Program Manager, Security Risk Management
StripeAbout the role
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone’s reach while doing the most important work of your career.
About the team
The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team.
The goal of the Security Ecosystem team at Stripe is to provide information security advice and operational structure to the Security organization and its customers, both internal and external to Stripe. The team is responsible for various functional areas, including Security Governance, Risk, Compliance, and Third Party Security Risk Assessment (TPSRA).
What you’ll do
We’re looking for an experienced Security Risk Management individual located in US Eastern Time Zone who has a diverse background in GRC and can help Stripe mature their security risk management and governance programs. The right candidate will be adaptable and can set direction and find organization in an evolving and maturing organization.
Responsibilities:
- Define and maintain a Security Risk & Common Control Taxonomy to support operational risk management activities
- Primary support for EMEA security risk and control assessments, risk reporting, and local representation (e.g., risk forums).
- Define, implement, and maintain a Security Risk Management Framework
- Contribute to a governance oversight function that reports on risk treatment (e.g., remediation, risk acceptance) decisions and helps leaders stay accountable
- Execute on annual and periodic security risk assessments
- Contribute to Stripe global legal entity risk management requirements for Security
- Operationalize strategic security programs by making them efficient, scalable, and reliable
- Function as an information security subject matter expert and lead cross-functional teams in making sound risk-based decisions
- Operate autonomously leading large-scale efforts across multiple teams and functions, with stakeholders in different disciplines across time zones
- Develop, define, and report on the team’s program health and success metrics to provide insights to management to help drive strategic direction
Who you are
We’re looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- Must be located in US Eastern Time zone
- At least 10 yrs of experience in a Security GRC or Risk Management role
- Strong background in information security operations, risks and controls identification and assessment
- Subject matter expert in information security frameworks, practices, policies, standards and procedures (e.g. NIST CSF, ISO 27001/2 or equivalent)
- Experience designing and implementing programs for Security Governance and Risk Management within fast moving organizations
- You have experience driving mid to large-scale projects and programs from start to finish within highly complex operating environments
- You have strong written and verbal communication skills, building strong relationships at all levels of the organization from executives to project teams
- Knowledge of how to use data to influence program strategy and tell compelling stories about organizational effectiveness and impact
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s