远程工作雷达

项目经理,安全GRC

Program Manager, Security GRC

开发工程全球可投
公司Stripe
薪资未公开
工作地点Remote
地域资格全球可投
时区要求无特别要求
用工类型未标注
发布时间2026-07-22
数据来源Greenhouse
前往企业招聘页投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

我们是谁

关于 Stripe

Stripe 是一家为 businesses 提供金融基础设施的平台。数百万家公司——从全球最大的企业到最具雄心的初创公司——使用 Stripe 来接受支付、增长收入并加速新的商业机会。我们的使命是提高互联网的 GDP,我们还有大量工作要做。这意味着你有机会在职业生涯中从事最重要的工作,让全球经济触手可及。

关于团队

Stripe 安全团队致力于提升 Stripe 及其用户的安全性。我们的用户将一些最敏感的信息交给我们,而我们在每项工作中都将安全作为首要考虑因素。安全问题不断演变,为安全团队创造了极为动态的工作环境。

Stripe 的安全治理、风险与合规(SGRC)团队为 Stripe 提供安全治理、风险管理与合规能力,使 Stripe 能够做出战略性的安全决策,评估我们的风险和控制状况,并向内部和外部实体展示 Stripe 安全状况。我们组织的高效运作通过优化安全计划的沟通和期望来加速 Stripe 的发展。

你将负责

我们正在寻找一位具备深厚安全合规经验的 Security GRC 项目经理,作为 Stripe 安全组织与外部审计师、监管机构和合规利益相关者之间的主要接口。在这个职位上,你将在审计活动中代表安全团队,阐述 Stripe 的安全控制是如何设计和运行的,并确保在全球复杂的监管环境中一致且严谨地满足合规义务。

在这个角色中,你将作为监管机构和审计师等外部实体与我们内部安全团队之间的代理,确保合规响应的一致性,并帮助维护一个精简而高效的合规计划。理想的候选人应具备适应性,并能在不断演进和成熟的组织中找到结构。

职责

  • 在跨职能审计活动中担任信息安全专家,代表安全团队与审计师和监管机构进行现场会议
  • 作为内部联络人(代理),与安全组织保持联系,确保审计工作得到有效且一致的管理
  • 创建
查看英文原文

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team.

The Security Governance, Risk, and Compliance (SGRC) team at Stripe provides security governance, risk management, and compliance capabilities to allow Stripe to make strategic security decisions, measure our risk and control posture, and represent Stripe Security to internal and external entities. The successful operation of our organization accelerates Stripe by optimizing the communication and expectations of our security program.

What you’ll do

We're looking for a Security GRC Program Manager with deep expertise in security compliance to serve as the primary interface between Stripe's Security organization and external auditors, regulators, and compliance stakeholders. In this role, you'll represent the Security team in audit engagements, articulate how Stripe's security controls are designed and how they operate, and ensure that compliance obligations across a complex global regulatory landscape are met with consistency and rigor.

In this role, you will act as a proxy between external entities like regulators and auditors, and our internal security teams, ensuring consistency in compliance responses and helping maintain a lean and effective compliance program. The ideal candidate is adaptable and finds structure in an evolving and maturing organization.

Responsibilities

  • Act as an information security subject matter expert during cross-functional audit engagements, representing the Security team in walkthrough meetings with auditors and regulators
  • Serve as the internal liaison (proxy) between  and the Security organization to ensure audits are managed effectively and consistently
  • Create and maintain a central repository of audit evidence artifacts required for compliance with SOC 2, PCI DSS, SOX, and other global regulatory standards
  • Perform security risk and control assessments against common frameworks to ensure compliance with Stripe's Information Security Policy and Standards and applicable regulations (e.g., ISO 2700x, PCI DSS, SOX, NIST, COBIT)
  • Support control owners with guidance on security control design and redesign to ensure continued compliance and effectiveness
  • Facilitate security compliance support for Stripe's legal entities with regulatory obligations, and collaborate with cross-functional stakeholders to track and report on control remediation efforts
  • Support broader GRC team program initiatives, including policy writing, security awareness training, and third-party security risk assessments

Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • Subject matter expert in information security frameworks, practices, policies, standards, and procedures (e.g., NIST CSF, SOC 2, PCI DSS, ISO 27001/2, or equivalent)
  • 6+ years of experience in Security Governance, Risk, and Compliance or Technology Compliance roles with a strong understanding of audit processes
  • Exposure to global regulatory requirements (e.g., DORA, FFIEC, EBA, NYDFS) and experience integrating them into compliance programs
  • Experience conducting security audits and supporting compliance across complex, overlapping regulatory frameworks
  • Strong program management skills with proficiency in coordinating security assessments and managing multiple stakeholder engagements across time zones
  • Excellent communication skills, with the ability to build relationships at all levels and translate technical security concepts for auditors, regulators, and executive audiences
本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

产品经理,移动端

StripeNew York City, Toronto, Chicago, or Remote6 天前
开发工程职能支持全球可投

竞争项目经理

StripeNYC, Seattle, SF, Remote11 天前
市场运营职能支持全球可投

← 返回全部职位