layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
US - Hybrid
Source: Stripe careers · View original posting
From Stripe's posting. “We” and “our” refer to the employer.
Who we are
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team.
The Security Governance, Risk, and Compliance (SGRC) team helps Stripe make informed security decisions, understand its risk and control posture, and represent its security program to internal and external stakeholders. The team also manages security risk arising from Stripe’s relationships with third parties by assessing their security controls, identifying and mitigating risk, and supporting informed onboarding and risk-acceptance decisions.
Our work helps Stripe move quickly while maintaining clear and consistent security expectations.
4+ years of relevant experience in third-party security risk, security assessments, information security, or a related risk-management function.
Experience conducting end-to-end third-party security assessments, including reviewing security documentation, identifying control gaps, determining risk, and defining remediation requirements.
Working knowledge of common security and assurance frameworks, such as SOC 2, ISO 27001, PCI DSS, NIST, and CSA.
Sound judgment and analytical skills, including the ability to distinguish material security risks from lower-priority findings and recommend a proportionate response.
Ability to independently manage multiple assessments, priorities, and stakeholder relationships while meeting defined timelines.
Clear written and verbal communication skills, including the ability to explain technical security findings to non-security stakeholders.
Experience using operational data and reporting to identify trends, communicate program health, and improve processes.
A collaborative approach and experience working with cross-functional partners such as Procurement, Legal, Privacy, and business teams.
Experience with third-party risk management platforms or procurement workflow tools such as Aravo, Zip, or similar systems.
Experience with Enhanced Due Diligence, security risk acceptance, or third-party incident response.
Experience improving or scaling a third-party risk assessment program
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted:
Greystar · The Waller, Austin, TX
Menasha · Neenah, Wisconsin; Menasha Global
Greystar · The Lucille Waco, Waco, TX
Frost Bank · Houston, TX - Westchase
Northern Trust · Key Biscayne, FL; Miami, FL
Bristol Myers Squibb · Princeton - NJ - US; Princeton LVL - NJ