WriterRemote · New York City, NY$183k-$240k
StripePosted 3mo ago
Incident Response Manager - Security at Stripe scores 0 out of 100 on AI centrality, which makes it AI Level 1 of 4 (Little AI) on this board. The level measures how much of the work is AI, not seniority.
AI in this role
Lead security incident response activities and coordinate threat analysis and remediation processes at Stripe.
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
The Security Incident Response team is responsible for triaging and assessing the severity of incoming security alerts, responding with initial containment measures and escalating as needed to incident responders for further investigation and resolution. They analyze a variety of data sources to identify potential threats, collect requirements for operational enhancements to detection and response systems, and generally scale security processes. From external attacks to insider threats, our goal is to respond with speed and precision, remediate, and support the incident postmortem process. The team is distributed globally and regularly coordinates with stakeholders in North America, Europe, and Asia.
What you’ll do
You will leverage your security incident response experience to improve capabilities at Stripe. You will manage and coordinate the entire incident response process, developing and implementing incident response plans, conducting risk assessments, establishing procedures, leading workstreams, and ensuring timely and effective resolution. You will also act as incident commander, collaborating with various internal stakeholders, performing post-incident analysis and reporting, and making continuous improvements to Stripe’s security engineering and incident response function.
Responsibilities
- Lead and coordinate security incident response activities and workstreams as the incident response manager (IRM)
- Analyze and investigate a broad range of threats or activities occurring on client devices, maintaining a high level of confidentiality and documenting incident details accordingly
- Make decisions and recommendations based on the results of incident analysis and communicate the appropriate context to stakeholders, including insights to help identify, prevent, detect, and respond to anomalous or potentially malicious activity
- Develop, document, and implement strategies, runbooks, capabilities, and techniques for incident response
- Work cross-functionally with security engineering and data science teams to build solutions for analyzing security events data at scale and protecting Stripe networks, systems, and data from threats
- Strengthen KPIs and metrics for measuring response effectiveness and provide clear and consistent reporting to internal stakeholders
- Continuously improve security processes and response capabilities by building relationships with key stakeholders and collaborating with engineers and analysts
- Mentor and develop other teammates, championing quality standards within the team
Who you are
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 5+ years experience in leading Security Incident Response
- B.S. or M.S. Computer Science or related field, or equivalent experience
- Working knowledge of Python and SQL, and familiarity with other programming languages
- Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
- Hands-on experience in analyzing and responding to security events, such as conducting log analysis, developing queries and analytics, troubleshooting security issues, and correlating complex data sets.
- Proficiency with developing and using novel analytical methods to automate response processes
- Excellent written and verbal communication skills, proactive in informing stakeholders, and ability to operate with little oversight.
- Ability to identify trends, insights, and relationships between internal and external data and intelligence sources to make risk mitigation recommendations.
Preferred qualifications
- Broad knowledge and experience across the information security domain, including familiarity with endpoint, email, network, identity management, cloud security, vulnerability management, incident response, and threat intelligence.
- Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
- Familiarity with network observability, security software, or data engineering solutions (Chronicle, osquery, LogScale, Splunk, etc.)
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a project where incident response was part of your work. What did you do?
- Tell me about a project where risk assessment was part of your work. What did you do?
- Tell me about a project where security operations was part of your work. What did you do?
- Tell me about a project where threat analysis was part of your work. What did you do?
- Walk me through how you've used Databricks in your day-to-day work.
Adapt your resume
- List these exact terms on your resume: Incident Response, Risk Assessment, Security Operations, Threat Analysis, and Databricks. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want your resume actually rewritten for this job?
The free preview above is everything we have today. A full resume rewrite is not live yet and has no price set. Join the waitlist and we will email you if we open it.
Similar roles
Security roles rated AI Level 1 at other companies.
Thought MachinePortugal, Lisbon€75k-€95k
DatadogRemote · Sydney, Australia
Anduril IndustriesWashington, District of Columbia, United States$166k-$220k
AmazonUS, TX, Austin$177k-$239k
WorkOSRemote · United States & Canada$175k-$275k







