Engineering Program Manager, Tech Grc

Stripe Stripe · Fintech · United States · 8135 Compliance

Stripe is seeking an Engineering Program Manager for their Technology Compliance team. This role focuses on implementing technology controls, automating evidence collection, and managing governance processes to ensure compliance with global standards like PCI-DSS and SOC. The position requires strong collaboration with engineering teams, program leadership, and data-driven communication to maintain audit readiness and operational resilience in a regulated fintech environment.

What you'd actually do

  1. Own the implementation of baseline technology controls, work with cross-functional teams to automate evidence collection, and contribute to the design of scalable governance and issue-management processes.
  2. Translate risk requirements into practical controls, track remediation progress, and continuously improve controls and workflows to support audit readiness and operational resilience.
  3. Serve as a strategic connector influencing senior stakeholders across infrastructure engineering to balance long-term platform health with feature delivery.
  4. Advise peers on secure / compliant architecture, drive decisions that maintain an always-on audit posture, and ensure compliance is embedded in engineering roadmaps and delivery processes.

Skills

Required

  • Technical compliance
  • Security
  • Risk management
  • Audit programs (ISO, SOC, PCI, UK Cyber Essentials, privacy audits)
  • Control implementation and operation
  • Evidence collection automation
  • Governance and issue management
  • Cross-functional collaboration
  • Program leadership
  • Stakeholder influence
  • Secure/compliant architecture
  • Risk assessment
  • Remediation tracking
  • Data-driven decision making
  • Communication (verbal and written)
  • Presenting to auditors and leadership
  • Program and project management
  • Coordination of cross-functional work streams

Nice to have

  • Acquisition integration experience
  • Fintech or regulated industry background
  • Financial reporting
  • Payment platforms
  • Certifications (CISA, CISSP, PCI-related, ISO lead auditor)

What the JD emphasized

  • Deep technical compliance experience: demonstrable experience implementing and operating controls and audit programs (ISO, SOC, PCI, UK Cyber Essentials, privacy audits, or similar) in complex, distributed environments.
  • Strong engineering collaboration: proven track record working with infrastructure, platform, SRE, and product engineering teams to deliver technical controls and automation.
  • Tooling and automation mindset: experience building scalable tools, frameworks, or platforms that reduce manual evidence collection and audit testing overhead.
  • Program leadership at scale: ability to lead cross‑organizational programs, influence senior engineers and executives, and drive consensus across competing priorities.
  • 12+ years of experience in technical compliance, security, or risk roles with direct responsibility for audit or certification delivery (ISO, SOC, PCI, UK Cyber Essentials, privacy audits, or similar).
  • Demonstrated experience leading end-to-end technical audit certification programs, including scoping, control mapping, evidence collection, remediation, and auditor engagement.
  • Proven track record working closely with infrastructure, platform, SRE, and product engineering teams to implement and operationalize controls.
  • Hands-on experience building or driving tooling/automation for evidence collection, testing, or compliance reporting.
  • Strong program and project management skills with experience coordinating cross-functional work streams and delivering on time against competing priorities.