Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Offensive Security Engineer

$170.4k - $255.7k

Stripe

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the team The Proactive Threat team is responsible for identifying vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure — before adversaries do. We operate as a hybrid offensive function: conducting penetration testing, emulating real-world threat actors through red team operations, and partnering closely with our defensive security teams to validate detection capabilities and improve Stripe's overall security posture. We are builders first. Our team develops custom tooling, automation frameworks, and internal platforms that scale our offensive capabilities and enable repeatable, high-fidelity assessments. We believe the best offensive security engineers are equal parts hacker and engineer. The team is distributed across the United States, primarily operating in Eastern and Pacific time zones, and collaborates regularly with security, engineering, and product stakeholders across Stripe — including teams in Europe and Asia. What you'll do As an Offensive Security Engineer on the Proactive Threat team, you will simulate the tactics, techniques, and procedures (TTPs) of real-world adversaries to uncover security risks across Stripe's products and infrastructure. You'll conduct hands-on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities. Your work will directly influence how Stripe builds, ships, and secures financial infrastructure used by millions of businesses worldwide. Beyond assessments, you'll design and build offensive tooling and automation that amplifies the team's impact. You'll leverage threat intelligence to prioritize testing efforts, contribute to incident investigations when needed, and act as a subject-matter expert for security initiatives across the company. Responsibilities Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks Support incident investigations by providing offensive expertise, log analysis, and root cause analysis when required Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverage Build internal platforms and workflows that enable scalable, repeatable offensive operations Contribute to internal security tooling repositories and champion engineering best practices within the team Automate repetitive testing tasks, payload generation, and reporting workflows using modern development practices Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non-technical stakeholders Act as a subject-matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and Stripe-wide security initiatives Lead offensive security projects end-to-end, mentor junior team members, and foster a culture of continuous learning and knowledge sharing Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and contribute to the broader security community Who you are We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement. Minimum requirements 5+ years of experience in offensive security, penetration testing, red teaming, or a related field Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.) Hands-on experience with cloud platforms (AWS, Azure, or GCP), including cloud-native attack techniques and misconfigurations Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including TTPs for initial access, privilege escalation, lateral movement, and exfiltration Excellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk-based recommendations Ability to think like an adversary — creative, persistent, and able to holistically assess risk in complex environments Preferred qualifications Experience conducting offensive security in fintech, financial services, or other highly regulated environments Background in vulnerability research, exploit development, or CVE discovery Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations) Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows Interest or experience in agentic automation — using LLMs or autonomous agents to augment reconnaissance, vulnerability discovery, or exploitation workflows Experience testing AI/ML systems or LLM-based applications for security weaknesses (prompt injection, training data extraction, model manipulation, etc.) Contributions to open-source security tools, published research, blog posts, or conference presentations Relevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications Location This role is remote within the United States. While you are welcome to visit Stripe offices for team meetings, on-sites, and events, our expectation is that you would regularly work from home. The team primarily coordinates across Eastern and Pacific time zones, with regular collaboration with stakeholders in Europe and Asia. Compensation & Benefits The annual US base salary range for this role is $170,400 – $255,700. This range may span multiple career levels and will be refined during the interview process based on experience, qualifications, and location. Additional benefits include: Equity participation in Stripe's growth 401(k) plan with matching contributions from day one Comprehensive medical, dental, and vision coverage Wellness stipends Annual budget for training, certifications, and conference attendance Stripe

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Offensive Security Engineer in New York, NY vacancy
  • $180k - $230k

    Senior Security Engineer, Threat & Offensive Security Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. We're a Series C company backed by a16z, transforming industries that others have written off as too complex to... 
    Suggested
    Remote work
    Flexible hours

    Valon

    New York, NY
    4 days ago
  • $187k - $220k

     ...high standards, clear accountability, and a strong focus on security and ethics in everything we build! The Red Team’s...  ...simulating adversary behavior and testing defenses. As a Staff Offensive Security Engineer, you will plan and execute security assessments across applications... 
    Suggested
    Work at office
    Shift work
    3 days per week

    Robin Hood

    New York, NY
    3 days ago
  • Senior Offensive Security Engineer (Red Team) Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword — it's a way of life. The world of work as we know it is changing... 
    Suggested

    Salesforce

    New York, NY
    4 days ago
  • Senior Offensive Security Engineer Our Cyber Adversary and Exposure Management team rolls up into Key's broader Cyber Defense function within Corporate Information Security. Cyber Defense's mission is simple: We aim to Deter, Detect, Deny, and Disrupt adversaries through... 
    Suggested

    KeyCorp

    New York, NY
    5 days ago
  • Seeking a full-time Senior Offensive Security Engineer focused on enhancing AI-driven offensive security, this remote position will manage the development of autonomous red team agents, improve existing agent capabilities, and mentor team members in advanced offensive tooling... 
    Suggested
    Full time
    Remote work

    Virtual Vocations Inc

    New York, NY
    3 days ago
  • Staff Offensive Security Engineer Cloaked is a consumer privacy and identity platform on a mission to give people back control of their personal data. We let anyone generate unlimited identities - masked emails, phone numbers, and payment cards - scrub their information... 

    Cloaked

    New York, NY
    4 days ago
  • $140k - $190k

    About Method Security Method Security is dedicated to reshaping cybersecurity in an era...  ...finally shift the advantage in security from offense to defense. Our Team and Values...  ...cybersecurity. Role Overview As a Security Engineer at Method Security, you will be... 
    Shift work

    Method Security

    New York, NY
    4 days ago
  • Your Role: Security Engineer We're looking for an experienced, hands-on Security Engineer to secure XBOW's product, cloud, and platform as...  ...Advantageous- Multi-cloud experience beyond AWS (e.g., Azure/GCP/OCI) Offensive security/pentesting background and ability to convert... 
    Full time
    Contract work
    Remote work

    XBOW

    New York, NY
    5 days ago
  • $85.4k - $168.1k

    Overview The Microsoft Windows Security team is looking for a learn-it-all security engineer that will help secure Microsoft Windows products and devices, with focus on offensive security and security engineering & mitigations for Windows. The Windows Security team is responsible... 
    Ongoing contract
    Local area
    Worldwide

    Microsoft Corporation

    New York, NY
    2 days ago
  • $200k - $240k

     ...diverse, global presence. The Liftoff Security team protects Liftoff's customers, users...  ...systems that defend it, and partner with engineering teams as they ship new products and...  ...Close the feedback loop between the team's offensive and proactive findings and detection... 
    Full time
    Remote work

    Liftoff Inc

    New York, NY
    3 days ago
  •  ...out the Launch Video About this role We're hiring Senior Security Engineers to design, harden, and continuously test the security of the...  ...language their teams can defend internally. Push the frontier on offensive and defensive AI for SAP. AI agents are uniquely powerful... 

    Nova Intelligence

    New York, NY
    4 days ago
  •  ...Job Description Job Description We are seeking an Autonomous Security Engineer, Customer Solutions to operate at the intersection of autonomous offensive security, technical consulting, and customer engineering. You'll be on the front lines of customer engagements... 

    Pensar

    New York, NY
    a month ago
  • $159.3k - $202.4k

    Amazon Stores Security is hiring a Security Engineer for our Application Security Compliance Penetration Testing (CPT) team.In this role you will attack...  ...+ years of hands-on application penetration testing or offensive security assessments across web applications, APIs, or... 
    Temporary work
    Fixed term contract
    Internship
    Flexible hours

    Amazon

    New York, NY
    12 days ago
  •  ...Job Description Job Description Senior Security Engineer Full Time Opportunity 5 days on site in NYC, NY The Senior Security...  ...languages for the purpose of automation Conduct lightweight offensive/discovery operations on your own or with a team Work... 
    Full time

    Enterprise Engineering

    New York, NY
    19 days ago
  • $170k - $200k

     ...automate property access, operations, and security from a single platform. Our products are...  ...is looking for a Senior Security Engineer to join our growing security team. In this...  ...secure development lifecycle practices and offensive testing. Strong understanding of web application... 
    Temporary work
    Remote work
    Worldwide
    Flexible hours
    Shift work

    ButterflyMX

    New York, NY
    3 days ago
  • The Position As our first dedicated Senior Security Engineer, you will join a remote, global health‑tech team that works at the intersection...  ...are a plus; we value candidates with real-world offensive experience, not just institutional credentials. Deep experience... 
    Remote work

    Sequencing.com

    New York, NY
    3 days ago
  • $237.6k - $297k

     ...We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the... 
    Full time

    Scale AI

    New York, NY
    17 hours ago
  • $190k - $240k

    Senior Staff Security Engineer, Incident Response Houston; New York; San Francisco; Seattle About Nscale Nscale is the GPU cloud engineered...  ..., Identity, Enterprise and Infrastructure teams, and Offensive Security. During a major incident, you will be the technical... 
    Permanent employment
    Flexible hours

    Nscale

    New York, NY
    4 days ago
  • $133k - $173k

     ...BY EMPOWERING HEALTHCARE CONSUMERS.  Come be part of remarkable. Overview How you can make a difference As a Principal Security Engineer, AI Offensive Security, you build and operate agentic systems that discover, validate, and help remediate vulnerabilities across HealthEquity... 
    Work experience placement
    Remote work

    HealthEquity

    New York, NY
    3 days ago
  • $230k - $290k

     ...teams to run agents across organizations without compromising security or reliability. Continue cloud agent runs that were triggered...  ...at a company where your work reaches hundreds of thousands of engineers every day, we'd love to have you. The Role This is a rare... 
    Work at office
    Remote work
    Flexible hours

    Mixpeek

    New York, NY
    2 days ago
  •  ...sensitive data and privileged access they need to get issues fixed. You'll lead application security across our SaaS and AI products as part of our infrastructure team within Engineering. Working directly with product managers and other engineers, you'll establish our... 
    Shift work

    A S S E M B L E D

    New York, NY
    4 days ago
  •  ...Job Description Insight Global is seeking a Security Engineer (AVP / Associate AVP) for a leading global financial services firm in New York, NY. This individual will join the firm’s Information Security team, focusing on cloud security, automation, and AI risk evaluation... 

    Insight Global

    New York, NY
    5 days ago
  •  ...13, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. Security Engineering is the engineering function inside the Plaid security org that focuses on developing the industry-leading security systems and... 
    Full time
    Work experience placement
    Local area

    Plaid

    New York, NY
    more than 2 months ago
  •  ...fraud, AI-driven scams, and identity abuse spread faster than any security team can respond to. So we built something different: an...  ...weeks. Built by ex-Palantir, ex-CTO/founders, and ex-Notion engineers, Outtake is designed for clarity, autonomy, and velocity. Our... 
    Full time
    Work at office
    Flexible hours

    Out Take

    New York, NY
    more than 2 months ago
  • $50 - $55 per hour

     ...your skills and experience — talk with your recruiter to learn more. Base pay range $50.00/hr - $55.00/hr Job Title: Security Engineer II Location-Type: Remote Start Date Is: 2–4 weeks from offer Duration: 6 months contract-to-hire Job Description... 
    Contract work
    Local area
    Remote work

    Mondo

    New York, NY
    1 day ago
  •  ...Description MULTIPLE POSITIONS AVAILABLE Employer: AMAZON DEVELOPMENT CENTER U.S., INC. Offered Position: Security Engineer III Job Location: New York, New York Job Number: AMZ9971078 Position Responsibilities: Partner closely with Product Management... 

    Amazon

    New York, NY
    17 hours ago
  • $237.6k - $297k

     ...We are seeking a Senior Security Engineer with a specialty in Detection and Incident Response to join our Security Engineering team. This role sits at the intersection of security operations and software engineering - you won't just investigate incidents, you'll build... 
    Full time

    United States Digital Space LLC

    New York, NY
    4 days ago
  •  ...Security EngineerLocation: New York, NY 10286 (hybrid) Duration: 12 Months with possible extension We're building the secure, scalable...  ...key management, and next?generation transaction security. Our engineers work on real-world challenges involving cryptography,... 
    Remote work

    InterSources

    New York, NY
    4 days ago
  • $128.9k - $180k

     ...team at your back. If Braze sounds like a place where you can thrive, we can't wait to meet you. WHAT YOU'LL DO As a Senior Security Engineer on the Enterprise Security team, you'll protect Braze employees, their assets, and work locations using various tools and technologies... 
    Work at office
    Local area
    Flexible hours

    Braze

    New York, NY
    1 day ago
  •  ...Manufacturing company, in business since 1951, is seeking a self motivated, team player, to focus on the following role: The IT Security Engineer is responsible for identifying, remediating, and tracking security vulnerabilities across the organization's systems while... 

    Es Vee Placement

    New York, NY
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Offensive Security Engineer. Be the first to apply!