MulaJob

Enterprise Risk Management (ERM) Program & Automation Lead, MALPB

Stripe · US-Remote

Finance & Legal🌍 Remote🇺🇸 United StatesPosted 2026-08-18
Apply on GreenhouseLet AI apply for me

You apply on Stripe's own site — MulaJob never submits anything for you without your say-so.

h2 strong Who we are /strong /h2

h3 strong About Stripe /strong /h3

p span style= font-weight: 400; Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world’s largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. /span /p

h3 strong About the team /strong /h3

p Stripe MALPB operates in a highly complex, fast-moving regulatory environment. The Risk and Compliance team is responsible for ensuring that our expansion is grounded in a bulletproof governance framework that matches the speed of our technology. /p

p Having successfully established our foundational ERM policies, taxonomy, and risk registers, we are entering the integration phase. This team is building the future of AI-Native risk management—where governance frameworks are embedded into daily business operations through automated data pipelines, machine learning, and LLM orchestration. /p

h2 strong What you’ll do /strong /h2

p As the sole dedicated ERM Lead for Stripe MALPB, you will own the enterprise risk program end-to-end. This is a unique hybrid role designed for a technically fluent risk architect. /p

ul

li Roughly 1/3rd of your time will be dedicated to ERM Integration and Execution: rolling out our mature risk framework to the First Line (1LoD), running the RCSA cycle, managing the control library, and synthesizing risk scorecards for executive and Board-level reporting. /li

li Roughly 2/3rds of your time will be dedicated to AI and Control Automation Design: acting as a hands-on developer to build and scale LLM tools, automated evidence-collection scripts, and real-time monitoring workflows that eliminate manual compliance overhead. /li

/ul

h3 strong Responsibilities /strong /h3

h4 strong ERM Framework Integration Execution (1/3rd) /strong /h4

ul

li strong Enterprise Rollout: /strong Drive the cross-functional implementation and adoption of the established ERM framework across all Stripe MALPB business lines and operational functions. /li

li strong RCSA Facilitation: /strong Execute the annual and semi-annual Risk and Control Self-Assessment (RCSA) cycles, providing robust independent 2LoD challenge to 1LoD risk ratings and control effectiveness. /li

li strong Control Library Governance: /strong Maintain the Master Control Library, Central Risk Register, and universal Risk Taxonomy, ensuring strict version control, change management, and alignment with emerging threats. /li

li strong Appetite KRI Monitoring: /strong Aggregate, analyze, and validate Key Risk Indicators (KRIs) against Board-approved Risk Appetite thresholds; trigger formal remediation and Management Action Plans (MAPs) upon breach. /li

li strong Board Executive Reporting: /strong Synthesize quantitative risk metrics and qualitative horizon scanning into the quarterly Enterprise Risk Scorecard for presentation to the Management Risk Committee and the Board of Directors. /li

/ul

h4 strong AI Control Automation Design (2/3rd) /strong /h4

ul

li strong Automated Evidence Collection: /strong Design, write, and deploy automated data extraction pipelines (via SQL and APIs) to systematically sample and pull control verification data from core systems. /li

li strong LLM Orchestration: /strong Build and implement AI/LLM agents to perform semantic analysis on operational logs, policy documents, and compliance records, automatically flagging anomalies or control deficiencies. /li

li strong GRC System Engineering: /strong Partner with technical teams to optimize and configure our GRC infrastructure, implementing automated self-attestation workflows and removing system bottlenecks. /li

li strong Continuous Monitoring: /strong Transition the bank away from passive, point-in-time testing toward a real-time, automated dashboard environment that monitors key operational and regulatory controls dynamically. /li

/ul

h2 strong Who you are /strong /h2

p span style= font-weight: 400; We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement. We are looking for a rare breed of professional: someone with the executive presence to stand up a banking governance program, combined with the hands-on engineering capabilities to automate it themselves. br /span /p

h3 strong Minimum requirements /strong /h3

ul

li strong Experience: /strong 8+ years of experience in enterprise risk management, operational risk, or risk advisory within a regulated financial institution, FinTech, or Big 4 tech-risk consultancy. /li

li strong Execution Track Record: /strong Proven experience successfully rolling out and integrating risk programs (RCSAs, KRIs, Control Libraries) into active, fast-paced operational business units. /li

li strong Technical Proficiency: /strong Hands-on experience writing strong Python /strong and strong SQL /strong to query databases, manipulate data, and interface with standard web/REST APIs. /li

li strong AI/Automation Familiarity: /strong Experience using modern LLM APIs, prompt engineering, or low-code/no-code automated workflow engines to analyze unstructured text or automate routine data tasks. /li

li strong Communication Presence: /strong Exceptional communication skills with a track record of effectively challenging senior business leaders and translating complex risk data into concise, Board-level narratives. /li

li strong Education: /strong A Bachelor's degree in Computer Science, Data Science, Finance, Business, or a related quantitative field. /li

/ul

h3 strong Preferred qualifications /strong /h3

ul

li Prior experience working in a heavily regulated FinTech environment, digital bank, or complex global payments processor. /li

li Deep knowledge of GRC software architecture (e.g., ServiceNow, Archer) and how to scale system configurations. /li

li Familiarity with international banking risk standards and regulatory expectations (e.g., COSO, ISO 31000, OCC Heightened Standards). /li

/ul

More Finance & Legal roles