Security Analyst, Bridge

Stripe Stripe · Fintech · United States · 8504 Bridge - R&D

Stripe's fintech innovation hub, Bridge, is seeking a Security Analyst / Program Manager to build and scale its security foundation. This role involves designing and implementing security governance, risk, and compliance roadmaps from scratch, identifying and mitigating security risks, and reinforcing secure engineering practices. The position requires extensive experience in Security GRC, familiarity with global frameworks like NIST CSF, and proven experience with regulatory audits, with a focus on balancing security rigor with speed in a fast-paced environment.

What you'd actually do

  1. Design, and implement Bridge’s security governance, risk and compliance roadmaps from first principles to production.
  2. Identify and tackle Bridge’s most important security risks quickly and pragmatically.
  3. Adopt Stripe’s programs, controls and processes where it makes sense, and find custom approaches where it doesn’t.
  4. Lead risk assessment, control design and testing for all Security and Technology Oversight globally.
  5. Ensure Bridge meets compliance and audit expectations as we scale to more regulated markets.

Skills

Required

  • 8+ years of experience in Security GRC
  • experience building security practices from the ground up
  • proficient with NIST CSF, OCC’s Cybersecurity Supervision Work Program and/or FFIEC IT Examination Handbook or other similar global frameworks
  • Proven prior experience with regulatory audits from Global auditors across Security domains
  • communicate clearly across technical and non-technical partners
  • experience building or scaling security programs

Nice to have

  • time spent in fast-paced startup environments
  • startup mindset: scrappy, pragmatic, and move quickly
  • Thrive in ambiguity and know how to ruthlessly prioritize
  • excited about the potential of crypto and stablecoins

What the JD emphasized

  • build and scale Bridge’s security foundation
  • design the security governance, risk and compliance programs from the ground up
  • security governance, risk and compliance roadmaps from first principles to production
  • most important security risks
  • meets compliance and audit expectations
  • security rigor with speed