Stripe9 дней назад
Program Manager, Security GRC
Зарплата не указана
Remote
Обязанности
- 01Act as an information security subject matter expert during cross-functional audit engagements, representing the Security team in walkthrough meetings with auditors and regulators
- 02Serve as the internal liaison (proxy) between and the Security organization to ensure audits are managed effectively and consistently
- 03Create and maintain a central repository of audit evidence artifacts required for compliance with SOC 2, PCI DSS, SOX, and other global regulatory standards
- 04Perform security risk and control assessments against common frameworks to ensure compliance with Stripe's Information Security Policy and Standards and applicable regulations (e.g., ISO 2700x, PCI DSS, SOX, NIST, COBIT)
- 05Support control owners with guidance on security control design and redesign to ensure continued compliance and effectiveness
- 06Facilitate security compliance support for Stripe's legal entities with regulatory obligations, and collaborate with cross-functional stakeholders to track and report on control remediation efforts
- 07Support broader GRC team program initiatives, including policy writing, security awareness training, and third-party security risk assessments
Требования
- 01Subject matter expert in information security frameworks, practices, policies, standards, and procedures (e.g., NIST CSF, SOC 2, PCI DSS, ISO 27001/2, or equivalent)
- 026+ years of experience in Security Governance, Risk, and Compliance or Technology Compliance roles with a strong understanding of audit processes
- 03Exposure to global regulatory requirements (e.g., DORA, FFIEC, EBA, NYDFS) and experience integrating them into compliance programs
- 04Experience conducting security audits and supporting compliance across complex, overlapping regulatory frameworks
- 05Strong program management skills with proficiency in coordinating security assessments and managing multiple stakeholder engagements across time zones
- 06Excellent communication skills, with the ability to build relationships at all levels and translate technical security concepts for auditors, regulators, and executive audiences