Level

StripePosted 3w ago

Incident Response Manager - Abuse Operations

Incident Response Manager - Abuse Operations at Stripe scores 50 out of 100 on AI centrality, which makes it AI Level 2 of 4 (Uses AI) on this board. The level measures how much of the work is AI, not seniority.

Remote (Dublin)mid

AI in this role

Lead fraud and abuse incident response workstreams, utilizing agentic automation approaches to investigate and neutralize threats.

databricks
incident-responsefraud-detectionabuse-operationsthreat-analysis

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.

What you’ll do

In this role, you will play a critical part in safeguarding our financial ecosystem by investigating high-risk accounts, identifying complex fraud patterns, performing post-incident analyses, and driving cross-functional improvements to scale fraud detection. Building on these core operational duties, you will leverage your fraud, abuse, or product trust experience to improve incident response capabilities across Stripe by managing the entire fraud and abuse incident response process, developing response plans, leading workstreams, and serving as incident commander to ensure timely resolution. Furthermore, you will conduct gamedays to pressure-test response processes, drive proactive improvements, and help automate response workflows using agentic approaches ensuring we neutralize threats with speed and precision while continuously elevating Stripe's fraud and abuse incident response function.

 

Responsibilities

  • Lead fraud and abuse incident response end-to-end as Incident Response Manager (IRM), coordinating workstreams, investigating high risk activity and accounts, and making actionable mitigation recommendations under pressure.
  • Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped  (Fraud Taxonomy 3.0) detection and signals enrichment to reduce uncertainty and accelerate response.
  • As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.
  • Develop, document, and execute incident response strategies, runbooks, and capabilities to continuously improve fraud and abuse detection and prevention.
  • Partner cross-functionally with security, data science, legal, and policy teams to build agentic response solutions, refine KPIs, and deliver clear incident reporting.
  • Mentor teammates, lead key incident response engineering projects, and elevate quality standards across the team.

Who you are

We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • 10+ years of experience leading security or fraud incident response; 
  • B.S./M.S. in Computer Science or equivalent experience.
  • Expert knowledge of Python and SQL, and familiarity with other programming languages
  • Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
  • Proven ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
  • Strong written and verbal communication skills with a track record of driving cross-functional alignment with minimal oversight.

Preferred qualifications

  • Broad expertise across fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
  • An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
  • Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
  • Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
  • Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
  • Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

Incident ResponseFraud DetectionAbuse OperationsThreat AnalysisDatabricks

Questions you could be asked

  1. Tell me about a project where incident response was part of your work. What did you do?
  2. Tell me about a project where fraud detection was part of your work. What did you do?
  3. Tell me about a project where abuse operations was part of your work. What did you do?
  4. Tell me about a project where threat analysis was part of your work. What did you do?
  5. Walk me through how you've used Databricks in your day-to-day work.

Adapt your resume

  • List these exact terms on your resume: Incident Response, Fraud Detection, Abuse Operations, Threat Analysis, and Databricks. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
  • Put the AI tool in a bullet point about what you did, not just in a skills list — this role treats it as a required part of the job.

Want your resume actually rewritten for this job?

The free preview above is everything we have today. A full resume rewrite is not live yet and has no price set. Join the waitlist and we will email you if we open it.

Similar roles

Operations roles rated AI Level 2 at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Stripe

Related searches

Same AI level