Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Offensive Security Engineer

$170.4k - $255.7k

Xapply

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

The Proactive Threat team is responsible for identifying vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure — before adversaries do. We operate as a hybrid offensive function: conducting penetration testing, emulating real-world threat actors through red team operations, and partnering closely with our defensive security teams to validate detection capabilities and improve Stripe's overall security posture.

We are builders first. Our team develops custom tooling, automation frameworks, and internal platforms that scale our offensive capabilities and enable repeatable, high-fidelity assessments. We believe the best offensive security engineers are equal parts hacker and engineer.

The team is distributed across the United States, primarily operating in Eastern and Pacific time zones, and collaborates regularly with security, engineering, and product stakeholders across Stripe — including teams in Europe and Asia.

What you'll do

As an Offensive Security Engineer on the Proactive Threat team, you will simulate the tactics, techniques, and procedures (TTPs) of real-world adversaries to uncover security risks across Stripe's products and infrastructure. You'll conduct hands-on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities. Your work will directly influence how Stripe builds, ships, and secures financial infrastructure used by millions of businesses worldwide.

Beyond assessments, you'll design and build offensive tooling and automation that amplifies the team's impact. You'll leverage threat intelligence to prioritize testing efforts, contribute to incident investigations when needed, and act as a subject-matter expert for security initiatives across the company.

Responsibilities
  • Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure
  • Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios
  • Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams
  • Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity
  • Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks
  • Support incident investigations by providing offensive expertise, log analysis, and root cause analysis when required
  • Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverage
  • Build internal platforms and workflows that enable scalable, repeatable offensive operations
  • Contribute to internal security tooling repositories and champion engineering best practices within the team
  • Automate repetitive testing tasks, payload generation, and reporting workflows using modern development practices
  • Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non-technical stakeholders
  • Act as a subject-matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and Stripe-wide security initiatives
  • Lead offensive security projects end-to-end, mentor junior team members, and foster a culture of continuous learning and knowledge sharing
  • Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and contribute to the broader security community
Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. The preferred qualifications are a bonus, not a requirement.

  • 5+ years of experience in offensive security, penetration testing, red teaming, or a related field
  • Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits
  • Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.)
  • Hands-on experience with cloud platforms (AWS, Azure, or GCP), including cloud-native attack techniques and misconfigurations
  • Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks
  • Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including TTPs for initial access, privilege escalation, lateral movement, and exfiltration
  • Excellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk-based recommendations
  • Ability to think like an adversary — creative, persistent, and able to holistically assess risk in complex environments
Preferred qualifications
  • Experience conducting offensive security in fintech, financial services, or other highly regulated environments
  • Background in vulnerability research, exploit development, or CVE discovery
  • Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations)
  • Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support
  • Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows
  • Interest or experience in agentic automation — using LLMs or autonomous agents to augment reconnaissance, vulnerability discovery, or exploitation workflows
  • Experience testing AI/ML systems or LLM-based applications for security weaknesses (prompt injection, training data extraction, model manipulation, etc.)
  • Contributions to open-source security tools, published research, blog posts, or conference presentations
  • Relevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications
Location

This role is remote within the United States. While you are welcome to visit Stripe offices for team meetings, on-sites, and events, our expectation is that you would regularly work from home. The team primarily coordinates across Eastern and Pacific time zones, with regular collaboration with stakeholders in Europe and Asia.

The annual US base salary range for this role is $170,400 – $255,700. This range may span multiple career levels and will be refined during the interview process based on experience, qualifications, and location.

Additional benefits include:

  • Equity participation in Stripe's growth
  • 401(k) plan with matching contributions from day one
  • Comprehensive medical, dental, and vision coverage
  • Wellness stipends
  • Annual budget for training, certifications, and conference attendance
#J-18808-Ljbffr
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Offensive Security Engineer in Eastern, KY vacancy
  • $300k - $320k

     ...growing group of committed researchers, engineers, policy experts, and business leaders working...  ...AI systems. About the Team The Security Engineering team's mission is to...  ...hands-on experience in red teaming and offensive security operations ~ Deep expertise in... 
    Suggested
    Visa sponsorship

    EngineersOfAI

    Eastern, KY
    3 days ago
  • $170.4k - $255.7k

    # Offensive Security Engineer: US - Remote: Sep 25, 2026: Sep 25, 2026## About the roleWho we areAbout StripeStripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe... 
    Suggested
    Remote work
    Work from home
    Worldwide

    Praxy, Inc.

    Eastern, KY
    3 days ago
  • $180k - $230k

     ...transform regulated industries and beyond. Security at Valon Our customers entrust us with...  ...team partners closely with Product and Engineering to design and deliver secure, scalable,...  ...Senior Security Engineer, Threat & Offensive Security to join our growing team! As a... 
    Suggested
    Local area
    Remote work
    Flexible hours

    Apply

    Eastern, KY
    5 days ago
  • $175k - $260k

     ...Senior Information Security Engineer, Offensive Security Seeking experienced offensive security professionals to conduct security assessments, red team operations, and network exploitation activities in support of client security requirements. What You'll be Owning... 
    Suggested
    Contract work
    Work experience placement

    Jobleads-US

    Eastern, KY
    1 day ago
  • DRW is seeking a Senior Offensive Security Engineer to lead red team engagements, adversary simulations, and exploit development. You will collaborate with security, infrastructure, and trading teams to translate findings into measurable improvements. Ideal candidates bring... 
    Suggested

    Tradermath

    Eastern, KY
    1 day ago
  • Crusoe is seeking a Staff Product Security Engineer with deep AI/ML security expertise to strengthen Crusoe’s security posture across applications...  ...teams rely on. You’ll operate at the intersection of offensive security, AI systems, and production engineering; owning... 

    DCYB

    Eastern, KY
    2 days ago
  • Bishop Fox is seeking a Solutions Engineer to join our security consultancy team. You’ll partner with clients to understand and test their security from an attacker’s perspective. You’ll translate complex concepts for executives, lead scoping discussions, and collaborate... 

    Bishop Fox

    Eastern, KY
    1 day ago
  • Horizon3 is hiring a Staff Attack Engineer specializing in AI/LLM security to join our team. You will break AI and agentic systems and turn research...  ...across customer environments and driving our LLM-powered offensive capabilities with technical leadership. #J-18808-... 

    Aimlroles

    Eastern, KY
    3 days ago
  •  ...traditional 9-to-5. The Opportunity Deepgram is looking for a Security Engineer to build and automate the technical controls behind our...  ...(IAM, SCPs, VPC) and Terraform. Kubernetes security. Offensive security background: penetration testing or red teaming.... 

    Linuxconfig

    Eastern, KY
    2 days ago
  • # Senior Security Engineer - Penetration TesterTruistFull-timeAtlanta, Georgia, USA, Charlotte, North Carolina, USA, Raleigh, North Carolina...  ...to support regulatory, audit, and compliance requirements.Offensive Security ExpertiseDefend findings during discussions with application... 
    Shift work

    MainframeMaster

    Eastern, KY
    3 days ago
  •  ...dollars, and stablecoins in one place, secured by multi-institution custody and delivered...  ...'s security roadmap, reporting to our Engineering Lead and partnering with our CCO, who owns...  ...a stronger playbook Build AI-driven offensive testing: continuous, agent-assisted pen... 
    Full time
    Contract work
    Remote work

    Onramp Bitcoin

    Eastern, KY
    1 day ago
  • Greenlight is seeking a Staff Offensive Security Engineer to lead continuous offensive validation across our consumer platforms, mobile apps, cloud infrastructure, and hardware lines. You will drive the long-term security strategy, design and run complex red team simulations... 

    Owl Ventures, LP

    Eastern, KY
    1 day ago
  •  ...Oversees the response to information system security incidents, including investigation of,...  ..., coaching, and mentorship to other ISO Engineers in executing their tasks &...  ...Threat Hunting, Vulnerability Management and Offensive Security, Email Security, Mobile, IoT, Distribution... 
    Work at office
    Local area
    Worldwide

    World Courier

    Eastern, KY
    5 days ago
  •  ...create world-class products. The Role: We're looking for a Security Engineer to join our AI Platform Security team. It is a high-...  ...Experience in security engineering, application security, offensive security, or a closely related technical discipline Deep,... 
    Work at office
    Local area
    Shift work
    3 days per week

    ThoughtSpot

    Eastern, KY
    3 days ago
  •  ...ranging from seed-stage startups to Meta. We are hiring a Senior Security Engineer to own the technical security posture of those systems once...  ...systems around them change. Vulnerability management and offensive security: Scanning, penetration testing, adversarial testing... 
    Immediate start
    Remote work

    Azumo

    Eastern, KY
    1 day ago
  • $150k - $170k

     ...Infrastructure Security EngineerSkip to main contentYou may choose to display a cookie banner...  ...legal counsel.#Infrastructure Security Engineer page is loaded## Infrastructure Security...  ...to run the operational core of our offensive and vulnerability management programs. You... 
    Remote work
    Shift work

    Cast & Crew Entertainment Services, LLC

    Eastern, KY
    1 day ago
  • $226k - $283k

     ...workflows inside some of the country’s most security-sensitive health systems. Security can't be bolted on - it must be engineered into the product. This is a senior...  ...ability to develop that expertise quickly. Offensive validation instincts. You can reproduce vulnerabilities... 
    Work at office
    3 days per week

    Apply

    Eastern, KY
    3 days ago
  • $10 per hour

     ...configuration drift across our critical SaaS applications. Own security configuration for the SaaS tools hundreds of Flexporters use...  ...years of experience in corporate, enterprise, or IT security engineering — we care more about what you've shipped than the exact number... 
    Work at office
    Immediate start
    Flexible hours

    Flexport

    Eastern, KY
    1 day ago
  • Markesman Group in Annapolis Junction, MD is seeking a Cyber Engineer to join our offensive cyber team. You will design, develop, test, and deploy embedded software for offensive operations and work on vulnerability exploitation. Applicants should have TS/SCI clearance... 

    Paychex

    Eastern, KY
    4 days ago
  • We are seeking an Autonomous Security Engineer, Customer Solutions to operate at the intersection of autonomous offensive security, technical consulting, and customer engineering. You'll be on the front lines of customer engagements, using Apex and the Pensar platform... 

    PensarAI, Inc.

    Eastern, KY
    1 day ago
  • NETWORK SECURITY ENGINEER: Expert Level Location: Chantilly, VA US Security Clearance Requirement: TS/SCI with Full Scope Polygraph Clearance...  ...Engineers who are familiar with both network defense and offensive techniques to support ongoing operations and secure our customers... 

    Inferno Systems Inc.

    Eastern, KY
    3 days ago
  •  ...infrastructure that developers need to securely scale their products to large organizations...  ...collaborative group with a strong engineering mindset. Our security program is shaped...  ...easiest path for engineers. Perform offensive security testing. Conduct penetration tests... 
    Work experience placement
    Remote work

    Kos Ai

    Eastern, KY
    3 days ago
  •  ...getting started. Role Overview As a Senior Software Engineer on the Product Security team at Harvey, you will have the opportunity to build...  ...of experience in product security, application security, offensive security, and/or security-focused software engineering... 
    Work experience placement

    Harvey

    Eastern, KY
    5 days ago
  • $120k - $175k

    # Security Research EngineerRun customer pentests with Apex, drive offensive security research, and shape our platform from the fieldLocationNew York, NYArrangementOn-...  ...Position OverviewWe are seeking a Security Research Engineer to operate as a hybrid Forward Deployed... 

    PensarAI, Inc.

    Eastern, KY
    2 days ago
  • Dominion Energy is seeking a Senior Cyber Security Analyst focused on penetration testing to identify exploitable weaknesses across applications, networks, cloud, and OT environments. You will plan engagements, perform hands‑on testing, and produce clear, actionable remediation... 

    Dominion Energy

    Eastern, KY
    2 days ago
  •  ...Security is at the foundation of Zizy’s mission to ensure that artificial general intelligence benefits all of humanity. The Security...  ...a robust security culture. About the Role As a Software Engineer focused on Security Partnerships on the Security Platform and Products... 

    Zizy Inc.

    Eastern, KY
    1 day ago
  •  ...provenance, consent, licensing and payment history associated with data records can be verified. We are looking for a hands-on Security Engineer to own and strengthen security across PIP Labs’ cloud environment, endpoints and internal systems, while also supporting... 

    The DATA Foundation

    Eastern, KY
    1 day ago
  •  ...customers, and what they find interesting and motivating to work on. Engineers lead product teams and make product decisions. Teams are...  .... Who we're looking for We are looking for an expert security generalist (in EU/UK) to assist with all things security at PostHog... 
    Remote work
    Flexible hours
    Night shift

    Jobgether SRL

    Eastern, KY
    1 day ago
  • $300k - $400k

     ...Member of Technical Staff, Security Engineer About Fleet Fleet studies how environments produce intelligence. We believe intelligence is an emergent property of environmental pressures: the environment determines what capabilities develop, what behaviors survive... 
    Full time

    Fleet AI, Inc.

    Eastern, KY
    3 days ago
  •  ...and Access Management (IAM) team is dedicated to ensuring the secure and efficient management of user identities, access privileges,...  ...the Role As an Identity and Access Management (IAM) Security Engineer, you will play a crucial role in designing, implementing, and scaling... 
    Local area

    Precision Labs

    Eastern, KY
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Offensive Security Engineer. Be the first to apply!