Security Engineer - Threat Detection
Core
Design, build, and maintain high-fidelity detections for malicious activity across Stripe's infrastructure, applications, and cloud environments using detection-as-code practices.
Role type
Senior IC security engineer (threat detection & hunting)
Builds
Detection logic, automation workflows, and tooling for threat detection and response
Domain
Cybersecurity, Threat Intelligence, Cloud Security
Required skills
detection engineering, threat hunting, adversary tradecraft analysis, malware analysis, reverse engineering, SIEM development, network/endpoint detection, telemetry analysis, detection query languages (SPL, KQL, EQL, YARA-L, SQL), Python programming
Preferred skills
fintech security experience, purple team operations, big data log analysis (Databricks, PySpark), AI/LLM-assisted development, agentic automation, detection validation tools (Atomic Red Team, ATT&CK Evaluations)
Technologies
Splunk, Chronicle, Elastic, CrowdStrike NG-SIEM, Panther, Microsoft Sentinel, AWS, GCP, Azure, Windows, Linux, macOS
Responsibilities
Design and tune detections across modern SIEM platforms covering full attack lifecycle TTPs; Conduct hypothesis-driven threat hunts to identify malicious activity and validate controls; Perform malware analysis and reverse engineering to extract indicators; Build network-based and endpoint-based detections across multiple OS platforms; Partner with Threat Intelligence to operationalize intel reports; Collaborate with IR and offensive security teams to refine detections; Build data pipelines and automation for detection-as-code; Map detection coverage to MITRE ATT&CK; Lead projects and mentor teammates
Seniority
Senior, hands-on IC with mentorship responsibilities