Offensive Security Engineer

Stripe

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$179,000–$268,400 / yr
Posted
6 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $179k
This role $224k
$116k most similar roles pay here $285k

This role pays more than 85% of similar roles. Most pay $149,206–$208,800 — the shaded band above. At the midpoint, this role pays about $224k versus about $179k for comparable roles.

Based on 240 similar postings.

Employer

About Stripe

Stripe is a financial infrastructure platform for internet businesses, providing payment processing, billing, fraud prevention, and banking-as-a-service APIs to businesses of all sizes globally. Industry: Payments Infrastructure & Financial Technology

Stripe currently has 77 open roles on FindRole.

Listed pay typically runs $206,086–$305,400 across 77 roles with salary data.

Most-posted roles

View all roles at Stripe

At a glance

TL;DR · Offensive Security Engineer

As an Offensive Security Engineer on the Proactive Threat team, you will function as both a hacker and an engineer to identify vulnerabilities across systems, applications, networks, and cloud infrastructure. You will perform hands-on penetration testing, lead red team engagements simulating real-world adversary tactics, and collaborate with defensive teams to validate detection capabilities. Your daily work involves building custom tools, automation frameworks, and internal platforms to scale offensive operations. You will conduct assessments across web applications, APIs, mobile apps, and cloud environments including AWS, GCP, and Azure. Required skills include proficiency in Python or Go, deep knowledge of OWASP Top 10, and experience with tools like Burp Suite, Cobalt Strike, Mythic, Sliver, and BloodHound. This role addresses the critical challenge of securing financial infrastructure against cyber and criminal threat actors targeting sensitive services.

What you'll do

  • Conduct comprehensive penetration tests across web applications, APIs, cloud environments, and internal infrastructure.
  • Execute red team engagements that emulate the tactics and techniques of real-world threat actors.
  • Perform assumed-breach assessments to validate detection and response capabilities with defensive teams.
  • Design, develop, and maintain custom offensive tools and automation frameworks to scale testing operations.
  • Provide offensive expertise and log analysis during incident investigations and root cause analyses.
  • Translate technical findings into actionable reports regarding business risk and remediation for various stakeholders.
  • Act as a subject-matter expert for security initiatives and provide guidance on adversary tradecraft.

What we're looking for

  • 5+ years of experience in offensive security, penetration testing, red teaming, or a related field.
  • Strong programming skills in Python, Go, or similar languages to build tools, automation, or custom exploits.
  • Deep knowledge of web application security, including OWASP Top 10 and common vulnerability classes.
  • Hands-on experience with cloud platforms (AWS, Azure, or GCP) and cloud-native attack techniques.
  • Proficiency with offensive tooling such as Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound, or similar frameworks.
  • Familiarity with adversary tradecraft and frameworks like MITRE ATT&CK.
  • Excellent written and verbal communication skills to translate technical findings into risk-based recommendations.
  • Experience in fintech, vulnerability research, purple team operations, or relevant certifications (preferred).

More like this

Similar roles

Senior Offensive Security Engineer

Robinhood

Bellevue, WA +3 16 days ago $187,000–$220,000
Penetration Testing Python Go JavaScript AWS GCP Kubernetes Docker Linux MacOS DNS TCP/IP IDS/IPS Packet Capture Network Analysis EDR JIRA GitHub
6+ yrs exp Hybrid

Senior Offensive Security Engineer, Vulnerability Operations

Nvidia

Remote (Austin, TX) +1 30 days ago
LLM Python Red Teaming Penetration Testing Kubernetes Exploit Development Vulnerability Research SAST DAST Fuzzing GitOps OpenShift prompt-injection defense Multi-agent Orchestration Offensive Security
10+ yrs exp Remote

Security Engineer

Stripe

Remote 22 days ago $173,000–$259,600
Python Go Java SQL API Rate-limiting Regression Testing Databricks Trino PySpark Threat Modeling MITRE ATT&CK Application Security Data Processing
3+ yrs exp Remote

Offensive Security Lead

SoFi

San Francisco, CA +5 29 days ago $172,800–$297,000
Penetration Testing Red Teaming Adversary Emulation AWS GCP Azure MITRE ATT&CK C2 Tooling Application Security Vulnerability Management purple-team Offensive Security
8+ yrs exp

Senior Red Team Operator

Booz Allen Hamilton

Chantilly, VA 37 days ago
Red Teaming Purple Teaming Active Directory Python Bash C/C++ C# Rust Go PowerShell Java Nessus Metasploit Burp Suite Pro Cobalt Strike Mythic Azure M365 Terraform x86 Reverse Engineering JTAG UART OWASP ATT&CK

Lead Penetration Test Engineer

S&P Global

Boston, MA +11 22 days ago $135,000–$200,000
Penetration Testing Vulnerability Management DAST SAST SCA CI/CD Burp Suite Nessus Metasploit Nmap OWASP Top 10 MITRE ATT&CK Python Go Bash PowerShell JavaScript AWS Azure GCP Java
8+ yrs exp Hybrid