採用
必須スキル
IT Governance
Risk Management
Compliance
IT Audit
ISO 27001
NIST
COBIT
Cloud Security
Access Control
Incident Management
Secure and Scale a Regulated Fintech Platform at the Heart of Stripe Bridge Building S.A. (BBSA)
is the Luxembourg regulated entity of Bridge, a Stripe company. We operate as an EMI and future CASP in one of Europe’s most demanding regulatory environments (CSSF, DORA, MiCA).
BBSA is building a local regulated platform powered by a global-first technology model. In this context, we are looking for a sharp IT GRC Analyst to act as the bridge between strict European regulations and high-velocity global engineering.
This role is the control and risk right hand of the Luxembourg Head of IT. While our global teams build the tech, you ensure it is compliant, resilient, and audit-ready. You will translate requirements like DORA and MiCA into tangible IT controls, oversee third-party risks, and maintain the integrity of our governance framework.
This is not a "tick-the-box" compliance role. It is a operational position for a professional who understands technology well enough to govern it effectively. You will have high visibility, owning the frameworks that allow us to scale securely.
Key Responsibilities
-
IT Governance & Risk Management
-
Maintain and evolve the IT Risk Register, ensuring risks are identified, assessed, and treated in line with the company’s risk appetite.
-
Drive the local implementation of the DORA (Digital Operational Resilience Act) framework, including ICT risk management and incident classification.
-
Bridge the gap between technical reality and policy by drafting, reviewing, and updating IT policies and procedures.
-
Perform periodic control testing to ensure global engineering practices align with local regulatory requirements.
-
Act as primary support to the local Head of IT
-
Third-Party Risk Management (TPRM)
-
Support ICT due diligence and risk assessments of critical vendors and service providers, while assisting with Developer / Customer Oversight.
-
Monitor SLAs and KPIs of critical vendors, challenging performance where necessary.
-
Act as the primary support to the Outsourcing Manager regarding technical vendor oversight.
-
Access Governance & Control (IAG)
-
Oversee the Identity & Access Governance strategy, including but not limited to adherence to Segregation of Duties, principle of least privileges and others..
-
Conduct periodic User Access Reviews for critical systems.
-
Regulatory Compliance & Audit Readiness
-
Act as the primary liaison for Internal Audit regarding IT topics.
-
Prepare technical inputs and evidence for CSSF notifications and regulatory reporting.
-
Monitor compliance with GDPR/Data Privacy controls (e.g., DLP oversight, data residency).
-
Coordinate Business Continuity (BCP) and Disaster Recovery (DR) testing documentation and reporting.
-
Incident Governance
-
Oversee the IT incident management process to ensure proper classification, reporting, and root cause analysis (RCA).
-
Ensure major incidents are reported to regulators within mandated timeframes (in collaboration with Compliance).
Requirements: Education
- Bachelor’s or Master’s degree in Information Systems, Cybersecurity, or Business Administration (with a strong IT focus).
Experience:
-
3–6 years of experience in IT Audit, IT Risk, GRC, or Information Security.
-
Experience in a regulated sector (Banking, Fintech, Insurance) or Big 4 Audit (IT Risk advisory) is highly preferred.
-
Experience dealing with CSSF circulars, EBA guidelines, or DORA is a strong asset.
-
Core Competencies
-
Framework Knowledge: Strong understanding of ISO 27001, NIST, or COBIT.
-
Tech Literacy: You don't need to code, but you must understand Cloud fundamentals (AWS), SaaS models, and modern infrastructure to audit them effectively.
-
Risk Mindset: Ability to distinguish between theoretical risk and actual business risk.
-
Communication: Ability to explain "Why we need this control" to engineers without slowing them down.
-
Languages
-
English: Fluent professional (Mandatory).
-
French: Asset.
-
Mindset
-
Pragmatic: You value effective controls over bureaucratic paperwork.
-
Resilient: You are comfortable dealing with ambiguity and evolving regulations.
-
Curious: You have a genuine interest in crypto-assets, blockchain, and the future of payments.
総閲覧数
1
応募クリック数
0
模擬応募者数
0
スクラップ
0
類似の求人

Data Security Engineer
Booz Allen Hamilton · Fort Meade, MD

Security Engineer, Red Team, Vehicle Software
Tesla · Palo Alto, California

OPERARIO DE PRODUCCION RESINAS
Sherwin-Williams · Ecuador, EC

Security engineer, detection and response (US)
Writer · San Francisco, CA

Cyber Security Architect/Engineer II
Honeywell · Phoenix, AZ, United States, US
Stripeについて

Stripe
Late StageFinancial infrastructure for the internet
8,000+
従業員数
South San Francisco
本社所在地
$50B
企業価値
レビュー
2.5
9件のレビュー
ワークライフバランス
2.0
報酬
4.0
企業文化
1.8
キャリア
3.2
経営陣
1.5
25%
友人に勧める
良い点
Smart and brilliant coworkers
High compensation and benefits
Challenging and rewarding work
改善点
Toxic culture
Poor work-life balance and overworking
Management and leadership issues
給与レンジ
1,050件のデータ
Mid/L4
Mid/L4 · Brand Risk Strategist
1件のレポート
$198,999
年収総額
基本給
$153,088
ストック
-
ボーナス
-
$198,999
$198,999
面接体験
1件の面接
難易度
3.0
/ 5
面接プロセス
1
Application Review
2
HR Screen
3
Hiring Manager Interview
4
Panel Interview
5
Executive Interview
6
Offer
よくある質問
Leadership Experience
Behavioral/STAR
Management Philosophy
Team Building
Strategic Thinking
ニュース&話題
Stripe doubles down on blockchain and stablecoins, aiming to become 'AWS for money' - CoinDesk
CoinDesk
News
·
3d ago
Once close enough for an acquisition, Stripe and Airwallex are now going after each other - TechCrunch
TechCrunch
News
·
3d ago
Inside Chris Henry Jr. Losing His Black Stripe at Ohio State - Sports Illustrated
Sports Illustrated
News
·
5d ago
Ohio State receiver Chris Henry Jr. loses Buckeyes black stripe - On3
On3
News
·
5d ago