Program Manager, Security GRC

🔥 0 minutes ago

🇺🇸 United States – Remote

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Stripe

Stripe

1001 - 5000 employees

Founded 2010

💳 Fintech

🛍️ eCommerce

🤝 B2B

💰 Venture Round on 2021-05

Fintech • eCommerce • B2B

Stripe is a global payments processing platform that enables businesses to accept online and in-person payments. It offers a comprehensive suite of financial services, including payment processing, billing, and revenue management tools, aimed at businesses of all sizes, from startups to enterprises. By providing a developer-friendly API, Stripe allows businesses to streamline their payment operations and embed financial services directly into their applications, facilitating both B2B and B2C transactions.

📋 Description

• Act as an information security subject matter expert during cross-functional audit engagements, representing the Security team in walkthrough meetings with auditors and regulators • Serve as the internal liaison (proxy) between and the Security organization to ensure audits are managed effectively and consistently • Create and maintain a central repository of audit evidence artifacts required for compliance with SOC 2, PCI DSS, SOX, and other global regulatory standards • Perform security risk and control assessments against common frameworks to ensure compliance with Stripe's Information Security Policy and Standards and applicable regulations (e.g., ISO 2700x, PCI DSS, SOX, NIST, COBIT) • Support control owners with guidance on security control design and redesign to ensure continued compliance and effectiveness • Facilitate security compliance support for Stripe's legal entities with regulatory obligations, and collaborate with cross-functional stakeholders to track and report on control remediation efforts • Support broader GRC team program initiatives, including policy writing, security awareness training, and third-party security risk assessments

🎯 Requirements

• Subject matter expert in information security frameworks, practices, policies, standards, and procedures (e.g., NIST CSF, SOC 2, PCI DSS, ISO 27001/2, or equivalent) • 6+ years of experience in Security Governance, Risk, and Compliance or Technology Compliance roles with a strong understanding of audit processes • Exposure to global regulatory requirements (e.g., DORA, FFIEC, EBA, NYDFS) and experience integrating them into compliance programs • Experience conducting security audits and supporting compliance across complex, overlapping regulatory frameworks • Strong program management skills with proficiency in coordinating security assessments and managing multiple stakeholder engagements across time zones • Excellent communication skills, with the ability to build relationships at all levels and translate technical security concepts for auditors, regulators, and executive audiences.

🏖️ Benefits

• Health insurance • Retirement plans • Paid time off • Flexible work arrangements • Professional development

Apply Now

Similar Jobs

🔥 5 hours ago

Foresite Cybersecurity

51 - 200

🔒 Cybersecurity

☁️ SaaS

🤝 B2B

Security Engineer specializing in Google Security Operations at Foresite. Contributing to a collaborative team environment and guiding clients in using Google security offerings.

🔥 10 hours ago

Applied High Voltage, LLC

11 - 50

⚡ Energy

🤝 B2B

Cybersecurity Program Lead responsible for building and maturing a cybersecurity program at Signal Energy. Translating cybersecurity strategy into actionable security practices while collaborating with diverse teams.

🔥 10 hours ago

Manager of IT Security overseeing security teams and initiatives at Lakeshore. Leading security strategy, risk management, and vulnerability response in a remote role.

🔥 13 hours ago

Venn Strategies

11 - 50

🏛️ Government

⚕️ Healthcare Insurance

Product Manager for Venn developing products for developers as buyers not just end users. Leading strategy, market discovery, and metrics for the developer security market.

🔥 13 hours ago

Carilion Clinic

10,000+ employees

🤝 Non-profit

👥 B2C

Workday Security Developer optimizing security model across Workday ERP Suite. Partnering with HR, Finance, and Compliance teams for secure access and system enhancements.