Security GRC Program Manager, Third Party Risk
Stripe · US - Hybrid · 8614 Office of the CISO & Partnership · listed October 6, 2026
The shape of it
Seniority
Manager
Experience asked
4+ years
Where
Hybrid
Requirements listed
8
Length
580 words
In the posting’s own words
The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team.
What it asks for · 8
- 4+ years of relevant experience in third-party security risk, security assessments, information security, or a related risk-management function.
- Experience conducting end-to-end third-party security assessments, including reviewing security documentation, identifying control gaps, determining risk, and defining remediation requirements.
- Working knowledge of common security and assurance frameworks, such as SOC 2, ISO 27001, PCI DSS, NIST, and CSA.
- Sound judgment and analytical skills, including the ability to distinguish material security risks from lower-priority findings and recommend a proportionate response.
- Ability to independently manage multiple assessments, priorities, and stakeholder relationships while meeting defined timelines.
- Clear written and verbal communication skills, including the ability to explain technical security findings to non-security stakeholders.
- Experience using operational data and reporting to identify trends, communicate program health, and improve processes.
- A collaborative approach and experience working with cross-functional partners such as Procurement, Legal, Privacy, and business teams.
Also a plus
- Experience with third-party risk management platforms or procurement workflow tools such as Aravo, Zip, or similar systems.
- Experience with Enhanced Due Diligence, security risk acceptance, or third-party incident response.
- Experience improving or scaling a third-party risk assessment program
What the job covers
- Independently manage a portfolio of Third Party Security Risk Assessments (TPSRAs) for new engagements, renewals / reassessments, and material changes in relationship scope.
- Review security questionnaires, independent assurance reports, certifications, penetration-test results, and other evidence to evaluate third-party control effectiveness.
- Identify security gaps, determine proportionate remediation requirements, and clearly communicate findings to Stripe DRIs and cross-functional partners.
- Apply Stripe’s third-party security standards consistently, documenting assessment results, decisions, and supporting evidence in Zip, Aravo, and other program systems.
- Escalate novel, complex, or high-risk findings and support Enhanced Due Diligence and risk-acceptance processes when a third party cannot meet Stripe’s security requirements.
- Partner with Procurement, Legal, Privacy, Business Continuity, Security, and business stakeholders to resolve assessment issues and support timely third-party onboarding.
- Provide practical guidance to Stripe teams on TPSRA requirements, timelines, and their responsibilities throughout the assessment process.
- Track assessment volume, aging, service levels, remediation status, and other program-health indicators; use the data to identify trends and recommend improvements.
- Identify gaps in program processes, documentation, or tooling and contribute to implementing improvements that increase consistency, scalability, and stakeholder experience.
- Contribute to third-party security risk policies, standards, procedures, and guidance.
Tools and skills named
Security & compliance
- Security29×
- PCI2×
- Risk management
- SOC 2
Ways of working
- Cross-functional2×
- Technical writing2×
Words the posting leans on
- security27×
- risk12×
- assessment9×
- third-party9×
- experience8×
- program5×
- security risk5×
- stakeholders5×
- control4×
- findings4×
- identify4×
- requirements4×
- third-party security4×
- business3×
- decisions3×
- gaps3×
Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.
The posting, your resume, and the gaps between them. One click loads all three.