Hiring.Camp

Security Incident Response Engineer

Stripe

Location
US Remote · US
Workplace
Remote
Department
Security
Experience
3+ years
Education
Master

Description

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

About the team

The Security Incident Response team works to analyze, investigate, and respond to threats before they impact Stripe’s business or users. From external attacks to insider threats, our goal is to respond with speed and precision, remediate, and support the incident postmortem process. The team is distributed, working across multiple AMER time zones, and will regularly coordinate with stakeholders in EMEA and APAC.

What you’ll do

You will leverage your security engineering experience to improve incident response capabilities at Stripe. With an emphasis on user and entity behavior analytics, as well as endpoint hardening, you will gain a deep understanding of Stripe’s systems, tooling, and workflows to be able to differentiate between legitimate and malicious activity.  Using both threat intelligence and collected telemetry, you will guide and build Stripe-specific signals enrichment logic and incident response solutions that scale with our company.  Lastly, your analytic capabilities will be critical during security incidents to reduce uncertainty, uncover root causes, and inform future prevention and detection mechanisms. 

Responsibilities

  • Analyze and investigate a broad range of threats or activities occurring on client devices
  • Develop requirements for detection models and enhancements to existing systems
  • Collect, transform, and ingest raw data from disparate sources into threat detection pipelines
  • Streamline incident response capabilities, ensuring the tooling and processes are clear
  • Work cross-functionally with security engineering and data science teams to build solutions for analyzing security events data at scale and protecting Stripe networks, systems, and data from threats
  • Provide actionable insights to help identify, prevent, detect, and respond to anomalous or potentially malicious user and entity activity
  • Act as the subject-matter expert and primary contact for stakeholder teams invested in Security Analytics and Detection programs as well as Stripe-wide security initiatives
  • Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team

Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • 3+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to security
  • B.S. or M.S. Computer Science or related field, or equivalent experience
  • Expert knowledge of Python and SQL, and familiarity with other programming languages
  • Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
  • Proficiency with developing and using novel analytical methods to build, automate, and improve detection and response systems
  • Ability to communicate results clearly and focus on impact
  • Ability to think creatively and holistically about reducing risk in a complex environment

Preferred qualifications

  • An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
  • Experience with software engineering, data processing and analysis tools (e.g. Databricks/Jupyter, Trino, etc.)
  • Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
  • Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
  • Familiarity with network observability, security software, or data engineering solutions (osquery, Splunk/LogScale, etc.)
  • Experience in one or more of the following areas: user and entity behavior analytics (UEBA), security information event management (SIEM), security orchestration automation and response (SOAR), or data loss prevention (DLP)

Skills

PythonSQLPandasDatabricksData ScienceData EngineeringSIEMSplunkLoss Prevention

Similar Jobs

30

Security Engineer – AWS Security Incident Response, Cloud Security, AI Security, EDR & SIEM

Alcon · Bangalore - AGS, India

Yesterday

Senior Analyst: Information Security Incident Response

Nttlimited · Sydney, Australia +1

2 days ago

10279 - Security Incident Response Manager (SSRM)

Hyundai Autoever America · Irvine, CA

6 days ago

Senior Product Cybersecurity Engineer, Product Security Incident Response Team (PSIRT)

General Motors · GM Global Technical Center - Cole Engineering Center Podium, United States of America · Hybrid

6 days ago

Senior/Lead Cyber Security - Incident Response Engineer

Fico · Work from Home, United States, United States of America · Remote

6 days ago

Security Incident Response Engineer

Acrisure · 1170 Peachtree St Ste 1200 - ATLANTA, GA, United States of America

1 week ago

Security Incident Response Engineer

Acrisure · 1170 Peachtree St Ste 1200 - ATLANTA, GA, United States of America +1

1 week ago

Business Operations for Security Incident Response (SIR) , Enterprise Support Strategy & Operations (ESSO), Enterprise Support Strategy & Operations (ESSO)

Amazon

1 week ago

Security Engineer, AWS Security Incident Response

Amazon

1 week ago

Senior Security Engineer, AWS Security Incident Response

Amazon

1 week ago

Associate Manager - Cyber Security Incident Response

LON3 London - 51 Lime Street · London, London, United Kingdom, GB

1 week ago

Security Engineer, AWS Security Incident Response

Amazon

2 weeks ago

Manager, Security Incident Response

hubinternational · Chicago - IL - 200 N. La Salle St - Suite 1700, United States of America · Hybrid

2 weeks ago

Senior Security Incident Response Analyst (m/f/x)

Scalable GmbH · Berlin, BE, Germany · Hybrid

3 weeks ago

Senior Security Incident Response Analyst (m/f/x)

Scalable GmbH · München, BY, Germany · Hybrid

3 weeks ago

Product Security Incident Response Engineer

Analogdevices · United Kingdom, Edinburgh, SC, Freer +1

3 weeks ago

Security Incident Response Orchestration Lead

Ghr · Chicago, United States of America +2 · Onsite

4 weeks ago

Security Incident Response Orchestration Lead

Ghr · Chicago, United States of America +2 · Onsite

4 weeks ago

Security Engineer, AWS Security Incident Response

Amazon

1 month ago

Security Engineer, AWS Security Incident Response

Amazon

1 month ago

Senior Manager, Global Security Incident Response

Melcoresorts · City of Dreams Manila, Philippines

1 month ago

Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA

GitLab · Remote, EMEA · Remote

1 month ago

Senior Staff Product Security Engineer | Product Security Incident Response Team (PSIRT)

ServiceNow · Kirkland, Washington, United States · Hybrid

1 month ago

Cloud Security Incident Response Senior Analyst

Cba · Eveleigh, NSW - 5-7 Central Ave, Australia +1

1 month ago

Cyber Security Incident Response Analyst (Panamá City, Panamá)

Signify · Panama City - Torre V · Onsite

1 month ago

Corporate Security Executive - Security Incident Response Executive

Ghr · Charlotte, United States of America +1 · Onsite

1 month ago

Corporate Security Executive - Security Incident Response Executive

Ghr · Charlotte, United States of America +1 · Onsite

1 month ago

Cyber Security Incident Response - Assistant Manager

LON3 London - 51 Lime Street · Madrid, Comunidad de Madrid, Spain, ES

1 month ago

IAM and Security Incident Response Working Student (m/f/d)

Find a job at GEA · Alcobendas : C/Cantabria, 2. Edificio Amura., Spain

2 months ago

Cyber Security Incident Response & Threat Intelligence Manager

Ncr · Chennai Embassy Tower Office, India

2 months ago