Software Engineer, Vulnerability Management
WFA Digital Insight
Stripe’s Vulnerability Management team tackles the problem of surfacing security flaws across a massive, constantly evolving payment platform. As a Software Engineer on this squad you’ll be building data‑heavy services and lightweight agents that automatically discover, triage, and prioritize vulnerabilities, then work hand‑in‑hand with product engineers to get fixes out fast. What sets this role apart is the blend of deep security expertise and full‑stack development – you’ll not only write detection logic but also own the pipelines that feed risk data back to the organization. Expect daily collaboration with engineers from many product groups, and a mandate to raise the bar on Stripe’s overall risk posture. Candidates should be comfortable with both security tooling and writing clean, maintainable code that scales.
Job Description
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
In this role, you would join Stripe's Vulnerability Management team, whose mission is to "Surface vulnerabilities at scale across Stripe." Our vision is to create a culture of continuous excellence in managing vulnerabilities. We want to enhance customer trust by giving users context about threats and vulnerabilities affecting Stripe's systems. We aim to be a key partner in Stripe's risk management by providing visibility into vulnerabilities across Stripe's products and services.
What you’ll do
As a Software Engineer focused on Vulnerability Management at Stripe, you will use your software engineering expertise to find and prioritize vulnerabilities in our systems. Working closely with engineers across the company, you will drive the timely remediation of discovered vulnerabilities, playing a key role in Stripe's overall security and risk strategy.
In addition, you will continuously improve Stripe's security defenses by enhancing our vulnerability management processes and selecting effective scanning tools to uncover weaknesses.
Your core responsibilities as a Vulnerability Management Software Engineer will involve building data- and agent-backed systems to surface vulnerabilities across Stripe. In addition, you will coordinate fixes to prevent exploits that could impact Stripe or our users and serve as an advisor on security risks. All of this requires collaborating cross-functionally to advocate for practices that strengthen the safety of Stripe's systems and data.
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Responsibilities
- Identify vulnerabilities using automated tools and triage them appropriately
- Collaborate with other teams to drive remediation of vulnerabilities
- Contribute to our overall security and risk management strategy
- Continuously improve our security posture, processes, and tools
Minimum requirements
- 2+ years of industry software engineering experience (does not include internships or co-ops)
- Software engineering experience within the security domain
- Empathy, strong communication skills and a deep respect for the power of collaboration
- Excellent problem-solving skills and attention to detail
- High standards for code quality and a constructive attitude to help others raise the bar
Preferred qualifications
- An ability to think creatively and holistically about reducing risk in a complex environment
- Familiarity with automated vulnerability identification tools and triage
- Delivery of successful projects using agents to automate human review processes
By joining our team, you will have an unprecedented opportunity to put the global economy within everyone’s reach, securely.
How to Stand Out
- Highlight any experience you have building or integrating vulnerability scanning tools; concrete examples win attention.
- Prepare a short demo or code sample that shows how you automated a security‑related workflow.
- Emphasize clear communication skills in your resume and cover letter; the role requires translating risk into actionable steps.
- Expect interview questions that probe both coding ability and security reasoning—practice explaining your thought process.
- Research Stripe’s public security blog and recent engineering posts to demonstrate genuine interest.
- When discussing past projects, focus on impact: how your work reduced remediation time or improved detection coverage.
- Be ready to discuss how you stay current with security trends without citing vague statistics; mention specific resources or communities you follow.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.