Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Offensive Security Engineer

$170.4k - $255.7k

Stripe

Who we are
About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

The Proactive Threat team is responsible for identifying vulnerabilities and security weaknesses across Stripe's systems, applications, networks, and cloud infrastructure — before adversaries do. We operate as a hybrid offensive function: conducting penetration testing, emulating real-world threat actors through red team operations, and partnering closely with our defensive security teams to validate detection capabilities and improve Stripe's overall security posture.

We are builders first. Our team develops custom tooling, automation frameworks, and internal platforms that scale our offensive capabilities and enable repeatable, high-fidelity assessments. We believe the best offensive security engineers are equal parts hacker and engineer.

The team is distributed across the United States, primarily operating in Eastern and Pacific time zones, and collaborates regularly with security, engineering, and product stakeholders across Stripe — including teams in Europe and Asia.

What you'll do

As an Offensive Security Engineer on the Proactive Threat team, you will simulate the tactics, techniques, and procedures (TTPs) of real-world adversaries to uncover security risks across Stripe's products and infrastructure. You'll conduct hands-on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities. Your work will directly influence how Stripe builds, ships, and secures financial infrastructure used by millions of businesses worldwide.

Beyond assessments, you'll design and build offensive tooling and automation that amplifies the team's impact. You'll leverage threat intelligence to prioritize testing efforts, contribute to incident investigations when needed, and act as a subject-matter expert for security initiatives across the company.

Responsibilities
  • Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure
  • Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios
  • Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams
  • Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity
  • Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks
  • Support incident investigations by providing offensive expertise, log analysis, and root cause analysis when required
  • Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverage
  • Build internal platforms and workflows that enable scalable, repeatable offensive operations
  • Contribute to internal security tooling repositories and champion engineering best practices within the team
  • Automate repetitive testing tasks, payload generation, and reporting workflows using modern development practices
  • Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non-technical stakeholders
  • Act as a subject-matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and Stripe-wide security initiatives
  • Lead offensive security projects end-to-end, mentor junior team members, and foster a culture of continuous learning and knowledge sharing
  • Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and contribute to the broader security community
Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements
  • 5+ years of experience in offensive security, penetration testing, red teaming, or a related field
  • Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits
  • Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.)
  • Hands-on experience with cloud platforms (AWS, Azure, or GCP), including cloud-native attack techniques and misconfigurations
  • Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks
  • Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including TTPs for initial access, privilege escalation, lateral movement, and exfiltration
  • Excellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk-based recommendations
  • Ability to think like an adversary — creative, persistent, and able to holistically assess risk in complex environments
Preferred qualifications
  • Experience conducting offensive security in fintech, financial services, or other highly regulated environments
  • Background in vulnerability research, exploit development, or CVE discovery
  • Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations)
  • Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support
  • Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows
  • Interest or experience in agentic automation — using LLMs or autonomous agents to augment reconnaissance, vulnerability discovery, or exploitation workflows
  • Experience testing AI/ML systems or LLM-based applications for security weaknesses (prompt injection, training data extraction, model manipulation, etc.)
  • Contributions to open-source security tools, published research, blog posts, or conference presentations
  • Relevant certifications such as OSCP, OSWE, OSEP, OSED, CRTO, CPTS, PNPT, GXPN, or cloud security certifications
Location

This role is remote within the United States. While you are welcome to visit Stripe offices for team meetings, on-sites, and events, our expectation is that you would regularly work from home. The team primarily coordinates across Eastern and Pacific time zones, with regular collaboration with stakeholders in Europe and Asia.

Compensation & Benefits

The annual US base salary range for this role is $170,400 – $255,700. This range may span multiple career levels and will be refined during the interview process based on experience, qualifications, and location.

Additional benefits include:

  • Equity participation in Stripe's growth
  • 401(k) plan with matching contributions from day one
  • Comprehensive medical, dental, and vision coverage
  • Wellness stipends
  • Annual budget for training, certifications, and conference attendance
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Offensive Security Engineer in United States vacancy
  •  ...your home. The Mission Praetorian is an expert-driven offensive security company. Our mission is to prevent breaches before they...  ...Looking For We are looking for an Offensive Security Engineer who operates with clear ownership. You're not just filling... 
    Suggested
    Internship
    Shift work

    Praetorian

    Austin, TX
    1 day ago
  • $73k - $171.3k

     ...travel insurance ~ Tuition assistance ~ Wellness reimbursement program ~ Paid holidays and vacation What is an Offensive Security Engineer? We are seeking a diligent and experienced Offensive Security Engineer to join our team. In this role, you will be... 
    Suggested
    Full time
    For contractors
    Local area
    Night shift
    Weekend work

    Central Hudson

    Poughkeepsie, NY
    3 days ago
  •  ...Our client is seeking an Offensive Security Engineer to help build and shape a brand-new offensive security program from the ground up. The ideal candidate will be hands-on, resourceful, and comfortable working directly with leadership to establish new processes and... 
    Suggested
    Flexible hours

    The Right Click, Inc.

    Poughkeepsie, NY
    2 days ago
  • $300k - $320k

     ...growing group of committed researchers, engineers, policy experts, and business leaders working...  ...AI systems. About the Team The Security Engineering team's mission is to safeguard...  ...hands-on experience in red teaming and offensive security operations Deep expertise in at... 
    Suggested
    Work at office
    Visa sponsorship
    Flexible hours

    Anthropic

    San Francisco, CA
    1 day ago
  •  ...year. About the Team We are looking for an enthusiastic Offensive Application Security Intern to join our team, where you'll conduct simulated...  ...of: C, C++, PHP, Go,x86, ARM, CAN, cryptography, reverse engineering, wireless networks Strong understanding of common web vulnerabilities... 
    Suggested
    Full time
    Temporary work
    Part time
    Internship
    Flexible hours

    Tesla

    Austin, TX
    2 days ago
  • $180k - $230k

    Senior Security Engineer, Threat & Offensive Security Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. We're a Series C company backed by a16z, transforming industries that others have written off as too complex to... 
    Remote work
    Flexible hours

    Valon

    New York, NY
    2 days ago
  • $160k - $200k

     ...Chantilly, VA, US Date Posted: 2026-09-24 Category: Engineering and Sciences Subcategory: Systems Engineer Schedule:...  ...is seeking a Communications Systems Engineer to act as Offensive Security Engineer to provide onsite systems engineering and technical... 
    Full time
    Contract work
    Work at office
    Remote work
    Shift work

    SAIC

    Chantilly, Loudoun County, VA
    1 day ago
  • $145k - $200k

     ...disruptions, locate missing children, and more. The Role Palantir's Offensive Security team probes our own products, infrastructure, and cloud...  ...the way a real attacker would. As an Offensive Security Engineer, you will test internal applications and infrastructure,... 
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    2 days ago
  • Job Description | Offensive Security Engineer - Red Team We are currently looking for qualified cybersecurity resources for the below requirements: ~1 Red Team Resource Egypt ~12 months ~ get expected

    Lancesoft Europe

    Alexandria, VA
    1 day ago
  •  ...every operation into concrete detection engineering wins and defensive improvements...  ...engineering guidance for IT, Network, and Security teams. - Track operational metrics: objectives...  ..., sharing tradecraft with internal offensive and defensive staff. What you'll bring... 
    Full time
    Work at office

    Sportygroup

    Remote
    3 days ago
  • $120k - $260k

    Senior Staff Security Engineer At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities. Every day we...  ...strategy and technical execution of Vulnerability Management and Offensive Security across a complex, hybrid technology ecosystem. This... 
    Hourly pay
    Work experience placement
    Local area

    GEICO

    Seattle, WA
    2 days ago
  •  ...Seeking a full-time Senior Offensive Security Engineer focused on enhancing AI-driven offensive security, this remote position will manage the development of autonomous red team agents, improve existing agent capabilities, and mentor team members in advanced offensive... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    4 days ago
  • $148.5k - $223.9k

     ...? You’re in the right place! Agentforce is the future of AI, and you are the future of Salesforce. Job Title: Senior Offensive Security Engineer, Red Team The Experience The Product Red Team focuses on attacking Salesforce's full deployed product ecosystem and... 
    Remote work

    Salesforce

    United States
    1 day ago
  • $175k - $250k

     ...Description What Impact You'll Have Seeking experienced offensive security professionals to conduct security assessments, red team...  ...offensive security certifications Experience with reverse engineering and exploit development Background in offensive cyber operations... 
    Contract work
    Work experience placement
    Immediate start

    GRVTY

    Columbia, MD
    24 days ago
  •  ...Senior Offensive Security Engineer (Red Team) Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword — it's a way of life. The world of work as we know it... 
    Remote work

    Salesforce

    United States
    4 days ago
  • $157.59k

     ...Senior Offensive Security Engineer Chime Chicago, IL, US Full-Time IT Fintech About Chime Chime was created with the mission to make financial peace of mind a reality for millions of everyday people. We're one of the fastest-growing financial technology... 
    Full time
    Work at office
    Local area
    Remote work
    Night shift

    Chime - Chicago, IL, US

    Chicago, IL
    1 day ago
  • $116k - $174k

     ...will play a crucial role in maintaining the efficiency and security of our IT environment, enabling the company to achieve its...  ...'s Information Security organization is hiring a Senior Offensive Security Engineer to help build and mature an offensive security capability... 
    Full time
    Remote work
    Flexible hours
    Shift work

    World Wide Technology

    Maryland Heights, MO
    4 days ago
  • $170k - $250k

     ...Senior Offensive Security Engineer - Internal Audit Chicago, IL (Elmhurst) Who We Are McMaster-Carr is a leading e-commerce company that industrial customers have trusted for 125 years. Our products help them get manufacturing lines back up quickly, keep operations... 

    McMaster-Carr

    Chicago, IL
    1 day ago
  • $96k - $181k

     ...broader Cyber Defense function within Corporate Information Security. Cyber Defense's mission is simple: We aim to Deter,...  ...adversaries through proactive threat-centric defense. The Senior Offensive Security Engineer serves as the technical and operational lead for the Cyber... 
    Work at office
    Remote work
    Flexible hours

    Key Bank

    Brooklyn, OH
    3 days ago
  • $187k - $220k

    Senior Offensive Security Engineer Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history... 
    Work at office
    Shift work
    3 days per week

    Robin Hood

    New York, NY
    4 days ago
  • $101.4k - $152.1k

    The Senior Offensive Security Engineer, Commercial Products will perform hands-on offensive security testing across Ecolab's commercial digital product portfolio. This role will focus on technical testing of customer-facing commercial products, including web and mobile... 
    Hourly pay
    Minimum wage
    Local area
    Flexible hours

    Ecolab

    Naperville, IL
    2 days ago
  •  ...About the role Mission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external...  ..., and endpoint defenses. The Offensive Security Engineer owns the security testing, continuous perimeter monitoring,... 
    Full time
    Work at office
    Local area
    Remote work

    Sporty Group

    Remote
    15 days ago
  • $99k - $120k

     ...natural tinkerer who loves attacking systems to make them unshakeable, this role is built for you. As a Security Engineer II on our Active Operational Offensive track , you’ll sit at the heart of Flywire’s security defenses under the guidance of senior engineers.... 
    Full time
    Local area
    Immediate start

    Flywire

    Boston, MA
    16 days ago
  • Senior Offensive Security Engineer (Red Team) Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action. Tech meets trust. And innovation isn't a buzzword — it's a way of life. The world of work as we know it is changing... 

    Salesforce

    New York, NY
    2 days ago
  • $196.75k - $243.29k

     ...solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in the offensive security assessments that strengthen our... 
    Full time
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday

    Roblox

    San Mateo, CA
    2 days ago
  • Anthropic is seeking a senior security engineer to lead red teaming and offensive security across our cloud and on-prem infrastructure. You will simulate adversaries, discover novel attack vectors, and help shape risk-based security roadmaps. The role requires strong programming... 

    Socket

    Friendly, WV
    1 day ago
  • Staff Offensive Security Engineer Cloaked is a consumer privacy and identity platform on a mission to give people back control of their personal data. We let anyone generate unlimited identities - masked emails, phone numbers, and payment cards - scrub their information... 

    Cloaked

    New York, NY
    2 days ago
  • $198.1k - $268k

    Job Description: The Security Research and Response team in Arm's Architecture and Technology Group is seeking a highly skilled SoC Offensive Security Staff Engineer to apply an attacker's mindset to Arm's next-generation solutions, identifying design and integration-... 
    Work at office
    Local area

    ARM

    Austin, TX
    2 days ago
  •  ...time managing life, and more time living it. That's why we get out of bed every morning. Greenlight is looking for a Staff Offensive Security Engineer for our Security team. This individual will be responsible for the continuous offensive security validation across our... 
    Full time
    Day shift

    Greenlight

    Remote
    17 days ago
  •  ...Employee Studio/Department CT - Security Work Model Hybrid Description...  ...Location: OrlandoReports to: Sr. Director Engineering, Application Security & Red TeamingJob...  ...drive everything we do. As an Offensive Security Engineer, you will report to the... 
    Local area

    Electronic Arts

    Orlando, FL
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Offensive Security Engineer. Be the first to apply!