Engineering Manager, Abuse Control Engineering

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.

About the team

Abuse Control Engineering (ACE) is Stripe’s rapid-response technical defense and control incubator. When urgent abuse vectors emerge, ACE bridges the gap using real attacker telemetry to prototype, test, and deploy software safeguards before vulnerabilities can be exploited at scale. We partner closely with Fraud, Risk and Product Engineering to run rigorous experiments, balancing aggressive risk mitigation against legitimate user conversion. Operating as both a strike team and an incubator, ACE builds automated regression suites in partnership with Abuse Research to permanently block threat recurrence and seamlessly transfers mature controls to long-term product owners across Stripe.

What you’ll do

As the Engineering Manager for Abuse Control Engineering, you will lead a team responsible for closing urgent, cross-product defense gaps and incubating controls until they are ready for long-term ownership. You will be accountable for the team’s technical direction, people leadership, hiring, coaching, and cross-functional execution.

You will help the team turn attacker evidence into clear technical priorities, guide the design and evaluation of safeguards, and ensure that decisions account for both risk reduction and the experience of legitimate users. You will also establish disciplined incubation and handoff practices so that successful controls move to the appropriate product teams with clear ownership, documentation, criteria, and timelines.

Responsibilities

  • Set technical direction: Define and communicate the team’s technical strategy and priorities for identifying cross-product abuse gaps, incubating controls, and preventing the recurrence of mitigated threats.
  • Lead and develop the team: Hire, manage, coach, and support engineers; provide clear expectations and feedback; and create opportunities for engineers to expand their technical judgment, leadership, and impact.
  • Guide evidence-based decisions: Ensure that attacker evidence, product context, and measurable outcomes inform technical abuse requirements, control designs, and investment decisions.
  • Drive secure control design: Partner with Application Security and product engineering teams to develop safeguards that are resilient, appropriately scoped, and compatible with the systems in which they operate.
  • Oversee experimentation: Guide experiments that assess risk reduction and the effect of controls on legitimate user conversion, helping the team make informed tradeoffs and refine its approach.
  • Build durable defenses: Ensure the team develops regression tests and other mechanisms that can detect whether previously mitigated abuse patterns recur.
  • Manage control incubation: Establish clear success measures, operational expectations, documentation, destination owners, handoff criteria, and target dates for incubated controls.
  • Complete ownership handoffs: Hold the team and its partners accountable for transferring successful controls to the product teams that permanently own the relevant surfaces, except where a control is intentionally maintained as a durable capability serving multiple products.
  • Lead cross-functional execution: Align security, product, engineering, and other partners around priorities, tradeoffs, responsibilities, and delivery plans, including in situations that require urgent coordination.

Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • Experience managing an engineering team, including setting direction, prioritizing work, and being accountable for delivery and technical outcomes.
  • A relevant technical foundation in software engineering, security engineering, application security, anti-abuse engineering, or a closely related field, developed through professional experience, education, or an equivalent path.
  • Experience hiring, coaching, and developing engineers with different levels of experience, including providing actionable feedback and supporting career growth.
  • Experience leading cross-functional technical work involving teams with different goals, areas of expertise, or ownership boundaries.
  • Ability to evaluate technical designs, ask effective questions, and guide engineering decisions involving reliability, security, risk, and product tradeoffs.
  • Experience communicating technical strategy, priorities, risks, and decisions clearly to engineering teams and cross-functional stakeholders.
  • Ability to create clarity in ambiguous or urgent situations and translate broad risk problems into actionable plans, ownership, and measurable outcomes.

Preferred qualifications

  • Experience guiding experimentation or A/B testing, including evaluating control effectiveness and balancing risk reduction against effects on legitimate user conversion.
  • Knowledge of threat modeling, secure systems design, or modern application security practices.
  • Familiarity with API safeguards and abuse controls such as rate limits, authorization checks, input validation, step-up challenges, or related protective mechanisms.
  • Knowledge of financial-fraud patterns, attacker behavior, attack methods, or the infrastructure used to conduct abuse.
  • Experience using or overseeing work involving large-scale data platforms to analyze system activity, identify patterns, or measure control performance.
  • Experience incubating technical capabilities and transferring them to long-term owners through explicit success criteria, documentation, operational readiness, and target dates.
  • Experience leading a distributed team or coordinating execution across teams in multiple locations or time zones.

Hybrid work at Stripe

This role is available either in an office or a remote location (35+ miles or 56+ km from a Stripe office).

In-office expectations

Office-assigned Stripes spend at least 50% of the time in a given month in their local office or with users. This hits a balance between bringing people together for in-person collaboration and learning from each other, while supporting flexibility about how to do this in a way that makes sense for individuals and their teams.

Working remotely at Stripe

A remote location is defined as being 35 miles (56 kilometers) or more from one of our offices. While you would be welcome to come into the office for team/business meetings, on-sites, meet-ups, and events, our expectation is you would regularly work from home rather than a Stripe office. Stripe does not cover the cost of relocating to a remote location. We encourage you to apply for roles that match the location where you currently live or plan to live.

Pay and benefits

The annual US base salary range for this role is $236,000 - $354,000. For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role. This salary range may be inclusive of several career levels at Stripe and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location. Applicants interested in this role and who are not located in the US may request the annual salary range for their location during the interview process.

Additional benefits for this role may include: equity, company bonus or sales commissions/bonuses; 401(k) plan; medical, dental, and vision benefits; and wellness stipends.

We look forward to hearing from you.

At Stripe, we're looking for people with passion, grit, and integrity. You're encouraged to apply even if your experience doesn't precisely match the job description. Your skills and passion will stand out—and set you apart—especially if your career has taken some extraordinary twists and turns. At Stripe, we welcome diverse perspectives and people who think rigorously and aren't afraid to challenge assumptions. Join us.

Apply now

Please find our California applicant personal information notice here.

The application window will remain open for 100 days after the Job Post is published. However, this opportunity will remain open based on the needs of the business, which may cause the application window to close before or after the 100-day mark.