InterviewHack.ai
Start free
Jobs / Stripe

Security GRC Program Manager, Third Party Risk

Stripe·US - Hybridmid

In short

  • →Gestiona evaluaciones de riesgo de terceros en Stripe, asegurando que sus proveedores cumplan con estándares de seguridad.
  • →Revisas documentación técnica, certificaciones y hallazgos de auditorías para identificar brechas y recomendar acciones correctivas.
  • →Destaca que trabajas con herramientas como Zip y Aravo, y tomas decisiones clave en procesos de onboarding de proveedores.

Proficiency in English required

Apply on company site ↗Share on WhatsApp
✓ Free to start✓ Runs in your browser✓ First dossier, no card✓ Ready in ~1 minute

In ~1 minute you get: who interviews you, the likely questions answered from your CV, and your CV tailored to this job. Your first dossier is free.

The questions they'll ask you

1. ¿Cómo evaluarías un informe de auditoría SOC 2 de un proveedor crítico y qué hallazgos considerarías materiales?

2. Describe cómo gestionarías una tercera parte que no cumple con el requisito de cifrado de datos en tránsito.

3. ¿Qué harías si un proveedor rechaza una recomendación de remedio que consideras de alto riesgo?

🔒 +7 more questions

No card. Upload your resume and the full dossier is ready in ~1 minute.

🎧Land the interview? Bring the copilot. Our free extension listens to the live interview and flashes 3-4-word anchors from your resume and prep — glance, connect, talk. Get the extension →

💵 USD · Remote · No visa

Not finding what you want? Try Micro1

Micro1 places engineers directly at US companies paying in USD. One vetting, multiple offers — no cold applying.

Get matched by Micro1 →
📬Jobs picked for YOUR resume, every morning on WhatsApp. Free: text “vacantes” and the bot sends your daily matches. Subscribe →

What they ask for

  • ✓4+ años en gestión de riesgo de terceros o evaluaciones de seguridad.
  • ✓Experiencia en evaluaciones completas de terceros, desde revisión de documentación hasta definición de remedios.
  • ✓Conocimiento de marcos como SOC 2, ISO 27001, PCI DSS, NIST y CSA.
  • ✓Capacidad para juzgar riesgos materiales y recomendar respuestas proporcionales.
  • ✓Habilidades analíticas para gestionar múltiples evaluaciones con autonomía.
  • ✓Experiencia en comunicación clara de hallazgos a equipos técnicos y no técnicos.

Don't tick every box? That's normal — your free dossier shows your gaps and how to cover them in the interview.

ZipAravoSOC 2ISO 27001PCI DSSNISTCSAsecurity questionnairesindependent assurance reportspenetration-test results

Who should you write to at Stripe?

Your free dossier identifies the people who'd interview you — their background, what they value, and how to reach out so you stand out before applying.

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the team The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team. The Security Governance, Risk, and Compliance (SGRC) team helps Stripe make informed security decisions, understand its risk and control posture, and represent its security program to internal and external stakeholders. The team also manages security risk arising from Stripe’s relationships with third parties by assessing their security controls, identifying and mitigating risk, and supporting informed onboarding and risk-acceptance decisions. Our work helps Stripe move quickly while maintaining clear and consistent security expectations. What you'll do • Independently manage a portfolio of Third Party Security Risk Assessments (TPSRAs) for new engagements, renewals / reassessments, and material changes in relationship scope. • Review security questionnaires, independent assurance reports, certifications, penetration-test results, and other evidence to evaluate third-party control effectiveness. • Identify security gaps, determine proportionate remediation requirements, and clearly communicate findings to Stripe DRIs and cross-functional partners. • Apply Stripe’s third-party security standards consistently, documenting assessment results, decisions, and supporting evidence in Zip, Aravo, and other program systems. • Escalate novel, complex, or high-risk findings and support Enhanced Due Diligence and risk-acceptance processes when a third party cannot meet Stripe’s security requirements. • Partner with Procurement, Legal, Privacy, Business Continuity, Security, and business stakeholders to resolve assessment issues and support timely third-party onboarding. • Provide practical guidance to Stripe teams on TPSRA requirements, timelines, and their responsibilities throughout the assessment process. • Track assessment volume, aging, service levels, remediation status, and other program-health indicators; use the data to identify trends and recommend improvements. • Identify gaps in program processes, documentation, or tooling and contribute to implementing improvements that increase consistency, scalability, and stakeholder experience. • Contribute to third-party security risk policies, standards, procedures, and guidance. What You'll Need: • 4+ years of relevant experience in third-party security risk, security assessments, information security, or a related risk-management function. • Experience conducting end-to-end third-party security assessments, including reviewing security documentation, identifying control gaps, determining risk, and defining remediation requirements. • Working knowledge of common security and assurance frameworks, such as SOC 2, ISO 27001, PCI DSS, NIST, and CSA. • Sound judgment and analytical skills, including the ability to distinguish material security risks from lower-priority findings and recommend a proportionate response. • Ability to independently manage multiple assessments, priorities,

Looking for something similar?

Leave your email and we'll alert you when matching jobs appear.

Don't apply unprepared

We research who's interviewing you, tailor your CV and rehearse you live — first one free.

InterviewHack.ai

Prepare for the exact interview: who's interviewing you, a tailored CV, and a real coach.

Product

JobsCompanies hiringAll free toolsResume verdict (Jev)Free cover letterInterview questions by roleTechnical assessment simulator"Tell me about yourself" answerFree ATS checkerInterview-English checkSalary checkSalary negotiation scriptFree STAR answerLinkedIn headline + AboutLATAM salary reportFree coursesBlogTailored CVSpoken practicePricingAffiliates — 30%

Remote jobs

ReactPythonFull-StackLATAMArgentinaMexicoSee all →

Prepare

Spoken practiceFrontendBackendAI EngineerBy companySell with your CV

Company

For employersAboutContactPrivacyTerms

© 2026 InterviewHack.ai · Your CV is yours. Never used to train anything. · A product of IA-PTY

Similar open roles

Partner Marketing Leader, Alliances & Channel

Stripe · Seattle, San Francisco, or US-Remote

→

GTM Recruiting Manager

Stripe · US-Remote, Chicago, Atlanta

→

Legal Program Manager, Launch Readiness

Stripe · Remote or Hybrid

→

Product Tax Specialist

Stripe · San Francisco, Seattle, New York City

→