安全GRC项目经理
查看雇主原标题
Program Manager, Security GRCStripe · Remote
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 50/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 远程职位
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 远程职位+8
- 稀有职位+1
- 公司来源健康度+8
该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译我们是谁
关于 Stripe
Stripe 是一个面向企业的金融基础设施平台。数百万家公司——从全球最大的企业到最有抱负的初创公司——都在使用 Stripe 来接受付款、增长收入并加速新的商业机会。我们的使命是提升互联网的 GDP,而我们面前还有大量工作要做。这意味着您拥有一个前所未有的机会,在从事职业生涯中最重要工作的同时,让全球经济触手可及。
关于团队
Stripe 安全团队致力于提升 Stripe 及其用户的安全性。用户将一些最敏感的信息托付给我们,而我们让安全成为我们所做一切事情中的首要考量。安全问题不断演变,为安全团队创造了极其动态的环境。
Stripe 的安全治理、风险与合规(SGRC)团队提供安全治理、风险管理和合规能力,使 Stripe 能够做出战略性安全决策、衡量我们的风险与控制态势,并在内部和外部实体面前代表 Stripe 安全。我们组织的成功运作通过优化安全项目的沟通和期望来加速 Stripe。
您将做什么
我们正在寻找一位在安全合规方面拥有深厚专业知识的 Security GRC Program Manager,作为 Stripe 安全组织与外部审计师、监管机构和合规利益相关方之间的主要接口。在此职位中,您将在审计工作中代表安全团队,清晰阐述 Stripe 的安全控制如何设计以及如何运作,并确保在复杂的全球监管环境中以一致的方式满足合规义务。
岗位职责
我们正在寻找一位在安全合规方面拥有深厚专业知识的 Security GRC Program Manager,作为 Stripe 安全组织与外部审计师、监管机构和合规利益相关方之间的主要接口。在此职位中,您将在审计工作中代表安全团队,清晰阐述 Stripe 的安全控制如何设计以及如何运作,并确保在复杂的全球监管环境中以一致且严谨的方式满足合规义务。
在此职位中,您将作为监管机构和审计师等外部实体与我们内部安全团队之间的代理,确保合规响应的一致性,并帮助维持一个精简且有效的合规项目。理想候选人应具备适应能力,并能在不断演变和成熟的组织中找到结构。
• 在跨职能审计工作中担任信息安全主题专家,在与审计师和监管机构的访谈会议中代表安全团队
• 作为内部联络人(代理)在安全组织之间进行协调,确保审计得到有效且一致的管理
• 创建并维护一个中央存储库,存放遵守 SOC 2、PCI DSS、SOX 和其他全球监管标准所需的审计证据工件
• 根据常见框架执行安全风险和控制评估,以确保符合 Stripe 的信息安全政策与标准以及适用法规(例如 ISO 2700x、PCI DSS、SOX、NIST、COBIT)
• 为控制负责人提供安全控制设计和重新设计方面的指导支持,以确保持续合规和有效性
• 为具有监管义务的 Stripe 法律实体促进安全合规支持,并与跨职能利益相关方合作,跟踪和报告控制整改工作
• 支持更广泛的 GRC 团队项目计划,包括政策撰写、安全意识培训和第三方安全风险评估
任职要求
我们正在寻找符合该职位最低要求的人选。如果您符合这些要求,鼓励您申请。优先资格是加分项,而非要求。
最低要求
• 信息安全框架、实践、政策、标准和程序方面的主题专家(例如 NIST CSF、SOC 2、PCI DSS、ISO 27001/2 或同等标准)
• 6 年以上安全治理、风险与合规或技术合规职位经验,并对审计流程有深入理解
• 接触过全球监管要求(例如 DORA、FFIEC、EBA、NYDFS),并具有将其整合到合规项目中的经验
• 具有开展安全审计并支持复杂、重叠监管框架合规的经验
• 强大的项目管理技能,擅长协调安全评估并管理跨时区的多个利益相关方工作
• 出色的沟通技能,能够与各层级建立关系,并向审计师、监管机构和高管受众阐释技术安全概念
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team.
The Security Governance, Risk, and Compliance (SGRC) team at Stripe provides security governance, risk management, and compliance capabilities to allow Stripe to make strategic security decisions, measure our risk and control posture, and represent Stripe Security to internal and external entities. The successful operation of our organization accelerates Stripe by optimizing the communication and expectations of our security program.
What you’ll do
We're looking for a Security GRC Program Manager with deep expertise in security compliance to serve as the primary interface between Stripe's Security organization and external auditors, regulators, and compliance stakeholders. In this role, you'll represent the Security team in audit engagements, articulate how Stripe's security controls are designed and how they operate, and ensure that compliance obligations across a complex global regulatory landscape are met with cons
岗位职责
We're looking for a Security GRC Program Manager with deep expertise in security compliance to serve as the primary interface between Stripe's Security organization and external auditors, regulators, and compliance stakeholders. In this role, you'll represent the Security team in audit engagements, articulate how Stripe's security controls are designed and how they operate, and ensure that compliance obligations across a complex global regulatory landscape are met with consistency and rigor.
In this role, you will act as a proxy between external entities like regulators and auditors, and our internal security teams, ensuring consistency in compliance responses and helping maintain a lean and effective compliance program. The ideal candidate is adaptable and finds structure in an evolving and maturing organization.
• Act as an information security subject matter expert during cross-functional audit engagements, representing the Security team in walkthrough meetings with auditors and regulators
• Serve as the internal liaison (proxy) between and the Security organization to ensure audits are managed effectively and consistently
• Create and maintain a central repository of audit evidence artifacts required for compliance with SOC 2, PCI DSS, SOX, and other global regulatory standards
• Perform security risk and control assessments against common frameworks to ensure compliance with Stripe's Information Security Policy and Standards and applicable regulations (e.g., ISO 2700x, PCI DSS, SOX, NIST, COBIT)
• Support control owners with guidance on security control design and redesign to ensure continued compliance and effectiveness
• Facilitate security compliance support for Stripe's legal entities with regulatory obligations, and collaborate with cross-functional stakeholders to track and report on control remediation efforts
• Support broader GRC team program initiatives, including policy writing, security awareness training, and third-party security risk assessments
任职要求
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
• Subject matter expert in information security frameworks, practices, policies, standards, and procedures (e.g., NIST CSF, SOC 2, PCI DSS, ISO 27001/2, or equivalent)
• 6+ years of experience in Security Governance, Risk, and Compliance or Technology Compliance roles with a strong understanding of audit processes
• Exposure to global regulatory requirements (e.g., DORA, FFIEC, EBA, NYDFS) and experience integrating them into compliance programs
• Experience conducting security audits and supporting compliance across complex, overlapping regulatory frameworks
• Strong program management skills with proficiency in coordinating security assessments and managing multiple stakeholder engagements across time zones
• Excellent communication skills, with the ability to build relationships at all levels and translate technical security concepts for auditors, regulators, and executive audiences