131K–197K USD / year

Security GRC Program Manager, Third Party Risk

OtherRemote — United States
Published on 2026-10-06
These details were extracted automatically from the original listing. They may not be complete or fully up to date — it's worth checking the original job post.

About this role

The Security GRC Program Manager will manage third-party security risk assessments for Stripe, ensuring that security frameworks and standards are applied effectively. This role involves communicating findings to stakeholders and collaborating with various teams to mitigate risks associated with third-party engagements.

About the company

Stripe provides payment infrastructure and financial tools that help businesses accept payments, manage subscriptions, and move money globally. It serves startups through large enterprises with APIs for online and in-person commerce.

The team

Security Governance, Risk, and Compliance (SGRC) team

Stack

Security frameworksSOC 2ISO 27001PCI DSSNISTCSA

What you'll do

  • Manage a portfolio of Third Party Security Risk Assessments (TPSRAs)
  • Review and evaluate third-party security documentation
  • Identify security gaps and remediation requirements
  • Communicate findings to stakeholders
  • Partner with cross-functional teams for onboarding
  • Track and report assessment metrics
  • Implement process improvements
  • Contribute to security risk policies and standards

What we're looking for

  • 4+ years of experience in third-party security risk or related fields
  • Experience conducting third-party security assessments
  • Knowledge of security frameworks like SOC 2 and ISO 27001
  • Strong analytical and communication skills
  • Ability to manage multiple assessments and priorities

Nice to have

  • Experience with risk management platforms like Aravo or Zip
  • Knowledge of Enhanced Due Diligence procedures
  • Experience scaling risk assessment programs
View original job post