Security Incident Response Engineer
en Stripe, Chicago, New York, Seattle, South San Francisco HQ / Remote in United States
17 de Septiembre de 2026
Security Incident Response Engineer
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies, from large global enterprises to ambitious startups, use Stripe to accept payments, grow revenue, and develop new business opportunities. Stripe's mission is to increase the GDP of the internet and make more of the global economy accessible through technology.
About the team
The Security Incident Response team analyzes, investigates, and responds to threats before they affect Stripe's business or users. Its work covers external attacks, insider threats, remediation, and support for the incident postmortem process.
The team is distributed across multiple AMER time zones and regularly coordinates with stakeholders in EMEA and APAC.
What the role involves
The Security Incident Response Engineer will use security engineering experience to strengthen Stripe's incident response capabilities. The role has a strong focus on user and entity behavior analytics and endpoint hardening.
The engineer will develop a deep understanding of Stripe's systems, tools, and workflows to distinguish legitimate activity from malicious behavior. Using threat intelligence and collected telemetry, the role will help develop Stripe-specific signal enrichment logic and incident response solutions that can scale with the company.
Analytical capabilities will also be important during security incidents to reduce uncertainty, identify root causes, and support future prevention and detection mechanisms.
Responsibilities
- Analyze and investigate a broad range of threats and activities occurring on client devices.
- Develop requirements for detection models and improvements to existing systems.
- Collect, transform, and ingest raw data from different sources into threat detection pipelines.
- Improve incident response capabilities and ensure that tools and processes are clear and effective.
- Work cross-functionally with security engineering and data science teams to build solutions for analyzing security event data at scale and protecting Stripe's networks, systems, and data.
- Provide actionable insights that support the identification, prevention, detection, and response to anomalous or potentially malicious user and entity activity.
- Act as a subject-matter expert and primary contact for teams involved in Security Analytics and Detection programmes and wider Stripe security initiatives.
- Collaborate with teammates, lead projects, mentor others, and help develop and promote quality standards within the team.
Candidate profile
Stripe is looking for candidates who meet the minimum requirements for the role. Preferred qualifications are considered an advantage, but are not required.
Minimum requirements
- 3+ years of experience analyzing large data sets to solve problems and/or building models using a behavioral approach to security.
- B.S. or M.S. in Computer Science or a related field, or equivalent professional experience.
- Expert knowledge of Python and SQL, with familiarity with other programming languages.
- Experience with log analysis, including first-party or third-party applications, system and data access, and event logs.
- Experience with network security, digital forensics, and incident response investigations.
- Ability to develop and use analytical methods to build, automate, and improve detection and response systems.
- Ability to communicate results clearly and focus on impact.
- Ability to think creatively and holistically about reducing risk in a complex environment.
Preferred qualifications
- An adversarial mindset and an understanding of threat actor goals, behavior, and TTPs.
- Experience with software engineering, data processing, and analysis tools such as Databricks, Jupyter, or Trino.
- Familiarity with open-source big data processing and data science frameworks such as PySpark, Pandas, and Sci-kit Learn.
- Experience with tactical threat intelligence and/or threat hunting for sophisticated threat actors in enterprise environments.
- Familiarity with network observability, security software, or data engineering tools such as osquery, Splunk, or LogScale.
- Experience in one or more areas including user and entity behavior analytics (UEBA), security information and event management (SIEM), security orchestration, automation and response (SOAR), or data loss prevention (DLP).
Hybrid work at Stripe
The role is available from a Stripe office or remotely in the United States. Remote work is available for candidates located at least 35 miles or 56 kilometres from a Stripe office.
In-office expectations
Employees assigned to an office are expected to spend at least 50% of their working time in a given month in their local office or with users. Stripe uses this model to combine in-person collaboration and learning with flexibility for individuals and teams.
Remote work
Remote employees are expected to work regularly from home rather than from a Stripe office. They may still attend team and business meetings, on-sites, meet-ups, and company events in Stripe offices. Stripe does not cover relocation costs to a remote location.
Pay and benefits
The annual US base salary range for this role is $144,300 to $216,500. The final salary range may vary depending on career level, experience, qualifications, and location.
Candidates outside the United States may request the salary range applicable to their location during the interview process.
Additional benefits may include equity, a company bonus or applicable sales commissions and bonuses, a 401(k) plan, medical, dental and vision benefits, and wellness stipends.
About candidates
Stripe is looking for people with passion, grit, and integrity. Candidates are encouraged to apply even if their experience does not match every element of the job description. Stripe values diverse perspectives, rigorous thinking, and people who are willing to challenge assumptions.