Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Communication @ 3
Compliance @ 3
Due Diligence @ 3
Reporting @ 3
Security @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Stripe is a financial infrastructure platform for businesses. The Stripe Security team improves the security of Stripe and its users, with security serving as a first-class consideration across the company.
The Security Governance, Risk, and Compliance (SGRC) team helps Stripe make informed security decisions, understand its risk and control posture, represent its security program to internal and external stakeholders, and manage security risk arising from relationships with third parties.
Responsibilities
- Independently manage a portfolio of Third Party Security Risk Assessments (TPSRAs) for new engagements, renewals or reassessments, and material changes in relationship scope.
- Review security questionnaires, independent assurance reports, certifications, penetration-test results, and other evidence to evaluate third-party control effectiveness.
- Identify security gaps, determine proportionate remediation requirements, and communicate findings to Stripe DRIs and cross-functional partners.
- Apply Stripe's third-party security standards consistently, documenting assessment results, decisions, and supporting evidence in Zip, Aravo, and other program systems.
- Escalate novel, complex, or high-risk findings and support Enhanced Due Diligence and risk-acceptance processes when a third party cannot meet Stripe's security requirements.
- Partner with Procurement, Legal, Privacy, Business Continuity, Security, and business stakeholders to resolve assessment issues and support timely third-party onboarding.
- Provide practical guidance to Stripe teams on TPSRA requirements, timelines, and responsibilities throughout the assessment process.
- Track assessment volume, aging, service levels, remediation status, and other program-health indicators; use the data to identify trends and recommend improvements.
- Identify gaps in program processes, documentation, or tooling and contribute to improvements that increase consistency, scalability, and stakeholder experience.
- Contribute to third-party security risk policies, standards, procedures, and guidance.
Requirements
- 4+ years of relevant experience in third-party security risk, security assessments, information security, or a related risk-management function.
- Experience conducting end-to-end third-party security assessments, including reviewing security documentation, identifying control gaps, determining risk, and defining remediation requirements.
- Working knowledge of common security and assurance frameworks, including SOC 2, ISO 27001, PCI DSS, NIST, and CSA.
- Sound judgment and analytical skills, including the ability to distinguish material security risks from lower-priority findings and recommend a proportionate response.
- Ability to independently manage multiple assessments, priorities, and stakeholder relationships while meeting defined timelines.
- Clear written and verbal communication skills, including the ability to explain technical security findings to non-security stakeholders.
- Experience using operational data and reporting to identify trends, communicate program health, and improve processes.
- A collaborative approach and experience working with cross-functional partners such as Procurement, Legal, Privacy, and business teams.
Nice to Have
- Experience with third-party risk management platforms or procurement workflow tools such as Aravo, Zip, or similar systems.
- Experience with Enhanced Due Diligence, security risk acceptance, or third-party incident response.
- Experience improving or scaling a third-party risk assessment program.
More jobs at Stripe
Solutions Architect, SMB
Stripe · Chicago, United States
USD 156,700-235,100 per year
Product Manager, Ecosystem
Stripe · United States
USD 214,300-321,500 per year
Staff Engineer, Compute Foundation
Stripe · Melbourne, Australia
AUD 208,000-312,000 per year
Product Manager, Radar
Stripe · United States, Chicago, United States, New York City, United States, South San Francisco, United States, Seattle, United States
USD 178,600-268,000 per year
Staff Product Manager, Radar - Fraud and Abuse Prevention
Stripe · United States, Chicago, United States, New York City, United States, South San Francisco, United States, Seattle, United States
USD 178,600-268,000 per year
Similar jobs
Technical Program Manager, Data Center Infrastructure
Anthropic · San Francisco, United States, New York City, United States, Seattle, United States
USD 365,000-435,000 per year
Manager, Professional Services
Collibra · Washington, United States, United States
USD 128,000-160,000 per year
IT Support Engineer, Application Administrator
Anthropic · San Francisco, United States, New York City, United States
USD 230,000-265,000 per year
Senior Business Systems Analyst, Finance Systems (Assets & Lease Management)
Anthropic · San Francisco, United States, Seattle, United States
USD 205,000-270,000 per year
Solutions Architect - Finance
Nvidia · Santa Clara, United States
USD 152,000-230,000 per year
Resilience & Business Continuity Risk Lead - Chief Risk Office
Bloomberg · New York City, United States
USD 185,000-245,000 per year
Staff Workday Integration Engineer, Tech Foundations
Airbnb · United States
USD 180,000-225,000 per year
Senior Technical Program Manager
GitLab · United States, Canada
USD 203,200-345,600 per year