
Security Analyst, Bridge
Stripe · United States
- Hybrid
- Full-time
- $295,000 / year
- United States
Tailored resume — keyword-matched to this role.
Hiring manager — we find who's hiring.
Intro email — drafted to reach them directly.
Job highlights
- Build and scale Bridge security foundation.
- Design GRC programs from ground up.
- Tackle critical security risks pragmatically.
- Collaborate with engineering and product teams.
- Leverage mature security organization's resources.
About the role
About Stripe
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.About The Team
We're creating an entirely new payments platform, built with stablecoins, to simplify global money movement. Bridge enables faster, cheaper payments and borderless access to dollars via stablecoins. Through our APIs, businesses can send and receive funds across borders faster and cheaper vs. SWIFT and other fiat-only rails. Our virtual accounts enable international consumers and businesses to easily access, store, and spend US dollars. Our payouts infrastructure enables platforms to disburse USD to anyone globally. We believe many trillions of dollars will move and settle through stablecoin payment rails. Bridge is pulling this future forward. We have a small team of people who have previously built financial infrastructure at some of the world's leading companies (Coinbase, Stripe, Square, Brex, Upstart, DoorDash, Airbnb), and each and every one of them chose Bridge because they fundamentally believe that stablecoins will be a critical piece of financial infrastructure that allows for the improvement of global money movement.What you'll do
We're hiring a Security Analyst and Program Manager to build and scale the Bridge security foundation. This is a rare opportunity to design the security governance, risk, and compliance programs from the ground up, while also leveraging the infrastructure, best practices, and tooling of one of the most mature security organizations in the industry.Responsibilities
- Design and implement Bridge security governance, risk, and compliance roadmaps from first principles to production.
- Identify and tackle the most important Bridge security risks quickly and pragmatically.
- Adopt Stripe programs, controls, and processes where it makes sense, and find custom approaches where it doesn't.
- Lead risk assessment, control design, and testing for all security and technology oversight globally.
- Reinforce engineering best practices around secure development and infrastructure.
- Ensure Bridge meets compliance and audit expectations as we scale to more regulated markets.
- Collaborate cross-functionally with engineering, product, and the Stripe security organization to move fast without compromising safety.
Who you are
Minimum Requirements- 8+ years of experience in Security GRC.
- Proven experience with regulatory audits from global auditors across security domains.
- Proficiency with NIST CSF, the OCC Cybersecurity Supervision Work Program, the FFIEC IT Examination Handbook, or other similar global frameworks.
- Experience in fast-paced startup environments, building security practices from the ground up.
- Startup mindset—scrappy, pragmatic, and quick to solve the most critical problems.
- Comfort with ambiguity and ability to ruthlessly prioritize.
- Ability to balance security rigor with speed, especially in fast-moving environments.
- Clear communication across technical and non-technical stakeholders.
- Experience building or scaling security programs at a startup or in an embedded role.
- Interest in the potential of crypto and stablecoins to power global financial infrastructure.
Hybrid work at Stripe
This role is available either in an office or a remote location (35+ miles or 56+ km from a Stripe office). In-office expectations Office-assigned Stripes spend at least 50% of the time in a given month in their local office or with users. This hits a balance between bringing people together for in-person collaboration and learning from each other, while supporting flexibility about how to do this in a way that makes sense for individuals and their teams. Working remotely at Stripe A remote location is defined as being 35 miles (56 kilometers) or more from one of our offices. While you would be welcome to come into the office for team/business meetings, on-sites, meet-ups, and events, our expectation is you would regularly work from home rather than a Stripe office. Stripe does not cover the cost of relocating to a remote location. We encourage you to apply for roles that match the location where you currently live or plan to live.Pay and benefits
The annual US base salary range for this role is $196,900 - $295,300. For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role. This salary range may be inclusive of several career levels at Stripe and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location. Applicants interested in this role and who are not located in the US may request the annual salary range for their location during the interview process. Additional benefits for this role may include: equity, company bonus or sales commissions/bonuses; 401(k) plan; medical, dental, and vision benefits; and wellness stipends. Key skills/competency- Security GRC
- Risk Assessment
- Compliance Programs
- Regulatory Audits
- NIST CSF
- FFIEC IT Examination Handbook
- Secure Development
- Technology Oversight
- Cross-functional Collaboration
- Startup Environments
Skills & topics
- Security Analyst
- GRC
- Risk Management
- Compliance
- Audits
- NIST CSF
- FFIEC
- Secure Development
- Financial Technology
- Stablecoins
How to get hired
- Tailor your resume: Highlight your 8+ years of Security GRC experience and success with regulatory audits.
- Showcase your framework knowledge: Emphasize proficiency with NIST CSF, OCC, or FFIEC frameworks.
- Demonstrate startup adaptability: Include examples of building security practices from scratch and handling ambiguity.
- Communicate effectively: Prepare to discuss your experience balancing security rigor with speed for technical and non-technical audiences.
Technical preparation
Master NIST CSF and FFIEC frameworks.,Practice risk assessment and control design.,Study secure development best practices.,Prepare for discussions on global audits.
Behavioral questions
Describe building security from scratch.,How do you handle ambiguity and prioritize?,Balance security rigor with business speed.,Communicate complex security concepts clearly.
Frequently asked questions
- What is the primary focus of the Security Analyst role at Stripe's Bridge team?
- The Security Analyst at Stripe's Bridge team will be responsible for building and scaling the security foundation of their new payments platform. This involves designing security governance, risk, and compliance programs from scratch, identifying and mitigating key risks, and ensuring compliance with global regulations.
- What are the key security frameworks Stripe's Security Analyst needs to be proficient in?
- Stripe's Security Analyst should be proficient in global frameworks such as NIST CSF, the OCC Cybersecurity Supervision Work Program, and the FFIEC IT Examination Handbook. Experience with similar frameworks is also highly valued.
- What kind of experience is considered essential for this Security Analyst position?
- Essential experience includes 8+ years in Security GRC and proven success with regulatory audits from global auditors across various security domains. Experience in fast-paced startup environments, building security practices from the ground up, is also highly preferred.
- How does Stripe support hybrid work for its Security Analyst role?
- The Security Analyst role at Stripe supports hybrid work, allowing for either in-office presence or remote work. Remote employees must be located at least 35 miles (56 km) from a Stripe office, with expectations for regular work from home.
- What is the salary range for the Security Analyst position at Stripe?
- The annual US base salary range for this Security Analyst role is $196,900 - $295,300. This range may be adjusted based on factors like candidate experience, qualifications, and location.
- Does Stripe offer additional benefits for this Security Analyst role?
- Yes, besides the base salary, additional benefits for this role may include equity, company bonuses, a 401(k) plan, comprehensive medical, dental, and vision benefits, and wellness stipends.
- What does 'startup mindset' mean for this Security Analyst role at Stripe?
- A 'startup mindset' for this role means being scrappy, pragmatic, and quick to solve critical problems. It involves comfort with ambiguity, the ability to ruthlessly prioritize, and a balance between security rigor and speed in a fast-moving environment.
- What is the mission of Stripe's Bridge team?
- The mission of Stripe's Bridge team is to simplify global money movement by creating a new payments platform built with stablecoins. They aim to enable faster, cheaper payments and provide borderless access to dollars.