Chat with Stripe sales 8 sales reps available We're here to discuss your business needs. Chat now with sales Program Manager, Security GRC Stripe logo Jobs Our opportunity Life at Stripe
Benefits University See open roles Open mobile navigation Jobs Our opportunity Life at Stripe
Benefits University See open roles Close mobile navigation Roles at Stripe Role details Program Manager, Security GRC
Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About
the team The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team. The Security Governance, Risk, and Compliance (SGRC) team at Stripe provides security governance, risk management, and compliance capabilities to allow Stripe to make strategic security decisions, measure our risk and control posture, and represent Stripe Security to internal and external entities. The successful operation of our organization accelerates Stripe by optimizing the communication and expectations of our security program. What you’ll do We're looking for a Security GRC Program Manager with deep expertise in security compliance to serve as the primary interface between Stripe's Security organization and external auditors, regulators, and compliance stakeholders. In this role, you'll represent the Security team in audit engagements, articulate how Stripe's security controls are designed and how they operate, and ensure that compliance obligations across a complex global regulatory landscape are met with consistency and rigor. In this role, you will act as a proxy between external entities like regulators and auditors, and our internal security teams, ensuring consistency in compliance responses and helping maintain a lean and effective compliance program. The ideal candidate is adaptable and finds structure in an evolving and maturing organization.
Responsibilities Act as an information security subject matter expert during cross-functional audit engagements, representing the Security team in walkthrough meetings with auditors and regulators Serve as the internal liaison (proxy) between and the Security organization to ensure audits are managed effectively and consistently Create and maintain a central repository of audit evidence artifacts required for compliance with SOC 2, PCI DSS, SOX, and other global regulatory standards Perform security risk and control assessments against common frameworks to ensure compliance with Stripe's Information Security Policy and Standards and applicable regulations (e.g., ISO 2700x, PCI DSS, SOX, NIST, COBIT) Support control owners with guidance on security control design and redesign to ensure continued compliance and effectiveness Facilitate security compliance support for Stripe's legal entities with regulatory obligations, and collaborate with cross-functional stakeholders to track and report on control remediation efforts Support broader GRC team program initiatives, including policy writing, security awareness training, and third-party security risk assessments
Who you are We're looking for someone who meets the minimum
requirements to be considered for
the role. If you meet these
requirements, you are encouraged to apply. The preferred
qualifications are a
bonus, not a requirement. Minimum
requirements Subject matter expert in information security frameworks, practices, policies, standards, and procedures (e.g., NIST CSF, SOC 2, PCI DSS, ISO 27001/2, or equivalent) 6+ years of experience in Security Governance, Risk, and Compliance or Technology Compliance roles with a strong understanding of audit processes Exposure to global regulatory
requirements (e.g., DORA, FFIEC, EBA, NYDFS) and experience integrating them into compliance programs Experience conducting security audits and supporting compliance across complex, overlapping regulatory frameworks Strong program management skills with proficiency in coordinating security assessments and managing multiple stakeholder engagements across time zones Excellent communication skills, with the ability to build relationships at all levels and translate technical security concepts for auditors, regulators, and executive audiences Working remotely at Stripe A remote location is defined as being 35 miles (56 kilometers) or more from one of our offices. While you would be welcome to come into the office for team/business meetings, on-sites, meet-ups, and events, our expectation is you would regularly work from home rather than a Stripe office. Stripe does not cover the cost of relocating to a remote location. We encourage you to apply for roles that match the location where you currently live or plan to live. Pay and
benefits The annual US base salary range for this role is $161,300 - $241,900. For sales roles, the range provided is
the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for
the role. This salary range may be inclusive of several career levels at Stripe and will be narrowed during the interview process based on a number of factors, including the candidate’s experience,
qualifications, and location. Applicants interested in this role and who are not located in the US may request the annual salary range for their location during the interview process. Additional
benefits for this role may include: equity, company
bonus or sales commissions/bonuses; 401(k) plan; medical, dental, and vision
benefits; and wellness stipends. Remote locations Remote in United States Team Security Job type Full time Apply for this role Please find our California applicant personal information notice here . The application window will remain open for 100 days after the Job Post is published. However, this opportunity will remain open based on the needs of the business, which may cause the application window to close before or after the 100-day mark. We look forward to hearing from you At Stripe, we're looking for people with passion, grit, and integrity. You're encouraged to apply even if your experience doesn't precisely match the job description. Your skills and passion will stand out—and set you apart—especially if your career has taken some extraordinary twists and turns. At Stripe, we welcome diverse perspectives and people who think rigorously and aren't afraid to challenge assumptions. Join us. Apply Now Stripe logo United States (English) Australia English Austria Deutsch English Belgium Nederlands Français Deutsch English Brazil Português English Bulgaria English Canada English Français China 简体中文 English Croatia English Italiano Cyprus English Czech Republic English Denmark English Estonia English Finland English Svenska France Français English Germany Deutsch English Gibraltar English Greece English Hong Kong English 简体中文 Hungary English India English Ireland English Italy Italiano English Japan 日本語 English Latvia English Liechtenstein Deutsch English Lithuania English Luxembourg Français Deutsch English Malaysia English 简体中文 Malta English Mexico Español English Netherlands Nederlands English New Zealand English Norway English Poland English Portugal Português English Romania English Singapore English 简体中文 Slovakia English Slovenia English Italiano Spain Español English Sweden Svenska English Switzerland Deutsch Français Italiano English Thailand ไทย English United Arab Emirates English United Kingdom English United States English Español 简体中文 Products & pricing Pricing Atlas Authorization Boost Billing Capital Checkout Climate Connect Crypto Data Pipeline Elements Financial Connections Identity Invoicing Issuing Link Managed Payments Payment links Payments Payouts Radar Revenue Recognition Stripe Sigma Tax Terminal Treasury Solutions Enterprises Startups Agentic commerce Crypto Ecommerce Embedded finance Finance automation Global businesses In-app payments Marketplaces Platforms SaaS AI companies Creator economy Gaming Hospitality, travel, and leisure Insurance Media and entertainment Nonprofits Professional services Public sector Retail Integrations & custom solutions Stripe App Marketplace Stripe Partner ecosystem Professional services Developers Documentation API reference API status API changelog Libraries and SDKs Stripe Projects Developer blog Resources Guides Customer stories Blog Community Sessions annual conference Privacy & terms Prohibited & restricted businesses Licenses Sitemap Cookie settings Your privacy choices Coverage transparency More resources Company Product roadmap Jobs Newsroom Stripe Press Contact sales Support Get support Managed support plans CA residents: +1 888 926 2289 Sign in © 2026 Stripe, LLC
Launched out of Y Combinator’s 2009 Summer batch, Stripe is a global technology company that builds economic infrastructure for the internet. Businesses of every size—from new startups to public companies—use our software to accept payments and manage their businesses online Stripe is a proud partner of YC companies—from Airbnb (S09) to Defog (W23)—to help them grow their businesses and increase the GDP of the internet.
Location
Remote
Experience
6+ years
Total raised
$6.0B
Last stage
Growth
Investors
No applications, no recruiter spam. Just the intro.
A few questions to make sure this role is the right shape for you. Two minutes.
I write the intro, send it to the founder, and handle the back-and-forth.
If they’re a yes, I book the chat. You show up — that’s the whole job-hunt.