←Jobiba.Me
S
Active1mo ago

Program Manager, Security GRC

Stripe·📍 Remote

Employment

FULL TIME

Work mode

Remote

Experience

SENIOR LEVEL

Salary

$133,144–$190,993 / year · Jobiba est.

Market pay estimate

$133,144–$190,993 / year for comparable Program Manager roles. Not employer-provided.

Salary →

Role overview

Job description

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the team The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team. The Security Governance, Risk, and Com

…

What they are looking for

Skills & requirements

Department · 8614 Office of the CISO & Partnership

Stripe logo

Hiring company

Stripe

Finance & Banking

Stripe is a financial services platform that helps all types of businesses accept payments, build flexible billing models and manage money movement.

Keep exploring

Similar active roles

Fresh roles matched to this title and market.

View all →
O
📍 San Francisco, California, United States· Full-time· Remote

About the Team Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. The GRC team provides security assurances and builds compliance for OpenAI’s technology, people, and products. We are technical in what we build but operational in how we do our work, and we partner deeply with Product, Security, Legal, Privacy, GTM, and Field Security to help OpenAI move quickly while maintaining trust with customers, auditors, regulators, and the public. About the Role We are looking for an experienced Product Lifecycle Assurance IC to help scale OpenAI’s GRC function across our product stack to ensure products address customer and regulatory compliance requirements at launch and regressions are detected promptly and corrected. You will partner closely with Product, Security, Legal, and Privacy teams to make sure OpenAI can move quickly while maintaining our security, privacy and compliance claims and giving customers, auditors, and regulators assurance about how OpenAI handles user data. You are responsible for product assurance end-to-end from inception to post-launch (continuous) monitoring. You leverage existing workflows, reviews, and data and enhance, augment and build the components needed to create an end-to-end product assurance program. This role is not about supporting SOC or ISO audits; it's a highly cross-functional and deeply technical operations role to ensure that OAI products meet the compliance bar at launch, regressions are prevented and detected, and our compliance state can be evidenced. This role also helps ensure that our product launch governance program operates effectively across key safety, privacy, legal and security stakeholders and lessons-learned from incidents and regressions are used to improve the program. You or in partnership with engineering teams, build key controls in our infrastructure stack, developer workflows and launch tooling to provide developers with guardrails, perform CI/CD confor

AWSKubernetesCI/CDRest
O
📍 Washington, District of Columbia, United States· Full-time

About the Team Governance, Risk, and Compliance (GRC) is foundational to Security delivering mission outcomes at OpenAI. We’re excited about building creative solutions to ambiguous security requirements and delivering new technologies to mission critical customers. The GRC team provides security and engineering expertise to ensure our customers’ most critical and stringent requirements are met. We are technical in what we build but are operational in how we do our work, and are committed to obtaining, expanding, and maintaining Authorizations to Operate (ATOs) for critical systems while fostering a collaborative and execution-driven culture. About the Role Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector. As a GRC Program Manager, you’ll play a pivotal role in achieving US government (USG) ATOs and compliance frameworks, including but not limited to FedRAMP and Department of War (DoW),for OpenAI products and support agency-specific ATOs for systems deployed in highly regulated and secure environments. You’ll work closely with engineers, internal stakeholders, and external assessors to design, document, and implement security controls that meet stringent compliance requirements. Your creativity and execution-focused approach will be critical in navigating complex challenges while maintaining the trust of our stakeholders. We’re looking for people who bring: Proven experience in obtaining and maintaining a FedRAMP ATO and agency specific ATOs in highly restricted environments, within government or regulated sectors. A deep understanding of USG security frameworks and policies (e.g., NIST, RMF, FedRAMP). Ability to communicate technical concepts to diverse audiences, including engineers and non-technical stakeholders. Exceptional technical program management skills, with the ability to multitask and deliver large complex programs under pressure. This role is base

AWSAzureKubernetesRest
O
📍 San Francisco, California, United States· Full-time

About the Team OpenAI’s Governance, Risk, and Compliance team helps ensure security and privacy are grounded in how our products and systems actually operate. Assurance Operations partners with Security, Engineering, Infrastructure, Product, Privacy, and Legal to make controls provable, risk decisions explicit, and audit readiness a result of well-designed systems. About the Role We are hiring a technical, product-minded GRC builder who can own consequential audits while improving the control and evidence systems behind them. You will build a reusable common control framework, use Codex to automate assurance work, validate changing system scope, and turn repeated audit friction into measurable improvements. We are looking for someone who questions inherited assumptions, solves novel problems creatively, works closely with engineers, and makes the next audit easier by improving the underlying system. You’ll be responsible for: Lead external, internal, customer, and certification audit work from scoping through evidence review, fieldwork, remediation, and closeout. Build a common control framework linking risk, control intent, implementation, owner, system, environment, evidence, and applicable frameworks. Validate actual scope and ownership instead of assuming last year's controls, product boundaries, or evidence remain accurate. Use Codex to build and test evidence checks, control mappings, request triage, owner workflows, monitoring, and remediation reporting. Partner with engineers on cloud architecture, identity, logging, data flows, software changes, vulnerabilities, and control effectiveness. Design maintainable, permission-aware tools that preserve source provenance, human review, and evidence integrity. Reduce repeated requests and operational burden for control owners through measurable workflow improvements. Define roadmaps, decision rights, milestones, success metrics, and clear cross-functional escalations. We’re looking for someone with: Direct ownership

SQLAWSRestAI
GI
📍 Denver, CO;San Francisco, CA· Full-time

About Gusto At Gusto, we're on a mission to grow the small business economy. We handle the hard stuff — payroll, health insurance, 401(k)s, and HR — so owners can focus on their craft and their customers. With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses nationwide and are building a workplace that reflects the people we serve. All full-time employees receive competitive base pay, benefits, and equity (RSUs) — because everyone who helps build Gusto should share in its success. Offer amounts are determined by role, level, and location. Learn more about our Total Rewards philosophy . AI is a fundamental part of how work gets done at Gusto. We expect all team members to actively engage with AI tools relevant to their role and grow their fluency as the technology evolves. AI experience requirements vary by role and will be assessed during the interview process. About the Role: Gusto is becoming an AI-native company, and that only works if our security posture keeps pace. As the Security TPM, you'll own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk. You'll drive the centralized vulnerability scorecard, expand detection and monitoring coverage, harden the SDLC, and stand up the security metrics leadership runs the business on. You'll drive the timelines, manage the dependencies, head off the risk, and use AI plugins to do the work itself, so security becomes something that helps Gusto move faster instead of slowing it down. About the Team: The TPM organization is part of our AIT, Risk, and Security team. We deliver the cross-functional work that lets Gusto securely accelerate its AI and platform modernization. The vulnerability management and security operations programs sit right at the intersection of security engineering, infrastructure, and GRC, and they're foundational to how Gusto scales i

SA
📍 San Francisco, Canada· Full-time

From $164.8K/yr

At Scale, we are driving the future of AI and Machine Learning across a variety of industries. As the Program Manager for Compliance, you will play a pivotal role in the continued success of Scale. Your role will be instrumental in ensuring the effective operation of our Compliance department and our GRC function, allowing us to maintain the highest standards in our industry. Reporting to the Director & Associate General Counsel, Compliance, you will be a dedicated program manager for Scale's enterprise compliance program and the person who turns policy into practice across anti-bribery and anti-corruption, gifts and entertainment, conflicts of interest, third-party risk and sanctions, policy lifecycle, and company-wide training. This is a hands-on builder, not a maintenance role. You will support Commercial, Public Sector, and international business lines, working closely with Legal, Procurement, Finance, Security, and go-to-market teams. You will: Help build, design, improve, and streamline Scale's core compliance programs, including anti-bribery and anti-corruption (ABAC), gifts and entertainment, conflicts of interest, and third-party risk and sanctions screening. Collaborate with stakeholders across the company to improve compliance policies, processes, and procedures. Monitor regulatory developments relevant to Scale's business, translate them into concrete policy and process changes, and track compliance obligations flowing out of customer contracts. Partner with leadership to build, mature, and operationalize the company's enterprise risk management (ERM) framework, identifying and assessing key business risks. Build the reporting layer: metrics and periodic reporting that give Legal & GRC leadership a defensible picture of program health. Flex into audit and assurance work during peak certification periods, and own inbound customer and investor compliance diligence questionnaires. Ideally you'd have: 5+ years building or operating ethics and c

AWSRestMachine LearningAI
R
📍 San Mateo, CA, United States· Full-time

From $180.6K/yr

Every day, tens of millions of people come to Roblox to explore, create, play, learn, and connect with friends in 3D immersive digital experiences– all created by our global community of developers and creators. At Roblox, we’re building the tools and platform that empower our community to bring any experience that they can imagine to life. Our vision is to reimagine the way people come together, from anywhere in the world, and on any device. We’re on a mission to connect a billion people with optimism and civility, and looking for amazing talent to help us get there. A career at Roblox means you’ll be working to shape the future of human interaction, solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone. As a Senior Privacy Engineer on the Security and Privacy GRC team, you will shepherd and grow Roblox's Privacy Review Program, the technical and process backbone that ensures privacy is engineered into every product before it ships. You will join the Security and Privacy GRC team, reporting to the Sr Engineering Manager for Privacy Governance and Operations. This is a hands-on privacy engineering role: you'll set standards for privacy-enhancing technologies, act as the go-to SME for policy-as-code, and partner closely with Product teams, Trust & Safety, Legal, and Regulatory Compliance as part of Roblox's broader cross-functional privacy program. You will: Shepherd and evolve the Privacy Review Program, designing consistent intake workflows, evaluation criteria, and documentation to systematically assess privacy risk across new products, features, and infrastructure changes. Develop standards and guidelines that enable product teams to adopt privacy-enhancing technologies (PETs) such as differential privacy, k-anonymity, data minimization, and secure computation, with clear guidance on trade-offs and implementation patterns. Act as the Privacy SME for policy-as-code, translating privacy

AWSGitAIGo

🔔 Get job alerts

New Program Manager, Security GRC jobs in Remote, straight to your inbox.

No spam · Unsubscribe anytime