Incident Response Manager - Abuse Operations
Stripe
Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
6,001 open operations roles across 636 companies are on ApplySarthi right now, most of them in Bengaluru (206), Hyderabad (144), Mumbai (126).
- Business Operations AssociateBjak
- Business Operations Werkstudent (m/w/d)Aampere
- Head of Delivery OperationsKraken
- Head of Legal OperationsSitecore
- Praktikant Operations & Office Management (m/w/d)CKM Group
What operations roles keep asking for: Supply chain (15%), Excel (14%) — counted across their open postings here.
Databricks jobs · Python jobs · SQL jobs · Spark jobs
Stripe has 702 open roles listed here.
- Head of Sales, Indiabengaluru
- Legal Operations Team Leadbengaluru
- Partner Solutions Engineer, Ecosystem
- Offensive Security Engineer
- Account Executive, Product - Local Payment Methods
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for operations roles keep coming back to Supply chain, Excel. Practise those questions before you sit with Stripe.
Questions you are likely to be asked
- Why do you want to join Stripe?
- What is your experience with Databricks? Tell me one thing you learned the hard way.
- How do you handle a delay that affects a customer?
- How do you plan when demand is hard to predict?
- Tell me about a time you had to coordinate many teams at once.
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Incident Response Manager - Abuse Operations at Stripe interview free →Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
Abuse Operations is the front-line incident response and remediation function handling active product abuse and fraud impacting Stripe and its merchants. This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active attacks, gathers requirements for operational tooling, and leads incidents. The team works directly with impacted merchants to resolve incidents and policy abuse rapidly. Operating primarily across Eastern, Pacific and Western European time zones, these team members regularly coordinate with global stakeholders across the world.
What you’ll do
In this role, you will play a critical part in safeguarding our financial ecosystem by investigating high-risk accounts, identifying complex fraud patterns, performing post-incident analyses, and driving cross-functional improvements to scale fraud detection. Building on these core operational duties, you will leverage your fraud, abuse, or product trust experience to improve incident response capabilities across Stripe by managing the entire fraud and abuse incident response process, developing response plans, leading workstreams, and serving as incident commander to ensure timely resolution. Furthermore, you will conduct gamedays to pressure-test response processes, drive proactive improvements, and help automate response workflows using agentic approaches ensuring we neutralize threats with speed and precision while continuously elevating Stripe's fraud and abuse incident response function.
Responsibilities
- Lead fraud and abuse incident response end-to-end as Incident Response Manager (IRM), coordinating workstreams, investigating high risk activity and accounts, and making actionable mitigation recommendations under pressure.
- Investigate, mitigate, and remediate urgent fraud incidents (e.g., ATO, card testing), utilizing FT3-mapped (Fraud Taxonomy 3.0) detection and signals enrichment to reduce uncertainty and accelerate response.
- As part of incidents, analyze high-risk accounts to identify fraudulent merchants, card testing, account takeovers, and other fraud vectors, classifying them using FT3 to standardize threat intelligence.
- Develop, document, and execute incident response strategies, runbooks, and capabilities to continuously improve fraud and abuse detection and prevention.
- Partner cross-functionally with security, data science, legal, and policy teams to build agentic response solutions, refine KPIs, and deliver clear incident reporting.
- Mentor teammates, lead key incident response engineering projects, and elevate quality standards across the team.
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 10+ years of experience leading security or fraud incident response;
- B.S./M.S. in Computer Science or equivalent experience.
- Expert knowledge of Python and SQL, and familiarity with other programming languages
- Existing experience with log analysis (e.g. first or third party applications, system / data access, event logs), network security, digital forensics, and incident response investigations
- Proven ability to build automated response workflows, leverage threat intelligence, and make risk mitigation recommendations.
- Strong written and verbal communication skills with a track record of driving cross-functional alignment with minimal oversight.
Preferred qualifications
- Broad expertise across fraud and abuse mitigation, risk management, product trust, and threat intelligence in a complex platform environment.
- An adversarial mindset, understanding the goals, behaviors, and TTPs of threat actors.
- Experience with engineering, data processing and analysis tools (e.g. Databricks, Trino, etc.)
- Familiarity with common open-source frameworks for big data processing and/or data science (PySpark, Pandas, Sci-kit Learn, etc.)
- Experience with tactical threat intelligence and/or hunting for sophisticated threat actors in an enterprise environment
- Ability to proactively challenge the status quo by leveraging data and taking a user-centric approach to address complex product integrity challenges.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- Account Executive, Enterprise (Grower) Stripe
- Account Executive, Enterprise (Grower) Stripe
- Account Executive, Existing Business (Central Eastern Europe)Stripe
- Account Executive, Hunter (Central Eastern Europe)Stripe
- Account Executive, Product Sales - Stablecoin IssuingStripe
- Accounts Receivable ManagerStripe · bengaluru
- AEO and GEO Marketing ManagerStripe
- ARG Engineering ManagerStripe
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on greenhouse · posted 2026-09-03. ApplySarthi collects openings and links to application pages; the role is advertised by Stripe, not by us.