Investigator

Stripe
United States
Remote

Who this role is best for

Aimed at mid-to-senior level professionals with incident response experience who excel in fraud detection and cross-functional collaboration.

Best fit for

  • Candidates with incident response experience in security or fraud domains and a background in data analysis or modeling
    — “3+ years of experience conducting incident response in security, product abuse or trust domains
  • Individuals with strong technical skills in Python and SQL, and a history of working with log analysis and network security tools
    — “Expert knowledge of Python and SQL, and familiarity with other programming languages
  • Professionals who can lead root cause analyses and drive systemic improvements based on threat intelligence frameworks
    — “Lead incident root cause analyses to identify gaps in current systems and strategies

Things to consider

  • The role demands working across multiple global time zones and coordinating with international stakeholders
    — “Operating primarily across Eastern, Pacific and Western European time zones
  • A strong commitment to detail and communication is necessary to mitigate risks and convey findings clearly
    — “Ability to communicate results clearly and focus on impact

How to stand out

  • Emphasize experience with fraud taxonomy frameworks and threat intelligence in your resume and interview responses
    — “classifying them using FT3 (Fraud Taxonomy 3.0) to standardize threat intelligence
  • Highlight your ability to lead and mentor others, especially in incident response or fraud detection contexts
    — “Collaborate effectively with teammates, leading projects, mentoring others
  • Demonstrate your skills in agentic solutions and automation for fraud response during interviews
    — “Work cross-functionally with security, fraud and data science teams to build agentic solutions
  • Showcase your ability to analyze large data sets and build models with a behavioral approach to fraud detection
    — “3+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to fraud detection
Pace · Fast PacedCollaboration · HighAutonomy · MediumDecision Impact · Company

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • Investigated and mitigated urgent fraud incidents
  • Led incident root cause analyses
  • Streamlined incident response capabilities
Typical background
3+ years of experience conducting incident responseExperience analyzing large data sets for fraud detection

Skills & requirements

Required

Incident ResponseFraud DetectionRoot Cause AnalysisAgentic SolutionsCross-functional CollaborationLegal And Policy Assessment

Preferred

Fraud ModelingBehavioral Approach To Fraud Detection

Stack & domain

Incident ResponseFraud DetectionFT3Data ProcessingAnalysis ToolsDatabricksTrinoPysparkPandasSci-kit LearnCollaborationMentoringQuality StandardsFraud PreventionCybersecurity

About the role

Original posting from Stripe

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

About the team

Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team  works directly with impacted merchants to resolve technical incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.

What you’ll do

You'll play a critical role in safeguarding our financial ecosystem by investigating high-risk accounts and identifying complex patterns of fraud during incidents. You will lead incident response for product abuse and fraud events, conducting deep-dive analyses to identify root causes. By collaborating cross-functionally, you will drive improvements that enhance our fraud detection and prevention strategies at scale. Your expertise will be essential in automating response processes through agentic approaches, allowing us to safeguard merchants and neutralize threats with speed and precision.

Responsibilities

Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped detection and signals enrichment to reduce uncertainty and accelerate response.

As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 (Fraud Taxonomy 3.0) to standardize threat intelligence.

Lead incident root cause analyses to identify gaps in current systems and strategies, leveraging the FT3 framework, data-driven model to drive enhancements and process improvements for emerging fraud risks.

Streamline incident response capabilities, ensuring the tooling and processes are clear, accurate and efficient

Work cross-functionally with security, fraud and data science teams to build agentic solutions for responding to abuse incidents at scale

Effectively communicate cross-functionally with legal and policy teams to assess and mitigate risks, while demonstrating strong problem-solving under pressure.

Collaborate effectively with teammates, leading projects, mentoring others, and developing and championing quality standards within the team

Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

3+ years of experience conducting incident response in security, product abuse or trust domains

3+ years experience analyzing large data sets to solve problems and/or building models with a behavioral approach to fraud detection

B.S. or M.S. Computer Science or related field, or equivalent experience

Expert knowledge of Python and SQL, and familiarity with other programming languages

Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations

Ability to communicate results clearly and focus on impact

Ability to think creatively and holistically about reducing risk in a complex environment

Preferred qualifications

An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.

Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)

Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)

Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment

Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges

Source: Stripe careers

Similar roles