Jobs / United States / Stripe

Security GRC Program Manager, Third Party Risk

Stripe · 🇺🇸 US - Hybrid

Sponsorship verdict

Sponsorship possible

One solid signal, not two — worth applying, and worth asking about sponsorship early.

  • Employer is on a government sponsor recordThe US Department of Labor certified 260 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 64 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
  • The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
  • No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
  • What Stripe paid sponsored hires in similar roles1 certified filing for “Technical Program Manager, Risk” (Computer and Information Systems Managers) in VA: $175k–$175k, median $175k. Most were filed at wage level II (100%) — 2 lottery entries, ≈31% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
  • Confirmed live todayWhen a source last listed this job as open.

US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).

A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.

Start free →

Or apply yourself on the official page →

Sponsor Radar — Stripe

260 H-1B filings certified since Oct 2025

The US Department of Labor certified 260 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 64 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).

Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Stripe →

About the role

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. About the team The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team. The Security Governance, Risk, and Compliance (SGRC) team helps Stripe make informed security decisions, understand its risk and control posture, and represent its security program to internal and external stakeholders. The team also manages security risk arising from Stripe’s relationships with third parties by assessing their security controls, identifying and mitigating risk, and supporting informed onboarding and risk-acceptance decisions. Our work helps Stripe move quickly while maintaining clear and consistent security expectations. What you'll do • Independently manage a portfolio of Third Party Security Risk Assessments (TPSRAs) for new engagements, renewals / reassessments, and material changes in relationship scope. • Review security questionnaires, independent assurance reports, certifications, penetration-test results, and other evidence to evaluate third-party control effectiveness. • Identify security gaps, determine proportionate remediation requirements, and clearly communicate findings to Stripe DRIs and cross-functional partners. • Apply Stripe’s third-party security standards consistently, documenting assessment results, decisions, and supporting evidence in Zip, Aravo, and other program systems. • Escalate novel, complex, or high-risk findings and support Enhanced Due Diligence and risk-acceptance processes when a third party cannot meet Stripe’s security requirements. • Partner with Procurement, Legal, Privacy, Business Continuity, Security, and business stakeholders to resolve assessment issues and support timely third-party onboarding. • Provide practical guidance to Stripe teams on TPSRA requirements, timelines, and their responsibilities throughout the assessment process. • Track assessment volume, aging, service levels, remediation status, and other program-health indicators; use the data to identify trends and recommend improvements. • Identify gaps in program processes, documentation, or tooling and contribute to implementing improvements that increase consistency, scalability, and stakeholder experience. • Contribute to third-party security risk policies, standards, procedures, and guidance. What You'll Need: • 4+ years of relevant experience in third-party security risk, security assessments, information security, or a related risk-management function. • Experience conducting end-to-end third-party security assessments, including reviewing security documentation, identifying control gaps, determining risk, and defining remediation requirements. • Working knowledge of common security and assurance frameworks, such as SOC 2, ISO 27001, PCI DSS, NIST, and CSA. • Sound judgment and analytical skills, including the ability to distinguish material security risks from lower-priority findings and recommend a proportionate response. • Ability to independently manage multiple assessments, priorities, and stakeholder relationships while meeting

View the official posting →

Source: Greenhouse (employer board) First seen: 2026-10-06 Last confirmed: 2026-10-06 How our data works → Report this job

Similar opportunities