Stripe9 дней назад

Program Manager, Security GRC

Зарплата не указана
Remote

Обязанности

  • 01Act as an information security subject matter expert during cross-functional audit engagements, representing the Security team in walkthrough meetings with auditors and regulators
  • 02Serve as the internal liaison (proxy) between and the Security organization to ensure audits are managed effectively and consistently
  • 03Create and maintain a central repository of audit evidence artifacts required for compliance with SOC 2, PCI DSS, SOX, and other global regulatory standards
  • 04Perform security risk and control assessments against common frameworks to ensure compliance with Stripe's Information Security Policy and Standards and applicable regulations (e.g., ISO 2700x, PCI DSS, SOX, NIST, COBIT)
  • 05Support control owners with guidance on security control design and redesign to ensure continued compliance and effectiveness
  • 06Facilitate security compliance support for Stripe's legal entities with regulatory obligations, and collaborate with cross-functional stakeholders to track and report on control remediation efforts
  • 07Support broader GRC team program initiatives, including policy writing, security awareness training, and third-party security risk assessments

Требования

  • 01Subject matter expert in information security frameworks, practices, policies, standards, and procedures (e.g., NIST CSF, SOC 2, PCI DSS, ISO 27001/2, or equivalent)
  • 026+ years of experience in Security Governance, Risk, and Compliance or Technology Compliance roles with a strong understanding of audit processes
  • 03Exposure to global regulatory requirements (e.g., DORA, FFIEC, EBA, NYDFS) and experience integrating them into compliance programs
  • 04Experience conducting security audits and supporting compliance across complex, overlapping regulatory frameworks
  • 05Strong program management skills with proficiency in coordinating security assessments and managing multiple stakeholder engagements across time zones
  • 06Excellent communication skills, with the ability to build relationships at all levels and translate technical security concepts for auditors, regulators, and executive audiences
Program Manager, Security GRC · Rekru