutes?
Follow a focused preparation plan based on this job.
Start 30-minute prep
Your 30-minute plan
Review Stripe's Security and Abuse Operations Materials
0–7 minSpend time reading Stripe's blog, security documentation, and any public incident response case studies to understand their approach.
Refresh Technical Skills in Python, SQL, and Data Analysis
7–15 minPractice using Python and SQL for log analysis and automation, focusing on tools like Pandas and Databricks.
Study Fraud Taxonomy 3.0 and Incident Classification
15–20 minFamiliarize yourself with FT3 or similar frameworks to discuss fraud vector classification confidently.
Prepare STAR Stories for Incident Response and External Collaboration
20–26 minDraft concise examples highlighting your experience in leading incidents, automating workflows, and working with law enforcement.
Draft Role-Specific Questions
26–30 minPrepare thoughtful questions about team processes, technical challenges, and success metrics to ask during the interview.
Talking points
, 5 itemsLeading Security and Fraud Incident Response
Prepare examples of managing and resolving high-stakes security or fraud incidents, demonstrating leadership and technical depth.
Technical Investigation Using Python and SQL
Showcase your ability to analyze logs, detect anomalies, and automate workflows using Python and SQL in real-world scenarios.
Collaboration with Law Enforcement and Threat Intelligence Communities
Be ready to discuss your experience working with external partners to share intelligence and coordinate responses.
Developing and Documenting Incident Response Strategies
Demonstrate your approach to creating, maintaining, and improving incident response runbooks and processes.
Communicating with Impacted Stakeholders
Highlight your skills in bridging technical and non-technical audiences, especially during and after incidents.
What to research
, 4 itemsStripe's Abuse Operations and Incident Response Approach
Research Stripe's public materials on abuse operations, incident response, and product integrity to understand their philosophy and recent challenges.
Fraud Taxonomy 3.0 (FT3) and Fraud Classification Frameworks
Review FT3 or similar frameworks to be able to discuss fraud vector classification and standardization.
Python, SQL, and Data Analysis Tools (e.g., Databricks, Pandas)
Refresh your knowledge of using these tools for log analysis, automation, and incident response workflows.
Threat Intelligence Sharing and Law Enforcement Collaboration
Prepare examples of working with external partners, including protocols, compliance, and relationship-building.
Questions to ask
, 6 itemsHow does the Forward Deployed Security Engineer team at Stripe typically engage with merchants during and after incidents?
Why ask this? Clarifies the depth and style of customer interaction expected in the role.
What are the most common fraud vectors or abuse scenarios currently impacting Stripe's ecosystem?
Why ask this? Helps you understand the threat landscape and tailor your preparation.
How does Stripe leverage FT3 or other taxonomies in its incident response and reporting?
Why ask this? Shows your interest in their analytical rigor and standardization practices.
What opportunities exist for Forward Deployed Security Engineers to contribute to tooling or automation improvements?
Why ask this? Assesses the scope for technical innovation and impact.
How does the team collaborate with external threat intelligence communities and law enforcement?
Why ask this? Clarifies expectations for external relationship management and information sharing.
What does success look like in this role after the first 6-12 months?
Why ask this? Helps you align your goals and understand performance metrics.
Register now to upload your CV
Create a free account, save a PDF or Word CV, and quick apply on roles that take applications here.
