Stripe is a financial infrastructure platform used by millions of businesses to accept payments and grow revenue, with a mission to increase the GDP of the internet. Its Security team makes security a first-class consideration in everything it does. As a Security GRC Program Manager, you'll be the primary interface between Stripe's Security organization and external auditors, regulators and compliance stakeholders — representing the Security team in audit engagements and keeping compliance obligations consistent across a complex global regulatory landscape.
Responsibilities
- ▹Act as an information security subject matter expert during cross-functional audit engagements, representing the Security team in walkthrough meetings with auditors and regulators
- ▹Serve as the internal liaison between external entities and the Security organization to ensure audits are managed effectively and consistently
- ▹Create and maintain a central repository of audit evidence artifacts required for compliance with SOC 2, PCI DSS, SOX and other global regulatory standards
- ▹Perform security risk and control assessments against common frameworks (ISO 2700x, PCI DSS, SOX, NIST, COBIT) to ensure compliance with Stripe's Information Security Policy and Standards
- ▹Support control owners with guidance on security control design and redesign
- ▹Facilitate security compliance support for Stripe's legal entities with regulatory obligations, and collaborate cross-functionally to track and report on control remediation
- ▹Support broader GRC program initiatives, including policy writing, security awareness training and third-party security risk assessments
Requirements
- ▹Subject matter expert in information security frameworks, practices, policies, standards and procedures (e.g. NIST CSF, SOC 2, PCI DSS, ISO 27001/2, or equivalent)
- ▹6+ years of experience in Security Governance, Risk and Compliance or Technology Compliance roles, with a strong understanding of audit processes
- ▹Exposure to global regulatory requirements (e.g. DORA, FFIEC, EBA, NYDFS) and experience integrating them into compliance programs
- ▹Experience conducting security audits and supporting compliance across complex, overlapping regulatory frameworks
- ▹Strong program management skills, coordinating security assessments and managing multiple stakeholder engagements across time zones
- ▹Excellent communication skills, able to build relationships at all levels and translate technical security concepts for auditors, regulators and executive audiences
Soft skills
About the company
Stripe is a financial infrastructure platform for businesses. Millions of companies — from the world's largest enterprises to the most ambitious startups — use Stripe to accept payments, grow their revenue and accelerate new business opportunities, with a mission to increase the GDP of the internet.
Similar jobs

Linux Malware Protection Engineer / Security Engineer (Linux)

Staff Software Engineer - Product Security

Sr. Staff Product Designer, Identity Security Platform & Systems
Security Automation Engineer

Security Automation Engineer

