# Offensive Security Engineer at Stripe

- Company: Stripe
- What the company does: Stripe is a financial services platform that helps all types of businesses accept payments, build flexible billing models, and manage money movement. Backed by General Catalyst, Khosla and Kleiner Perkins.
- Company website: https://stripe.com/
- Type: Startups
- Level: Mid level
- Location: US - Remote
- Work setup: Remote
- Pay: $170K to $256K base salary per year (USD)
- Posted: 2026-09-25
- Apply by: 2026-11-09
- Apply: https://stripe.com/jobs/search?gh_jid=8233889
- Page: https://www.1752.vc/careers/jobs/stripe-offensive-security-engineer/

## About the role

As an Offensive Security Engineer on the Proactive Threat team, you will simulate the tactics, techniques, and procedures (TTPs) of real-world adversaries to uncover security risks across Stripe's products and infrastructure. You'll conduct hands-on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities.

## What they're looking for

- 5+ years of experience in offensive security, penetration testing, red teaming, or a related field
- Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits
- Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes (injection, auth flaws, business logic, etc.)
- Hands-on experience with cloud platforms (AWS, Azure, or GCP), including cloud-native attack techniques and misconfigurations
- Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks
- Familiarity with adversary tradecraft and frameworks such as MITRE ATT&CK, including TTPs for initial access, privilege escalation, lateral movement, and exfiltration

Tags: Security Analytics
