Stripe
Program Manager, Security GRC
World Remote Middle
Description
Program Manager, Security GRC
What you’ll do
- We're looking for a Security GRC Program Manager with deep expertise in security compliance to serve as the primary interface between Stripe's Security organization and external auditors, regulators, and compliance stakeholders.
- In this role, you'll represent the Security team in audit engagements, articulate how Stripe's security controls are designed and how they operate, and ensure that compliance obligations across a complex global regulatory landscape are met with consistency and rigor.
- In this role, you will act as a proxy between external entities like regulators and auditors, and our internal security teams, ensuring consistency in compliance responses and helping maintain a lean and effective compliance program.
- The ideal candidate is adaptable and finds structure in an evolving and maturing organization.
Responsibilities
- Act as an information security subject matter expert during cross-functional audit engagements, representing the Security team in walkthrough meetings with auditors and regulators
- Serve as the internal liaison (proxy) between and the Security organization to ensure audits are managed effectively and consistently
- Create and maintain a central repository of audit evidence artifacts required for compliance with SOC 2, PCI DSS, SOX, and other global regulatory standards
- Perform security risk and control assessments against common frameworks to ensure compliance with Stripe's Information Security Policy and Standards and applicable regulations (e.g., ISO 2700x, PCI DSS, SOX, NIST, COBIT)
- Support control owners with guidance on security control design and redesign to ensure continued compliance and effectiveness
- Facilitate security compliance support for Stripe's legal entities with regulatory obligations, and collaborate with cross-functional stakeholders to track and report on control remediation efforts
- Support broader GRC team program initiatives, including policy writing, security awareness training, and third-party security risk assessments
Who you are
- Minimum requirements
- Subject matter expert in information security frameworks, practices, policies, standards, and procedures (e.g., NIST CSF, SOC 2, PCI DSS, ISO 27001/2, or equivalent)
- 6+ years of experience in Security Governance, Risk, and Compliance or Technology Compliance roles with a strong understanding of audit processes
- Exposure to global regulatory requirements (e.g., DORA, FFIEC, EBA, NYDFS) and experience integrating them into compliance programs
- Experience conducting security audits and supporting compliance across complex, overlapping regulatory frameworks
- Strong program management skills with proficiency in coordinating security assessments and managing multiple stakeholder engagements across time zones
- Excellent communication skills, with the ability to build relationships at all levels and translate technical security concepts for auditors, regulators, and executive audiences