Security GRC Program Manager, Third Party Risk
Stripe
Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.
Got this interview? Our apps help you get the job.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
3,273 open security roles across 428 companies are on ApplySarthi right now, most of them in Bengaluru (118), Pune (22), Hyderabad (21).
- Principal Security Engineer, Security Tribehellofresh
- Security Lead - Member of Technical StaffCallosum
- Senior Staff Network Security EngineerMarvell · bengaluru
- Senior Consultant - SecurityWSP · delhi ncr
- Application Security EngineerTeliogroup
What security roles keep asking for: AWS (31%), Python (28%), SIEM (14%), CI/CD (14%), Azure (14%), GCP (13%), IAM (13%) — counted across their open postings here.
Stripe has 729 open roles listed here.
- Writer, Content Marketing
- Bridge Product Accountantbengaluru
- Engineering Manager - Support Experience
- Marketing Operations Manager, AMER Events
- Account Executive, Product Sales - Open Issuance
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for security roles keep coming back to AWS, Python, SIEM, CI/CD. Practise those questions before you sit with Stripe.
Questions you are likely to be asked
- Why do you want to join Stripe?
- What is your experience with Stakeholder management? Tell me one thing you learned the hard way.
- How do you keep secrets and access safe in your infrastructure?
- Walk me through how code gets from a commit to production where you work.
- Tell me about an outage you handled. What did you learn from it?
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Security GRC Program Manager, Third Party Risk at Stripe interview free →Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team.
The Security Governance, Risk, and Compliance (SGRC) team helps Stripe make informed security decisions, understand its risk and control posture, and represent its security program to internal and external stakeholders. The team also manages security risk arising from Stripe’s relationships with third parties by assessing their security controls, identifying and mitigating risk, and supporting informed onboarding and risk-acceptance decisions. Our work helps Stripe move quickly while maintaining clear and consistent security expectations.
What you'll do
- Independently manage a portfolio of Third Party Security Risk Assessments (TPSRAs) for new engagements, renewals / reassessments, and material changes in relationship scope.
- Review security questionnaires, independent assurance reports, certifications, penetration-test results, and other evidence to evaluate third-party control effectiveness.
- Identify security gaps, determine proportionate remediation requirements, and clearly communicate findings to Stripe DRIs and cross-functional partners.
- Apply Stripe’s third-party security standards consistently, documenting assessment results, decisions, and supporting evidence in Zip, Aravo, and other program systems.
- Escalate novel, complex, or high-risk findings and support Enhanced Due Diligence and risk-acceptance processes when a third party cannot meet Stripe’s security requirements.
- Partner with Procurement, Legal, Privacy, Business Continuity, Security, and business stakeholders to resolve assessment issues and support timely third-party onboarding.
- Provide practical guidance to Stripe teams on TPSRA requirements, timelines, and their responsibilities throughout the assessment process.
- Track assessment volume, aging, service levels, remediation status, and other program-health indicators; use the data to identify trends and recommend improvements.
- Identify gaps in program processes, documentation, or tooling and contribute to implementing improvements that increase consistency, scalability, and stakeholder experience.
- Contribute to third-party security risk policies, standards, procedures, and guidance.
What You'll Need:
- 4+ years of relevant experience in third-party security risk, security assessments, information security, or a related risk-management function.
- Experience conducting end-to-end third-party security assessments, including reviewing security documentation, identifying control gaps, determining risk, and defining remediation requirements.
- Working knowledge of common security and assurance frameworks, such as SOC 2, ISO 27001, PCI DSS, NIST, and CSA.
- Sound judgment and analytical skills, including the ability to distinguish material security risks from lower-priority findings and recommend a proportionate response.
- Ability to independently manage multiple assessments, priorities, and stakeholder relationships while meeting defined timelines.
- Clear written and verbal communication skills, including the ability to explain technical security findings to non-security stakeholders.
- Experience using operational data and reporting to identify trends, communicate program health, and improve processes.
- A collaborative approach and experience working with cross-functional partners such as Procurement, Legal, Privacy, and business teams.
Nice to have:
- Experience with third-party risk management platforms or procurement workflow tools such as Aravo, Zip, or similar systems.
- Experience with Enhanced Due Diligence, security risk acceptance, or third-party incident response.
- Experience improving or scaling a third-party risk assessment program
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- Account Executive, Enterprise (Grower) Stripe
- Account Executive, Enterprise (Grower) Stripe
- Account Executive, Existing Business (Central Eastern Europe)Stripe
- Account Executive, Hunter (Central Eastern Europe)Stripe
- Account Executive, Product Sales - Stablecoin IssuingStripe
- Accounts Receivable ManagerStripe · bengaluru
- AEO and GEO Marketing ManagerStripe
- ARG Engineering ManagerStripe
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on greenhouse · posted 2026-10-06. ApplySarthi collects openings and links to application pages; the role is advertised by Stripe, not by us.