Offensive Security Engineer (f/m/d)
<h3><strong>Notre équipe Cyber Defense recherche un·e <strong data-path-to-node="6" data-index-in-node="40">Offensive Security Engineer (f/m…
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
The Proactive Threat team is responsible for identifying vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure — before adversaries do. We operate as a hybrid offensive function: conducting penetration testing, emulating real-world threat actors through red team operations, and partnering closely with our defensive security teams to validate detection capabilities and improve Stripe's overall security posture.
We are builders first. Our team develops custom tooling, automation frameworks, and internal platforms that scale our offensive capabilities and enable repeatable, high-fidelity assessments. We believe the best offensive security engineers are equal parts hacker and engineer.
The team is distributed across the United States, primarily operating in Eastern and Pacific time zones, and collaborates regularly with security, engineering, and product stakeholders across Stripe — including teams in Europe and Asia.
What you’ll do
As an Offensive Security Engineer on the Proactive Threat team, you will simulate the tactics, techniques, and procedures (TTPs) of real-world adversaries to uncover security risks across Stripe's products and infrastructure. You'll conduct hands-on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities. Your work will directly influence how Stripe builds, ships, and secures financial infrastructure used by millions of businesses worldwide.
Beyond assessments, you'll design and build offensive tooling and automation that amplifies the team's impact. You'll leverage threat intelligence to prioritize testing efforts, contribute to incident investigations when needed, and act as a subject-matter expert for security initiatives across the company.
Responsibilities
Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure
Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios
Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams
Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity
Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks
Support incident investigations by providing offensive expertise, log analysis, and root cause analysis when required
Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverage
Build internal platforms and workflows that enable scalable, repeatable offensive operations
Contribute to internal security tooling repositories and champion engineering best practices within the team
Automate repetitive testing tasks, payload generation, and reporting workflows using modern development practices
Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non-technical stakeholders
Act as a subject-matter exp
Neutral 2–4 sentence summary of what working at this company is like, drawn from public reviews and press coverage. Tone, collaboration style, pace, benefits highlights.
£45,000 – £60,000 (Glassdoor, Levels.fyi, 2025)
Stripe's culture is characterized by high standards, urgency, and a fast-paced environment, with a strong emphasis on user focus and meticulous craft. The company fosters deep, multifunctional collaboration and a writing-first approach to knowledge sharing. While employees generally appreciate the leadership and team quality, some reviews indicate challenges related to work-life balance due to the demanding nature of the work.
Perks
Salary range: £84,400 – £126,600 (Stripe Official Job Posting, May 2026)
<h3><strong>Notre équipe Cyber Defense recherche un·e <strong data-path-to-node="6" data-index-in-node="40">Offensive Security Engineer (f/m…
<h3><strong>Notre équipe Cyber Defense recherche un·e <strong data-path-to-node="6" data-index-in-node="40">Offensive Security Engineer (f/m…
About DockerDocker has been one of the most loved brands in developer tooling, trusted by more than 20 million monthly users and over 20 bil…
<h3><strong>About Atari</strong></h3> <p>Atari is an interactive entertainment company and an iconic gaming industry brand recognized worldw…
At Quorum Cyber, we're on a mission to help good people win. Founded in Edinburgh in 2016, we're one of the fastest growing cyber security c…
<div class="content-intro"><p><span style="font-family: arial, helvetica, sans-serif;"><strong>Who we are</strong></span></p> <p><span style…