You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Early Window: Be the first to open itNo views yetCloses in
Company hidden

Security GRC Program Manager

  • Hybrid
  • 3-6 years

Salary

Not stated

Similar roles pay $115K - 175K a year · our estimate

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

Who we are

About the company

The company is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use the company to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

The the company Security team is dedicated to improving the security of the company and its users. Our users trust us with some of their most sensitive information, and we make security a first-class consideration in everything we do. Security concerns are ever-evolving, creating an extremely dynamic environment for the Security team.

The Security Governance, Risk, and Compliance (SGRC) team helps the company make informed security decisions, understand its risk and control posture, and represent its security program to internal and external stakeholders. The team also manages security risk arising from the company’s relationships with third parties by assessing their security controls, identifying and mitigating risk, and supporting informed onboarding and risk-acceptance decisions. Our work helps the company move quickly while maintaining clear and consistent security expectations.

Responsibilities

  • Independently manage a portfolio of Third Party Security Risk Assessments (TPSRAs) for new engagements, renewals / reassessments, and material changes in relationship scope.
  • Review security questionnaires, independent assurance reports, certifications, penetration-test results, and other evidence to evaluate third-party control effectiveness.
  • Identify security gaps, determine proportionate remediation requirements, and clearly communicate findings to the company DRIs and cross-functional partners.
  • Apply the company’s third-party security standards consistently, documenting assessment results, decisions, and supporting evidence in Zip, Aravo, and other program systems.
  • Escalate novel, complex, or high-risk findings and support Enhanced Due Diligence and risk-acceptance processes when a third party cannot meet the company’s security requirements.
  • Partner with Procurement, Legal, Privacy, Business Continuity, Security, and business stakeholders to resolve assessment issues and support timely third-party onboarding.
  • Provide practical guidance to the company teams on TPSRA requirements, timelines, and their responsibilities throughout the assessment process.
  • Track assessment volume, aging, service levels, remediation status, and other program-health indicators; use the data to identify trends and recommend improvements.
  • Identify gaps in program processes, documentation, or tooling and contribute to implementing improvements that increase consistency, scalability, and stakeholder experience.
  • Contribute to third-party security risk policies, standards, procedures, and guidance.

Requirements

  • 4+ years of relevant experience in third-party security risk, security assessments, information security, or a related risk-management function.
  • Experience conducting end-to-end third-party security assessments, including reviewing security documentation, identifying control gaps, determining risk, and defining remediation requirements.
  • Working knowledge of common security and assurance frameworks, such as SOC 2, ISO 27001, PCI DSS, NIST, and CSA.
  • Sound judgment and analytical skills, including the ability to distinguish material security risks from lower-priority findings and recommend a proportionate response.
  • Ability to independently manage multiple assessments, priorities, and stakeholder relationships while meeting defined timelines.
  • Clear written and verbal communication skills, including the ability to explain technical security findings to non-security stakeholders.
  • Experience using operational data and reporting to identify trends, communicate program health, and improve processes.
  • A collaborative approach and experience working with cross-functional partners such as Procurement, Legal, Privacy, and business teams.
  • Experience with third-party risk management platforms or procurement workflow tools such as Aravo, Zip, or similar systems.
  • Experience with Enhanced Due Diligence, security risk acceptance, or third-party incident response.
  • Experience improving or scaling a third-party risk assessment program

Where you’d work

Part of the week in the office

You can work from

  • United States

About the company

Company hidden

  • Industry: FinTech

Your chances

Still hiring, not crowded yet, and you'd be among the first.

  • 16 checks run
  • 4 good signs
  • 1 red flag

Still hiring?

11 checks

Actively hiring

In its favour3

  • Still on the company's own careers site, checked 1 h agoModerate evidence
  • Found in the last 48 hours, before the big job boardsModerate evidence
  • The company opened 49 roles and closed 42 in the last 2 weeks: hiring is movingModerate evidence

Against it1

  • Vague on the basics: no salary, stack or contract statedModerate evidence

How crowded?

5 checks

Low

In its favour1

  • In its Early Window: not on the big job boards yetStrong evidence

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details10 facts · Role, Location, Compensation, Company
Seniority
Lead
Industry
FinTech
Specialty
Project Manager
Region
United States
Pay period
Annual
Show 5 more factsShow less

Role

Category
Product & Project
Specialty
Project Manager
Seniority
Lead
Experience
4+ years

Location

Work model
Hybrid
Region
United States
Remote from
  • United States

Compensation

Salary
Salary by agreement
Pay period
Annual

Company

Industry
FinTech

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Lead SMB & Channel Sales Program Manager

    €90,000 - 165,000 / year

    • Hybrid · Dublin
    • Lead & Manager
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Technical Program Manager

    $200,000 - 240,000 / year

    • Hybrid · US
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Project Manager

    Salary by agreement

    • Office · Sydney, Australia
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Project Technical Delivery Manager

    Salary by agreement

    • Remote · Europe, Germany
    • Lead & Manager

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason