- Страна
- США
Откликайтесь
на вакансии с ИИ

Engineering Program Manager, Tech GRC
Stripe — один из самых престижных работодателей в финтехе. Вакансия предлагает высокий уровень ответственности, работу с передовыми технологиями и возможность влиять на глобальную финансовую инфраструктуру.
Сложность вакансии
Высокий уровень сложности обусловлен требованием к огромному опыту (более 12 лет) и необходимости сочетать глубокие знания в области аудита (ISO, SOC, PCI) с инженерным пониманием инфраструктуры и автоматизации.
Анализ зарплаты
Зарплата для данной роли в Stripe обычно находится в верхнем дециле рынка США для опытных программных менеджеров, часто включая значительный пакет акций (RSU). Наш прогноз соответствует рыночным стандартам для Senior/Staff уровней в Tier-1 технологических компаниях.
Сопроводительное письмо
I am writing to express my strong interest in the Engineering Program Manager, Tech GRC position at Stripe. With over 12 years of experience at the intersection of technical compliance and infrastructure engineering, I have a proven track record of leading complex audit programs such as SOC2, ISO 27001, and PCI-DSS within high-growth distributed environments. My approach focuses on bridging the gap between rigorous compliance requirements and high-velocity engineering by driving automation in evidence collection and embedding controls directly into the SDLC.
At my previous roles, I have successfully collaborated with SRE and platform teams to transform manual audit processes into scalable, automated workflows. I am particularly drawn to Stripe’s mission of increasing the GDP of the internet and your commitment to maintaining user trust through robust technology controls. I am confident that my technical background and experience in risk prioritization will allow me to contribute effectively to Stripe’s global compliance posture and support the seamless integration of new products and acquisitions.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в stripe уже сейчас
Присоединяйтесь к Stripe, чтобы формировать будущее финансовой инфраструктуры интернета и управлять сложнейшими программами технического комплаенса!
Описание вакансии
Who we are
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
About the team
The Technology Compliance team is dedicated to delivering excellence across Stripe’s compliance with global and industry-specific technology control regimes, such as PCI-DSS, SOC, and other international technology certifications. We are a team of specialist program managers to lead external audits of Stripe’s technology environment, design and improve technology controls, and support our many engineering and business partners in maintaining compliance with controls requirements. We are consultants to company leaders, partners to our external auditors, builders of risk-reducing controls and internal products, and effective executors of large programs that are integral to the trust our Users place in Stripe and that of our regulators and partners.
What you’ll do
In this role, your daily focus centers on bridging the gap between compliance requirements and high-velocity engineering. You will own the implementation of baseline technology controls, work with cross-functional teams to automate evidence collection, and contribute to the design of scalable governance and issue-management processes. You’ll translate risk requirements into practical controls, track remediation progress, and continuously improve controls and workflows to support audit readiness and operational resilience.On any given day, you might be conducting a gap analysis for a new global compliance certification, prioritizing remediation tasks based on a data-driven risk assessment, or translating complex ISO/SOC2 controls into actionable technical tickets for product engineers. As a program leader, you will serve as a strategic connector influencing senior stakeholders across infrastructure engineering to balance long-term platform health with feature delivery. You’ll advise peers on secure / compliant architecture, drive decisions that maintain an always-on audit posture, and ensure compliance is embedded in engineering roadmaps and delivery processes.
Responsibilities
- Deep technical compliance experience: demonstrable experience implementing and operating controls and audit programs (ISO, SOC, PCI, UK Cyber Essentials, privacy audits, or similar) in complex, distributed environments.
- Design and implement baseline technology controls, ensuring they are practical, scalable, and aligned with compliance and security requirements.
- Strong engineering collaboration: proven track record working with infrastructure, platform, SRE, and product engineering teams to deliver technical controls and automation.
- Tooling and automation mindset: experience building scalable tools, frameworks, or platforms that reduce manual evidence collection and audit testing overhead.
- Acquisition integration experience (preferred): experience assessing and integrating acquired products/systems into an enterprise compliance environment.
- Fintech or regulated industry background preferred: experience with financial reporting, payment platforms, or similarly regulated systems is strongly desired.
- Program leadership at scale: ability to lead cross‑organizational programs, influence senior engineers and executives, and drive consensus across competing priorities.
- Data‑driven communicator: strong analytical skills to prioritize risk and remediation, and the ability to present complex technical compliance concepts to auditors and executives.
- People leadership and mentorship: experience coaching peers and engineering partners on program delivery and compliance‑oriented engineering practices.
- Relevant education/certifications: degree in Computer Science, Information Security, Engineering, or equivalent experience. Certifications such as CISA, CISSP, PCI-related, ISO lead auditor, or other relevant credentials are a plus.
Who you are
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
Minimum requirements
- 12+ years of experience in technical compliance, security, or risk roles with direct responsibility for audit or certification delivery (ISO, SOC, PCI, UK Cyber Essentials, privacy audits, or similar).
- Demonstrated experience leading end-to-end technical audit certification programs, including scoping, control mapping, evidence collection, remediation, and auditor engagement.
- Proven track record working closely with infrastructure, platform, SRE, and product engineering teams to implement and operationalize controls.
- Hands-on experience building or driving tooling/automation for evidence collection, testing, or compliance reporting.
- Strong program and project management skills with experience coordinating cross-functional work streams and delivering on time against competing priorities.
- Excellent verbal and written communication skills, with experience presenting technical compliance status to auditors, engineers, and senior leadership.
- Solid analytical and risk‑prioritization skills to sequence remediation activities and make data‑driven decisions.
- Experience integrating acquired products or systems into an enterprise compliance posture (preferred).
- Relevant certifications such as CISA, CISSP, ISO Lead Auditor, PCI-related certifications, or equivalent.
Preferred qualifications
- Fintech or payments industry experience (preferred), including familiarity with regulatory expectations, payment platform architectures, and financial services risk models.
- Experience integrating acquired products or systems into an enterprise compliance posture.
- Proven ability to leverage a variety of tools to develop key metrics and broadcast program efficacy through data-driven dashboards.
- Strong background in cloud and infrastructure technologies (AWS, GCP, Azure), containerization, and modern platform engineering practices.
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- AWS
- Azure
- Program Management
- Risk Management
- ISO 27001
- PCI DSS
- SRE
- CISA
- CISSP
- Information Security
- Google Cloud Platform
- SOC2
- Automation
Возможные вопросы на собеседовании
Проверка опыта автоматизации комплаенса, что критично для Stripe.
Расскажите о конкретном случае, когда вы автоматизировали сбор доказательств для аудита. Какие инструменты вы использовали и как это повлияло на работу инженеров?
Оценка способности балансировать между требованиями безопасности и скоростью разработки.
Как вы подходите к разрешению конфликтов между жесткими требованиями комплаенса и необходимостью быстрого выпуска фич продуктовой командой?
Проверка навыков управления рисками в сложных системах.
Опишите ваш процесс проведения gap-анализа для новой международной сертификации в распределенной облачной среде.
Оценка опыта интеграции, указанного в предпочтительных требованиях.
Какой стратегии вы придерживаетесь при интеграции приобретенного стартапа в существующую систему контроля и комплаенса головной компании?
Проверка лидерских качеств и влияния на стейкхолдеров.
Как вы убеждаете руководство и старших инженеров в необходимости внедрения новых контролей, которые могут потребовать значительных ресурсов?
Похожие вакансии
Руководитель направления SberUp
Deployment Program Manager - Enterprise
Senior Customer Success Manager / Program Manager – Amazon Relay Rewards (US)
Senior Technical Program Manager
Senior Program Manager, Go-To-Market Systems
Senior Legal Program Manager
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- США