# Program Manager, Security GRC

**Company:** [Stripe](https://hotfix.jobs/companies/stripe)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 6+ years
**Skills:** Nist Csf, SOC 2, Pci Dss, ISO 27001, Iso 27002, Sox, Nist, Cobit, Dora, Ffiec, Eba, Nydfs, Security Compliance, GRC, Audit Management
**Posted:** 2026-07-22

> Security GRC Program Manager serving as primary interface between Stripe's Security team and external auditors/regulators. Manage audits, maintain evidence repository, perform risk/control assessments across global frameworks, and support compliance initiatives.

## Job Description

## Responsibilities
- Act as an information security subject matter expert during cross-functional audit engagements, representing the Security team in walkthrough meetings with auditors and regulators.
- Serve as the internal liaison (proxy) between external entities and the Security organization to ensure audits are managed effectively and consistently.
- Create and maintain a central repository of audit evidence artifacts required for compliance with SOC 2, PCI DSS, SOX, and other global regulatory standards.
- Perform security risk and control assessments against common frameworks to ensure compliance with Stripe's Information Security Policy and Standards and applicable regulations (e.g., ISO 2700x, PCI DSS, SOX, NIST, COBIT).
- Support control owners with guidance on security control design and redesign to ensure continued compliance and effectiveness.
- Facilitate security compliance support for Stripe's legal entities with regulatory obligations, and collaborate with cross-functional stakeholders to track and report on control remediation efforts.
- Support broader GRC team program initiatives, including policy writing, security awareness training, and third-party security risk assessments.

## Minimum Requirements
- Subject matter expert in information security frameworks, practices, policies, standards, and procedures (e.g., NIST CSF, SOC 2, PCI DSS, ISO 27001/2, or equivalent).
- 6+ years of experience in Security Governance, Risk, and Compliance or Technology Compliance roles with a strong understanding of audit processes.
- Exposure to global regulatory requirements (e.g., DORA, FFIEC, EBA, NYDFS) and experience integrating them into compliance programs.
- Experience conducting security audits and supporting compliance across complex, overlapping regulatory frameworks.
- Strong program management skills with proficiency in coordinating security assessments and managing multiple stakeholder engagements across time zones.
- Excellent communication skills, with the ability to build relationships at all levels and translate technical security concepts for auditors, regulators, and executive audiences.

## Similar jobs

- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Security GRC Lead](https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1) - Mercor - San Francisco, CA - $350k – $425k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr
- [Senior Platform Security Engineer](https://hotfix.jobs/jobs/3ac667bf-62fa-4280-8ccb-2af3468d8579) - Discord - $196k – $245k/yr

**Apply:** https://hotfix.jobs/jobs/ebbb7ed4-3326-417b-a2e6-af74d7cc5cc9
**Canonical:** https://hotfix.jobs/jobs/ebbb7ed4-3326-417b-a2e6-af74d7cc5cc9