{"id":1954413,"url":"https://alion.io/job/stripe-security-grc-program-manager-third-party-risk","title":"Security GRC Program Manager, Third Party Risk","company":{"id":64,"name":"Stripe","domain":"stripe.com","url":"https://alion.io/company/stripe","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"B","score":76,"open_postings":114,"ghost_share":0.009,"stale_share":0.719,"repost_share":0.035,"time_to_fill_p50_days":63,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Management","role_family":"Management","seniority":"middle","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":112000,"max_usd":215000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":1330},"experience_years_min":4,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ISO 27001","optional":false},{"name":"PCI DSS","optional":false},{"name":"SOC 2","optional":false},{"name":"Stripe","optional":false}],"status":"live","first_seen_at":"2026-10-06T10:58:35Z","employer_posted_date":"2026-10-06","last_verified_at":"2026-10-11T01:23:50Z","board_verified":true,"closed_at":null,"days_open":4,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":4},"description":"Who we are\nAbout Stripe\nStripe is a financial infrastructure platform for businesses. Millions of companies-from the world's largest enterprises to the most ambitious startups-use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.\nAbout the team\nThe Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team.\nThe Security Governance, Risk, and Compliance (SGRC) team helps Stripe make informed security decisions, understand its risk and control posture, and represent its security program to internal and external stakeholders. The team also manages security risk arising from Stripe’s relationships with third parties by assessing their security controls, identifying and mitigating risk, and supporting informed onboarding and risk-acceptance decisions. Our work helps Stripe move quickly while maintaining clear and consistent security expectations.\nWhat you'll do\nIndependently manage a portfolio of Third Party Security Risk Assessments (TPSRAs) for new engagements, renewals / reassessments, and material changes in relationship scope.\nReview security questionnaires, independent assurance reports, certifications, penetration-test results, and other evidence to evaluate third-party control effectiveness.\nIdentify security gaps, determine proportionate remediation requirements, and clearly communicate findings to Stripe DRIs and cross-functional partners.\nApply Stripe’s third-party security standards consistently, documenting assessment results, decisions, and supporting evidence in Zip, Aravo, and other program systems.\nEscalate novel, complex, or high-risk findings and support Enhanced Due Diligence and risk-acceptance processes when a third party cannot meet Stripe’s security requirements.\nPartner with Procurement, Legal, Privacy, Business Continuity, Security, and business stakeholders to resolve assessment issues and support timely third-party onboarding.\nProvide practical guidance to Stripe teams on TPSRA requirements, timelines, and their responsibilities throughout the assessment process.\nTrack assessment volume, aging, service levels, remediation status, and other program-health indicators; use the data to identify trends and recommend improvements.\nIdentify gaps in program processes, documentation, or tooling and contribute to implementing improvements that increase consistency, scalability, and stakeholder experience.\nContribute to third-party security risk policies, standards, procedures, and guidance.\nWhat You'll Need:\n4+ years of relevant experience in third-party security risk, security assessments, information security, or a related risk-management function.\nExperience conducting end-to-end third-party security assessments, including reviewing security documentation, identifying control gaps, determining risk, and defining remediation requirements.\nWorking knowledge of common security and assurance frameworks, such as SOC 2, ISO 27001, PCI DSS, NIST, and CSA.\nSound judgment and analytical skills, including the ability to distinguish material security risks from lower-priority findings and recommend a proportionate response.\nAbility to independently manage multiple assessments, priorities, and stakeholder relationships while meeting defined timelines.\nClear written and verbal communication skills, including the ability to explain technical security findings to non-security stakeholders.\nExperience using operational data and reporting to identify trends, communicate program health, and improve processes.\nA collaborative approach and experience working with cross-functional partners such as Procurement, Legal, Privacy, and business teams.\nNice to have:\nExperience with third-party risk management platforms or procurement workflow tools such as Aravo, Zip, or similar systems.\nExperience with Enhanced Due Diligence, security risk acceptance, or third-party incident response.\nExperience improving or scaling a third-party risk assessment program","description_format":"text","description_chars":4467,"description_truncated":false,"requirements":{"experience_years_min":4,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Payment Processing & Gateways"],"lifecycle":[{"event":"open","at":"2026-10-06T11:41:08Z"}],"visa":[{"country":"US","licensed_sponsor":true,"evidence":"H-1B filings in 12 months: 319 · green card filings: 110","filings_12m":319,"filings_prev_12m":318,"green_card_filings_12m":110,"median_offered_wage_usd":168770,"route":null,"cap_exempt":false,"checked_at":"2026-10-03T21:08:04+00:00","sources":["US Department of Labor: LCA disclosure data (H-1B, H-1B1, E-3)","US Department of Labor: PERM disclosure data (green cards)"],"filings_for_role_12m":0}],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":3,"expected_fill_days":63,"reasons":["conf:1","stale_co","velocity","win:early","comp:brand"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/stripe-security-grc-program-manager-third-party-risk","json_url":"https://alion.io/job/stripe-security-grc-program-manager-third-party-risk.json","meta":{"generated_at":"2026-10-11T02:19:11Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3661,"day_limit":5000,"remaining_today":1339,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":64},"rest":"https://alion.io/mcp/rest/get_company?id=64"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fstripe-security-grc-program-manager-third-party-risk"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fstripe-security-grc-program-manager-third-party-risk"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fstripe-security-grc-program-manager-third-party-risk"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/stripe-security-grc-program-manager-third-party-risk\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fstripe-security-grc-program-manager-third-party-risk"}]}