Jobs › Companies › Stripe › Security GRC Program Manager, Third Party Risk

Sobre este puesto de Security GRC Program Manager, Third Party Risk en Stripe

Stripe · Híbrido · US - Hybrid

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team.

The Security Governance, Risk, and Compliance (SGRC) team helps Stripe make informed security decisions, understand its risk and control posture, and represent its security program to internal and external stakeholders. The team also manages security risk arising from Stripe’s relationships with third parties by assessing their security controls, identifying and mitigating risk, and supporting informed onboarding and risk-acceptance decisions. Our work helps Stripe move quickly while maintaining clear and consistent security expectations.

What you'll do

  • Independently manage a portfolio of Third Party Security Risk Assessments (TPSRAs) for new engagements, renewals / reassessments, and material changes in relationship scope.
  • Review security questionnaires, independent assurance reports, certifications, penetration-test results, and other evidence to evaluate third-party control effectiveness.
  • Identify security gaps, determine proportionate remediation requirements, and clearly communicate findings to Stripe DRIs and cross-functional partners.
  • Apply Stripe’s third-party security standards consistently, documenting assessment results, decisions, and supporting evidence in Zip, Aravo, and other program systems.
  • Escalate novel, complex, or high-risk findings and support Enhanced Due Diligence and risk-acceptance processes when a third party cannot meet Stripe’s security requirements.
  • Partner with Procurement, Legal, Privacy, Business Continuity, Security, and business stakeholders to resolve assessment issues and support timely third-party onboarding.
  • Provide practical guidance to Stripe teams on TPSRA requirements, timelines, and their responsibilities throughout the assessment process.
  • Track assessment volume, aging, service levels, remediation status, and other program-health indicators; use the data to identify trends and recommend improvements.
  • Identify gaps in program processes, documentation, or tooling and contribute to implementing improvements that increase consistency, scalability, and stakeholder experience.
  • Contribute to third-party security risk policies, standards, procedures, and guidance.

What You'll Need:

  • 4+ years of relevant experience in third-party security risk, security assessments, information security, or a related risk-management function.
  • Experience conducting end-to-end third-party security assessments, including reviewing security documentation, identifying control gaps, determining risk, and defining remediation requirements.
  • Working knowledge of common security and assurance frameworks, such as SOC 2, ISO 27001, PCI DSS, NIST, and CSA.
  • Sound judgment and analytical skills, including the ability to distinguish material security risks from lower-priority findings and recommend a proportionate response.
  • Ability to independently manage multiple assessments, priorities, and stakeholder relationships while meeting defined timelines.
  • Clear written and verbal communication skills, including the ability to explain technical security findings to non-security stakeholders.
  • Experience using operational data and reporting to identify trends, communicate program health, and improve processes.
  • A collaborative approach and experience working with cross-functional partners such as Procurement, Legal, Privacy, and business teams.

Nice to have:

  • Experience with third-party risk management platforms or procurement workflow tools such as Aravo, Zip, or similar systems.
  • Experience with Enhanced Due Diligence, security risk acceptance, or third-party incident response.
  • Experience improving or scaling a third-party risk assessment program
¿Listo para postularte en Stripe?
Postúlate en Stripe

Empleos similares

Odyssey
Program Support Manager
Odyssey
⚡ Postúlate pronto Remote, US · restringido por ubicación $60,000–$80,000
● Nuevo 👁 Visto ✓ Postulado hace 1m
Crusoe
Project Manager II, Power Distribution (Switchboard Program)
Crusoe
⚡ Postúlate pronto Tulsa, OK - US (2) Presencial $100,000–$110,000
● Nuevo 👁 Visto ✓ Postulado hace 8m
Backblaze External Website
Senior Technical Program Manager (Security)
Backblaze External Website
⚡ Postúlate pronto Remote - US · restringido por ubicación $130,000–$150,000
● Nuevo 👁 Visto ✓ Postulado hace 2h
Stripe
Privacy Operations Program Manager
Stripe
⚡ Postúlate pronto US Remote · restringido por ubicación
● Nuevo 👁 Visto ✓ Postulado hace 5h
QTS Data Centers
Development, Program Manager MEPR (Van Wert, OH)
QTS Data Centers
⚡ Postúlate pronto New Albany, OH Presencial
● Nuevo 👁 Visto ✓ Postulado hace 9h
CACI
Deputy Program Manager
CACI
⚡ Postúlate pronto Jessup, MD, US Presencial $94,400–$198,200
● Nuevo 👁 Visto ✓ Postulado hace 11h
Twilio
Program Manager, Carrier Operations & Governance
Twilio
⚡ Postúlate pronto Remote - US · restringido por ubicación
● Nuevo 👁 Visto ✓ Postulado hace 11h
OpenAI
Vendor Security Technical Program Manager
OpenAI
⚡ Postúlate pronto US - Remote · restringido por ubicación $231,300–$256,500
● Nuevo 👁 Visto ✓ Postulado hace 15h
Pinterest
Staff Technical Program Manager, Security
Pinterest
⚡ Postúlate pronto San Francisco, CA, US; Remote,... · restringido por ubicación $145,747–$300,067
● Nuevo 👁 Visto ✓ Postulado hace 18h

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Stripe

Ver todos los empleos en Stripe →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis