Enterprise Risk Management (ERM) Program & Automation Lead, MALPB
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI
API @ 4
Change Management
Communication @ 9
Compliance
Data Pipelines
Data Science @ 6
FinTech @ 7
LLM @ 4
Machine Learning
Payments @ 4
Prompt Engineering @ 4
Python @ 4
SQL @ 4
ServiceNow @ 7
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Who We Are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Stripe’s mission is to increase the GDP of the internet.
About the Team
Stripe MALPB operates in a highly complex, fast-moving regulatory environment. The Risk and Compliance team is responsible for ensuring that expansion is grounded in a robust governance framework that matches the speed of Stripe’s technology.
Having established foundational enterprise risk management policies, taxonomy, and risk registers, the team is entering the integration phase. The team is building an AI-native approach to risk management, embedding governance frameworks into daily business operations through automated data pipelines, machine learning, and LLM orchestration.
Responsibilities
As the sole dedicated ERM Lead for Stripe MALPB, you will own the enterprise risk program end to end. This is a hybrid role for a technically fluent risk architect.
Approximately one-third of the role will focus on ERM integration and execution, while approximately two-thirds will focus on AI and control automation design.
ERM Framework Integration and Execution
- Drive the cross-functional implementation and adoption of the established ERM framework across all Stripe MALPB business lines and operational functions.
- Execute annual and semi-annual Risk and Control Self-Assessment (RCSA) cycles, providing independent second-line-of-defense challenge to first-line-of-defense risk ratings and control effectiveness.
- Maintain the Master Control Library, Central Risk Register, and universal Risk Taxonomy, ensuring version control, change management, and alignment with emerging threats.
- Aggregate, analyze, and validate Key Risk Indicators (KRIs) against Board-approved Risk Appetite thresholds.
- Trigger formal remediation and Management Action Plans upon risk appetite breaches.
- Synthesize quantitative risk metrics and qualitative horizon scanning into quarterly Enterprise Risk Scorecards for presentation to the Management Risk Committee and Board of Directors.
AI and Control Automation Design
- Design, write, and deploy automated data extraction pipelines using SQL and APIs to systematically sample and retrieve control verification data from core systems.
- Build and implement AI/LLM agents to perform semantic analysis on operational logs, policy documents, and compliance records, automatically flagging anomalies or control deficiencies.
- Partner with technical teams to optimize and configure GRC infrastructure, implement automated self-attestation workflows, and remove system bottlenecks.
- Transition from passive, point-in-time testing to a real-time, automated dashboard environment that dynamically monitors key operational and regulatory controls.
Requirements
Minimum Requirements
- 8+ years of experience in enterprise risk management, operational risk, or risk advisory within a regulated financial institution, FinTech, or Big Four technology-risk consultancy.
- Proven experience rolling out and integrating risk programs, including RCSAs, KRIs, and control libraries, into active, fast-paced operational business units.
- Hands-on experience writing Python and SQL to query databases, manipulate data, and interface with standard web and REST APIs.
- Experience using modern LLM APIs, prompt engineering, or low-code/no-code automated workflow engines to analyze unstructured text or automate routine data tasks.
- Exceptional communication skills, with experience challenging senior business leaders and translating complex risk data into concise, Board-level narratives.
- Bachelor’s degree in Computer Science, Data Science, Finance, Business, or a related quantitative field.
Preferred Qualifications
- Experience working in a heavily regulated FinTech environment, digital bank, or complex global payments processor.
- Deep knowledge of GRC software architecture, such as ServiceNow and Archer, and experience scaling system configurations.
- Familiarity with international banking risk standards and regulatory expectations, including COSO, ISO 31000, and OCC Heightened Standards.