Program Manager, Security GRC

Stripe
United States
Workplace: RemoteFull timeFunction: Program & Project Management (PMO)Experience: 6+ yearsSkills: ["Program management","Stakeholder management","Communication","Relationship building","Adaptability"]

Serve as the primary interface between the Security organization and external auditors, regulators, and compliance stakeholders. Represent the Security team in audit engagements, explain how security controls operate, and ensure consistent compliance responses across a complex global regulatory landscape. Build and maintain a centralized repository of audit evidence, run security risk and control assessments against core frameworks, and partner with control owners and legal entities to track remediation and uphold an effective, lean GRC program.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Stripe
Stripe
1 month ago

Program Manager, Security GRC

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 11 hours agoStatus: Live

Job Summary

Serve as the primary interface between the Security organization and external auditors, regulators, and compliance stakeholders. Represent the Security team in audit engagements, explain how security controls operate, and ensure consistent compliance responses across a complex global regulatory landscape. Build and maintain a centralized repository of audit evidence, run security risk and control assessments against core frameworks, and partner with control owners and legal entities to track remediation and uphold an effective, lean GRC program.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Program & Project Management (PMO)
Seniority: Mid level

Key Responsibilities

  • •Represent the Security team as an information security subject matter expert during cross-functional audit engagements with auditors and regulators.
  • •Act as an internal liaison to ensure audits are managed effectively and consistently.
  • •Create and maintain a central repository of audit evidence artifacts for compliance (SOC 2, PCI DSS, SOX, and other standards).
  • •Perform security risk and control assessments against common frameworks to ensure compliance with policy and applicable regulations (e.g., ISO 2700x, NIST, COBIT).
  • •Support control owners and legal entities by guiding control design/redesign, tracking remediation, and contributing to GRC initiatives like policy writing and security awareness training.

Key Requirements

  • •Subject matter expertise in information security frameworks, practices, policies, standards, and procedures (e.g., NIST CSF, SOC 2, PCI DSS, ISO 27001/2, or equivalent).
  • •6+ years of experience in Security Governance, Risk, and Compliance or Technology Compliance with strong understanding of audit processes.
  • •Exposure to global regulatory requirements (e.g., DORA, FFIEC, EBA, NYDFS) and experience integrating them into compliance programs.
  • •Experience conducting security audits and supporting compliance across complex, overlapping regulatory frameworks.
  • •Strong program management skills coordinating security assessments and managing multiple stakeholder engagements across time zones.
Experience:6+ years
Skills:Program managementStakeholder managementCommunicationRelationship buildingAdaptability
Languages:English
Tech Stack:SOC 2PCI DSSSOXISO 27001/2NIST CSFNISTCOBITISO 2700xDORAFFIECEBANYDFSInformation Security PolicySecurity controls

Company Brief

Stripe
Provides payment processing APIs and financial infrastructure for internet businesses. Powers online payments for millions of companies from startups to Fortune 500s.
Industry: Payments
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Scaleup
Valuation: Decacorn (USD 10B+)
Funding: Series E+
Headquarters: San Francisco, United States
Founded: 2010
Glassdoor
Glassdoor: 4.2
WebsiteLinkedInGlassdoor