À propos de ce poste Enterprise Risk Management (ERM) Program & Automation Lead, MALPB chez Stripe
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
Stripe MALPB operates in a highly complex, fast-moving regulatory environment. The Risk and Compliance team is responsible for ensuring that our expansion is grounded in a bulletproof governance framework that matches the speed of our technology.
Having successfully established our foundational ERM policies, taxonomy, and risk registers, we are entering the integration phase. This team is building the future of "AI-Native" risk management—where governance frameworks are embedded into daily business operations through automated data pipelines, machine learning, and LLM orchestration.
What you’ll do
As the sole dedicated ERM Lead for Stripe MALPB, you will own the enterprise risk program end-to-end. This is a unique hybrid role designed for a technically fluent risk architect.
- Roughly 1/3rd of your time will be dedicated to ERM Integration and Execution: rolling out our mature risk framework to the First Line (1LoD), running the RCSA cycle, managing the control library, and synthesizing risk scorecards for executive and Board-level reporting.
- Roughly 2/3rds of your time will be dedicated to AI and Control Automation Design: acting as a hands-on developer to build and scale LLM tools, automated evidence-collection scripts, and real-time monitoring workflows that eliminate manual compliance overhead.
Responsibilities
ERM Framework Integration & Execution (1/3rd)
- Enterprise Rollout: Drive the cross-functional implementation and adoption of the established ERM framework across all Stripe MALPB business lines and operational functions.
- RCSA Facilitation: Execute the annual and semi-annual Risk and Control Self-Assessment (RCSA) cycles, providing robust independent 2LoD challenge to 1LoD risk ratings and control effectiveness.
- Control Library & Governance: Maintain the Master Control Library, Central Risk Register, and universal Risk Taxonomy, ensuring strict version control, change management, and alignment with emerging threats.
- Appetite & KRI Monitoring: Aggregate, analyze, and validate Key Risk Indicators (KRIs) against Board-approved Risk Appetite thresholds; trigger formal remediation and Management Action Plans (MAPs) upon breach.
- Board & Executive Reporting: Synthesize quantitative risk metrics and qualitative horizon scanning into the quarterly Enterprise Risk Scorecard for presentation to the Management Risk Committee and the Board of Directors.
AI & Control Automation Design (2/3rd)
- Automated Evidence Collection: Design, write, and deploy automated data extraction pipelines (via SQL and APIs) to systematically sample and pull control verification data from core systems.
- LLM Orchestration: Build and implement AI/LLM agents to perform semantic analysis on operational logs, policy documents, and compliance records, automatically flagging anomalies or control deficiencies.
- GRC System Engineering: Partner with technical teams to optimize and configure our GRC infrastructure, implementing automated self-attestation workflows and removing system bottlenecks.
- Continuous Monitoring: Transition the bank away from passive, point-in-time testing toward a real-time, automated dashboard environment that monitors key operational and regulatory controls dynamically.
Who you are
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement. We are looking for a rare breed of professional: someone with the executive presence to stand up a banking governance program, combined with the hands-on engineering capabilities to automate it themselves.
Minimum requirements
- Experience: 8+ years of experience in enterprise risk management, operational risk, or risk advisory within a regulated financial institution, FinTech, or Big 4 tech-risk consultancy.
- Execution Track Record: Proven experience successfully rolling out and integrating risk programs (RCSAs, KRIs, Control Libraries) into active, fast-paced operational business units.
- Technical Proficiency: Hands-on experience writing Python and SQL to query databases, manipulate data, and interface with standard web/REST APIs.
- AI/Automation Familiarity: Experience using modern LLM APIs, prompt engineering, or low-code/no-code automated workflow engines to analyze unstructured text or automate routine data tasks.
- Communication & Presence: Exceptional communication skills with a track record of effectively challenging senior business leaders and translating complex risk data into concise, Board-level narratives.
- Education: A Bachelor's degree in Computer Science, Data Science, Finance, Business, or a related quantitative field.
Preferred qualifications
- Prior experience working in a heavily regulated FinTech environment, digital bank, or complex global payments processor.
- Deep knowledge of GRC software architecture (e.g., ServiceNow, Archer) and how to scale system configurations.
- Familiarity with international banking risk standards and regulatory expectations (e.g., COSO, ISO 31000, OCC Heightened Standards).