Jobs › Hybrid › Security GRC Program Manager, Third Party Risk
Security GRC Program Manager, Third Party Risk
Stripe is hiring for the job of Security GRC Program Manager, Third Party Risk, Hybrid (On-site). This is a Risk job in the governance, risk, and compliance field. Review the full details below and apply directly with Stripe.
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies, from the world s largest enterprises to the most ambitious startups, use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone s reach while doing the most important work of your career.
About the team
The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team.
The Security Governance, Risk, and Compliance (SGRC) team helps Stripe make informed security decisions, understand its risk and control posture, and represent its security program to internal and external stakeholders. The team also manages security risk arising from Stripe’s relationships with third parties by assessing their security controls, identifying and mitigating risk, and supporting informed onboarding and risk-acceptance decisions. Our work helps Stripe move quickly while maintaining clear and consistent security expectations.
What you ll do
Independently manage a portfolio of Third Party Security Risk Assessments (TPSRAs) for new engagements, renewals / reassessments, and material changes in relationship scope.
Review security questionnaires, independent assurance reports, certifications, penetration-test results, and other evidence to evaluate third-party control effectiveness.
Identify security gaps, determine proportionate remediation requirements, and clearly communicate findings to Stripe DRIs and cross-functional partners.
Apply Stripe’s third-party security standards consistently, documenting assessment results, decisions, and supporting evidence in Zip, Aravo, and other program systems.
Escalate novel, complex, or high-risk findings and support Enhanced Due Diligence and risk-acceptance processes when a third party cannot meet Stripe’s security requirements.
Partner with Procurement, Legal, Privacy, Business Continuity, Security, and business stakeholders to resolve assessment issues and support timely third-party onboarding.
Provide practical guidance to Stripe teams on TPSRA requirements, timelines, and their responsibilities throughout the assessment process.
Track assessment volume, aging, service levels, remediation status, and other program-health indicators; use the data to identify trends and recommend improvements.
Identify gaps in program processes, documentation, or tooling and contribute to implementing improvements that increase consistency, scalability, and stakeholder experience.
Contribute to third-party security risk policies, standards, procedures, and guidance.
What You ll Need:
4+ years of relevant experience in third-party security risk, security assessments, information security, or a related risk-management function.
Experience conducting end-to-end third-party security assessments, including reviewing security documentation, identifying control gaps, determining risk, and defining remediation requirements.
Working knowledge of common security and assurance frameworks, such as SOC 2, ISO 27001, PCI DSS, NIST, and CSA.
Sound judgment and analytical skills, including the ability to distinguish material security risks from lower-priority findings and recommend a proportionate response.
Ability to independently manage multiple assessments, priorities, and stakeholder relationships while meeting defined timelines.
Clear written and verbal communication skills, including the ability to explain technical security findings to non-security stakeholders.
Experience using operational data and reporting to identify trends, communicate program health, and improve processes.
A collaborative approach and experience working with cross-functional partners such as Procurement, Legal, Privacy, and business teams.
Nice to have:
Experience with third-party risk management platforms or procurement workflow tools such as Aravo, Zip, or similar systems.
Experience with Enhanced Due Diligence, security risk acceptance, or third-party incident response.
Experience improving or scaling a third-party risk assessment program
Location and market context
This job is based in Hybrid on-site. Local candidates benefit from being close to Stripe's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About risk management jobs
Risk jobs own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Jobs like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.
How to position yourself for this risk management job
Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how Stripe would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Chief Transformation Officer – Governance, Risk & Cybersecurity, APAC · ServiceNow · Sydney, au
- Customer Support Manager - Risk · Mercury · San Francisco, CA, New York · Remote
- Risk Operations Manager · Stripe · Bangalore
- Divisional Risk and Control Senior Analyst, AVP · Deutsche Bank · Mumbai, Nirlon Knowledge Park
- Financial Institution Specialist (Risk Management) · Federal Deposit Insurance Corporation · Multiple Locations
- RESILIENCE AND RISK REDUCTION COORDINATOR · Army National Guard Units · Latham, New York
- Chief, Institution Risk Branch, CM-1101-00 (Merit Promotion) · Federal Deposit Insurance Corporation · Multiple Locations
- Chief, Institution Risk Branch, CM-1101-00 (Public) · Federal Deposit Insurance Corporation · Multiple Locations
More jobs at Stripe
- Operations Associate, Sanctions · Stripe · Bengaluru
- U.S. Banking Regulatory Compliance Lead · Stripe · Remote
- Risk Operations Analyst - SSO · Stripe · Remote
- Security GRC Analyst/Program Manager, Bridge · Stripe · New York
- User Risk Strategist · Stripe · New York, NY
- Third Party Risk Analyst · Stripe · Bengaluru
More GRC jobs in Hybrid
- Internal Audit Manager (F/H) · Younited · Paris
- FINANCIAL SYSTEMS ANALYST (CYBER) · Defense Finance and Accounting Service · Multiple Locations
- Medical Records Technician (Coder) Auditor · Veterans Health Administration · Anywhere in the . job · Remote
- Lead Compliance Specialist · Comenity Bank · 5 Locations
- Data Centre Services - Global Service Operations & Governance Lead · Deutsche Bank · London 10 Upper Bank Street
- Deputy Head of Compliance and MLRO · Capital Rx · Dubai
Hiring for Risk?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Security GRC Program Manager, Third Party Risk in Hybrid open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.