# Program Manager, Security GRC

**Company**: Stripe
**Location**: Remote
**Work arrangement**: remote
**Experience**: senior
**Job type**: full-time
**Category**: IT
**Industry**: Finance

**Apply**: https://job-boards.greenhouse.io/stripe/jobs/8078131?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_7ef733dc-03b

## Description

## Job Description

We're looking for a Security GRC Program Manager with deep expertise in security compliance to serve as the primary interface between Stripe's Security organization and external auditors, regulators, and compliance stakeholders.

### Responsibilities

- Act as an information security subject matter expert during cross-functional audit engagements, representing the Security team in walkthrough meetings with auditors and regulators

- Serve as the internal liaison (proxy) between and the Security organization to ensure audits are managed effectively and consistently

- Create and maintain a central repository of audit evidence artifacts required for compliance with SOC 2, PCI DSS, SOX, and other global regulatory standards

- Perform security risk and control assessments against common frameworks to ensure compliance with Stripe's Information Security Policy and Standards and applicable regulations (e.g., ISO 2700x, PCI DSS, SOX, NIST, COBIT)

- Support control owners with guidance on security control design and redesign to ensure continued compliance and effectiveness

- Facilitate security compliance support for Stripe's legal entities with regulatory obligations, and collaborate with cross-functional stakeholders to track and report on control remediation efforts

- Support broader GRC team program initiatives, including policy writing, security awareness training, and third-party security risk assessments

### Requirements

- Subject matter expert in information security frameworks, practices, policies, standards, and procedures (e.g., NIST CSF, SOC 2, PCI DSS, ISO 27001/2, or equivalent)

- 6+ years of experience in Security Governance, Risk, and Compliance or Technology Compliance roles with a strong understanding of audit processes

- Exposure to global regulatory requirements (e.g., DORA, FFIEC, EBA, NYDFS) and experience integrating them into compliance programs

- Experience conducting security audits and supporting compliance across complex, overlapping regulatory frameworks

- Strong program management skills with proficiency in coordinating security assessments and managing multiple stakeholder engagements across time zones

- Excellent communication skills, with the ability to build relationships at all levels and translate technical security concepts for auditors, regulators, and executive audiences

## Skills

### Required
- information security frameworks
- security compliance
- audit processes
- global regulatory requirements
- program management
- communication skills

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/stripe/jobs/8078131?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
