Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Stripe

Offensive Security Engineer

Stripe

. Conduct comprehensive penetration tests across web applications, APIs, cloud environments, mobile applications, and internal infrastructure .

Posted 9/25/2026full-timeRemote • United StatesMid-LevelSenior💰 $170,400 - $255,700 per yearWebsite

Tech Stack

Tools & technologies
AWSAzureCloudGoogle Cloud PlatformPythonGo

About the role

Key responsibilities & impact
  • Conduct comprehensive penetration tests across web applications, APIs, cloud environments, mobile applications, and internal infrastructure
  • Plan and execute red team engagements emulating cyber and criminal threat actors targeting financial services
  • Perform assumed-breach and objective-based assessments to test detection and response capabilities
  • Partner with detection engineering, threat intelligence, and incident response teams to validate controls and improve detection fidelity
  • Contribute adversary tradecraft insights to detection rules, threat hunting hypotheses, and incident response playbooks
  • Support incident investigations with offensive expertise, log analysis, and root cause analysis
  • Design, develop, and maintain custom offensive tools, scripts, and automation frameworks
  • Build internal platforms and workflows for scalable, repeatable offensive operations
  • Automate testing tasks, payload generation, and reporting workflows
  • Produce reports communicating technical findings, business risk, and remediation guidance
  • Act as a subject-matter expert and point of contact for offensive security initiatives
  • Lead projects end-to-end, mentor junior team members, and foster continuous learning
  • Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and with the security community

Requirements

What you’ll need
  • 5+ years of experience in offensive security, penetration testing, red teaming, or a related field
  • Strong programming skills in Python, Go, or similar languages, with demonstrated experience building tools, automation, or custom exploits
  • Deep knowledge of web application security, including OWASP Top 10, ASVS, and common vulnerability classes
  • Hands-on experience with AWS, Azure, or GCP, including cloud-native attack techniques and misconfigurations
  • Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks
  • Familiarity with MITRE ATT&CK and adversary TTPs for initial access, privilege escalation, lateral movement, and exfiltration
  • Excellent written and verbal communication skills, with the ability to translate complex technical findings into clear, risk-based recommendations
  • Ability to think like an adversary — creative, persistent, and able to holistically assess risk in complex environments

Benefits

Comp & perks
  • Equity participation in Stripe's growth
  • 401(k) plan with matching contributions from day one
  • Comprehensive medical, dental, and vision coverage
  • Wellness stipends
  • Annual budget for training, certifications, and conference attendance
  • Remote work from home within the United States
  • Office visits for team meetings, on-sites, and events