InterviewHack.ai
Empezar gratis
Vacantes / Stripe

Security GRC Program Manager, Third Party Risk

Stripe·US - Hybridmid

En corto

  • →Gestiona evaluaciones de riesgo de terceros en Stripe, asegurando que sus proveedores cumplan con estándares de seguridad.
  • →Revisas documentación técnica, certificaciones y hallazgos de auditorías para identificar brechas y recomendar acciones correctivas.
  • →Destaca que trabajas con herramientas como Zip y Aravo, y tomas decisiones clave en procesos de onboarding de proveedores.

Proficiency in English required

Postularme en la empresa ↗Compartir por WhatsApp
✓ Gratis para empezar✓ Corre en tu navegador✓ Primer dossier sin tarjeta✓ Listo en ~1 minuto

En ~1 minuto te damos: quién te entrevista, las preguntas probables con respuestas desde tu CV, y tu CV adaptado a esta vacante. Tu primer dossier es gratis.

Las preguntas que te van a hacer

1. ¿Cómo evaluarías un informe de auditoría SOC 2 de un proveedor crítico y qué hallazgos considerarías materiales?

2. Describe cómo gestionarías una tercera parte que no cumple con el requisito de cifrado de datos en tránsito.

3. ¿Qué harías si un proveedor rechaza una recomendación de remedio que consideras de alto riesgo?

🔒 +7 preguntas más

Sin tarjeta. Subís tu CV y en ~1 minuto tenés el dossier completo.

🎧¿Llegás a la entrevista? Llevá el copiloto. Nuestra extensión escucha la entrevista en vivo y te muestra anclas de 3-4 palabras desde tu CV y tu preparación — mirás, conectás, hablás. Gratis. Ver la extensión →

💵 USD · Remote · No visa

¿No encontrás lo que buscás? Probá Micro1

Micro1 te ubica directo en empresas de EE. UU. que pagan en USD. Un solo proceso de vetting, múltiples ofertas — sin aplicar en frío.

Que Micro1 te matchee →
📬Vacantes elegidas para TU CV, cada mañana por WhatsApp. Gratis: escribí “vacantes” y el bot te manda tus matches del día. Suscribirme →

¿Qué piden?

  • ✓4+ años en gestión de riesgo de terceros o evaluaciones de seguridad.
  • ✓Experiencia en evaluaciones completas de terceros, desde revisión de documentación hasta definición de remedios.
  • ✓Conocimiento de marcos como SOC 2, ISO 27001, PCI DSS, NIST y CSA.
  • ✓Capacidad para juzgar riesgos materiales y recomendar respuestas proporcionales.
  • ✓Habilidades analíticas para gestionar múltiples evaluaciones con autonomía.
  • ✓Experiencia en comunicación clara de hallazgos a equipos técnicos y no técnicos.

¿No cumplís todo? Es lo normal — tu dossier gratis te dice qué gaps tenés y cómo cubrirlos en la entrevista.

ZipAravoSOC 2ISO 27001PCI DSSNISTCSAsecurity questionnairesindependent assurance reportspenetration-test results

¿A quién escribirle en Stripe?

Tu dossier gratis identifica a las personas que te entrevistarían — con su background, qué valoran y cómo escribirles para destacar antes de aplicar.

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the team The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team. The Security Governance, Risk, and Compliance (SGRC) team helps Stripe make informed security decisions, understand its risk and control posture, and represent its security program to internal and external stakeholders. The team also manages security risk arising from Stripe’s relationships with third parties by assessing their security controls, identifying and mitigating risk, and supporting informed onboarding and risk-acceptance decisions. Our work helps Stripe move quickly while maintaining clear and consistent security expectations. What you'll do • Independently manage a portfolio of Third Party Security Risk Assessments (TPSRAs) for new engagements, renewals / reassessments, and material changes in relationship scope. • Review security questionnaires, independent assurance reports, certifications, penetration-test results, and other evidence to evaluate third-party control effectiveness. • Identify security gaps, determine proportionate remediation requirements, and clearly communicate findings to Stripe DRIs and cross-functional partners. • Apply Stripe’s third-party security standards consistently, documenting assessment results, decisions, and supporting evidence in Zip, Aravo, and other program systems. • Escalate novel, complex, or high-risk findings and support Enhanced Due Diligence and risk-acceptance processes when a third party cannot meet Stripe’s security requirements. • Partner with Procurement, Legal, Privacy, Business Continuity, Security, and business stakeholders to resolve assessment issues and support timely third-party onboarding. • Provide practical guidance to Stripe teams on TPSRA requirements, timelines, and their responsibilities throughout the assessment process. • Track assessment volume, aging, service levels, remediation status, and other program-health indicators; use the data to identify trends and recommend improvements. • Identify gaps in program processes, documentation, or tooling and contribute to implementing improvements that increase consistency, scalability, and stakeholder experience. • Contribute to third-party security risk policies, standards, procedures, and guidance. What You'll Need: • 4+ years of relevant experience in third-party security risk, security assessments, information security, or a related risk-management function. • Experience conducting end-to-end third-party security assessments, including reviewing security documentation, identifying control gaps, determining risk, and defining remediation requirements. • Working knowledge of common security and assurance frameworks, such as SOC 2, ISO 27001, PCI DSS, NIST, and CSA. • Sound judgment and analytical skills, including the ability to distinguish material security risks from lower-priority findings and recommend a proportionate response. • Ability to independently manage multiple assessments, priorities,

¿Buscando algo parecido?

Dejá tu email y te avisamos cuando salgan vacantes que coincidan con tu perfil.

No apliques sin prepararte

Investigamos quién te entrevista, adaptamos tu CV y te ensayamos en vivo — gratis la primera.

InterviewHack.ai

Preparate para la entrevista exacta: quién te entrevista, tu CV a medida y coach real.

Producto

VacantesEmpresas contratandoTodas las herramientasVeredicto de CV (Jev)Cover letter gratisPreguntas de entrevista por rolSimulador de test técnico"Hablame de vos" (respuesta)Revisar CV (ATS) gratis¿Cómo suena tu inglés?¿Te pagan bien?Guion de negociación salarialRespuesta STAR gratisTitular + About de LinkedInReporte de sueldos LATAMCursos gratisBlogCV a medidaPráctica habladaPreciosAfiliados — 30%

Empleos remotos

ReactPythonFull-StackLATAMArgentinaMéxicoVer todas →

Preparate

Práctica habladaFrontendBackendAI EngineerPor empresaVendete con tu CV

Empresa

Buscás talentoAcerca deContactoPrivacidadTérminos

© 2026 InterviewHack.ai · Tu CV es tuyo. Nunca se usa para entrenar nada. · Un producto de IA-PTY

Vacantes similares activas

Partner Marketing Leader, Alliances & Channel

Stripe · Seattle, San Francisco, or US-Remote

→

GTM Recruiting Manager

Stripe · US-Remote, Chicago, Atlanta

→

Legal Program Manager, Launch Readiness

Stripe · Remote or Hybrid

→

Product Tax Specialist

Stripe · San Francisco, Seattle, New York City

→