On this page
TechJobs.ie Job Insights
At a glance
- Employment type
- Full-time
- Location
- Dublin, Ireland
- Workplace
- On-site
- Category
- Security
Technologies & skills
Other technical skills
What you'll be doing
Staff Security Engineer, Abuse Control at Stripe (Dublin, On-site). Join the Abuse Control Engineering team to rapidly prototype, test, and deploy technical defenses against emerging abuse vectors. Collaborate cross-functionally, run experiments, and build automated regression suites to safeguard Stripe’s financial ecosystem.
- Design, prototype, and deploy technical controls to address high-impact abuse vectors
- Translate attacker evidence and threat research into technical abuse requirements and control specifications
- Collaborate with teams to design resilient, secure controls across various product surfaces
- Run experiments and A/B tests to measure risk reduction and user impact
- Build regression test suites and automated attack simulations
- Define handoff criteria and documentation for transferring controls to product teams
Key requirements
Must-have
- 10+ years of experience in security engineering, software engineering, application security, or anti-abuse engineering in high-scale production environments
- Bachelor’s or master’s degree in computer science, cybersecurity, software engineering, or related field, or equivalent experience
- Proficiency in Python, Go, Java, or similar production programming language
- Advanced SQL skills
- Experience using frontier AI models for software development, learning, and analysis
- Hands-on experience building API-level safeguards, rate-limiting frameworks, authentication or authorization checks, or input-validation controls
- Experience with automated testing frameworks, including writing unit, integration, and regression tests
- Strong cross-functional collaboration and communication skills
Nice-to-have
- Experience designing and executing A/B tests and evaluating control efficacy
- Expertise in threat modeling, secure systems architecture, and modern application-security design principles
Experience: 10+ years
Role signals
- Technical focus
- security engineering, abuse control, software development
- Hands-on vs management
- Hands-on
Similar jobs
Full job description
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE uses real-world attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale.
We partner closely with Fraud, Risk, Abuse Research, and Product Engineering to run rigorous experiments that balance effective risk mitigation with legitimate user activity and conversion. Operating as both a strike team and an incubator, ACE builds automated regression suites to prevent threats from recurring and transfers mature controls to long-term product owners across Stripe.
What you’ll do
As an Abuse Control Engineer on the ACE team, you will design, prototype, and incubate technical defenses that safeguard Stripe’s financial ecosystem against complex, cross-cutting abuse vectors.
When emerging threat patterns reveal weaknesses in Stripe products, ACE rapidly builds and experiments with technical safeguards. Guided by empirical evidence and Stripe’s Fraud Taxonomy 3.0 (FT3) framework, you will translate threat intelligence into precise technical control requirements, such as API rate limits, step-up challenges, parameter validation, and pre-debit holds.
You will run experiments to evaluate risk reduction against the impact on legitimate user conversion, carefully balancing security and product velocity. You will manage controls through a structured incubation lifecycle, build automated regression suites to prevent threats from recurring, and partner with product engineering teams to transfer mature, long-term defenses.
Responsibilities
-
Rapid control prototyping: Design, prototype, and deploy technical controls across API, protocol, and product boundaries to address high-impact abuse vectors.
-
Evidence-based technical requirements: Translate empirical attacker evidence and FT3 threat research from Abuse Research, Fraud, and Security teams into precise technical abuse requirements and control specifications.
-
Control co-design: Collaborate with teams across Stripe to design resilient, secure controls across payments, onboarding, identity, and Connect surfaces.
-
Risk experimentation: Run rigorous experiments and A/B tests to measure risk reduction against the impact on legitimate user conversion, optimizing controls to minimize friction while neutralizing threats.
-
Regression testing: Build comprehensive regression test suites and automated attack simulations with Abuse Research to ensure mitigated abuse vectors do not recur.
-
Stakeholder management: Execute ACE’s incubation model by defining handoff criteria, operational documentation, timelines, and target dates for transferring successful controls to product teams.
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
-
10+ years of experience in security engineering, software engineering, application security, or anti-abuse engineering in a high-scale production environment.
-
A bachelor’s or master’s degree in computer science, cybersecurity, software engineering, or a related technical field, or equivalent practical experience.
-
A strong software development background, with proficiency in Python, Go, Java, or a similar production programming language, as well as advanced SQL skills for analyzing system telemetry.
-
Experience using frontier AI models for software development, learning, and analysis.
-
Hands-on experience building API-level safeguards, rate-limiting frameworks, authentication or authorization checks, or input-validation controls.
-
Experience with automated testing frameworks, including writing unit, integration, and regression tests for critical backend software.
-
Strong cross-functional collaboration and communication skills, with a track record of partnering across security, product, and platform teams to drive technical outcomes.
Preferred qualifications
-
A track record of designing and executing A/B tests, evaluating control efficacy, and balancing security safeguards against user conversion friction.
-
Expertise in threat modeling, secure systems architecture, and modern application-security design principles.
-
Familiarity with established threat frameworks, such as FT3 or MITRE ATT&CK, and experience applying adversary kill-chain analysis to build resilient defenses.
-
Knowledge of financial fraud vectors, threat-actor tactics, techniques, and procedures, and attacker infrastructure, including account takeover, card testing, and credential stuffing.
-
Hands-on experience with large-scale data-processing platforms, such as Databricks, Trino, or PySpark, to monitor and measure control performance across distributed systems.
-
Experience incubating software features, establishing clear operational handoff criteria, and transitioning ownership to partner engineering teams.
Interview prep pack
Grounded in this listing. Use it to prepare examples before you apply.
Your interview focus
Based on this listing, the Staff Security Engineer, Abuse Control at Stripe will rapidly design, prototype, and deploy technical safeguards to protect against complex abuse vectors, collaborating closely with cross-functional teams and leveraging advanced software engineering and security expertise.
- Hands-on security engineering in high-scale environments·Medium
- Rapid prototyping and experimentation·Medium
- Cross-functional technical collaboration·High
- Automated testing and regression analysis·High
Only have 30 minutes?
Follow a focused preparation plan based on this job.
Start 30-minute prep
Your 30-minute plan
Review Abuse Control and Security Engineering Case Studies
0–8 minPrepare 1-2 detailed examples from your experience where you rapidly designed and deployed technical safeguards in response to abuse or security threats.
Refresh API Security and Automated Testing Knowledge
8–15 minStudy best practices for API-level controls and automated regression testing, focusing on technologies mentioned in the listing (Python, Go, Java, SQL).
Prepare to Discuss Experimentation and A/B Testing
15–20 minOutline a scenario where you ran experiments or A/B tests to balance security and user experience, including metrics and outcomes.
Research Stripe’s ACE Team and Security Culture
20–25 minRead available Stripe engineering blogs, security whitepapers, or public talks to understand the company’s approach to abuse control and cross-functional collaboration.
Draft Role-Specific Questions
25–30 minWrite down 3-4 thoughtful questions about the team’s processes, technical stack, and success metrics to ask during your interview.
Talking points
, 6 itemsRapid Prototyping of Security Controls
Be ready to discuss examples where you quickly designed and deployed technical controls in response to emerging threats, as this is central to the ACE team's mission.
API Safeguards and Rate Limiting
Prepare to explain your experience building API-level protections, such as rate limiting, authentication, and input validation, since these are key technical requirements.
Experimentation and A/B Testing for Risk Reduction
Showcase your ability to run experiments and A/B tests to balance security with user experience, as the role emphasizes optimizing controls for both risk mitigation and conversion.
Automated Regression Testing
Demonstrate your experience building automated test suites to ensure that mitigated abuse vectors do not recur, as this is a core responsibility.
Cross-functional Collaboration
Highlight situations where you partnered with product, fraud, or research teams to deliver technical outcomes, as strong collaboration is required.
Use of AI Models in Security Engineering
Be prepared to discuss how you have leveraged AI models for software development or threat analysis, as this is a listed requirement.
What to research
, 4 itemsStripe’s Abuse Control Engineering (ACE) Team Mission and Processes
Review Stripe’s public materials and any available information on the ACE team’s approach to rapid-response abuse control and technical defense incubation.
API Security Best Practices
Refresh your knowledge of API-level safeguards, including rate limiting, authentication, authorization, and input validation, especially in high-scale environments.
Automated Testing Frameworks
Be prepared to discuss your experience with unit, integration, and regression testing frameworks relevant to backend security controls.
Experimentation and A/B Testing in Security Contexts
Review methodologies for running experiments and A/B tests to measure the impact of security controls on both risk and user experience.
Questions to ask
, 6 itemsHow does the ACE team prioritize which abuse vectors to address first?
Why ask this? To understand the decision-making process and how your work would be focused.
What are the main challenges the team faces when balancing security controls with user conversion?
Why ask this? To gain insight into the practical trade-offs and expectations for this role.
How does the handoff process to product teams typically work, and what support is provided during this transition?
Why ask this? To clarify expectations for documentation, operationalization, and collaboration.
What tools and frameworks does the team currently use for automated regression testing and attack simulation?
Why ask this? To assess the technical environment and how your experience aligns.
How does the team leverage AI models in its security engineering and analysis workflows?
Why ask this? To understand the maturity and scope of AI integration in daily work.
What does success look like for someone in this role after the first 6-12 months?
Why ask this? To set clear expectations for impact and growth.
Register now to upload your CV
Create a free account, save a PDF or Word CV, and quick apply on roles that take applications here.
