HomeJobsStripe › 8505 Bridge - G&A

IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg

Stripe Luxembourg Full-time 8505 Bridge - G&A Posted Jun 3, 2026
Apply Now →

What it’s like to work at Stripe

Payments Infrastructure · San Francisco

4
Employee Rating
3.6
Work-Life Balance
484
Open Roles
eng-drivenlearningequityproduct-impacttransparent

What employees love

  • Engineering culture is elite — code quality and writing culture are best-in-class
  • Top compensation in fintech — competitive base, equity, and benefits

What could be better

  • Perfectionism can slow shipping — high bar sometimes means slower velocity
  • The 2022-23 layoffs affected morale — company has been rebuilding confidence
View full Stripe culture profile →

About the Role

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

Bridge Building S.A. (BBSA) is the Luxembourg regulated entity of Bridge, a Stripe company. We operate as an EMI and future CASP in one of Europe's most demanding regulatory environments (CSSF, DORA, MiCA).

BBSA is building a local regulated platform powered by a global-first technology model.

What you'll do

In this context, we're looking for an IT GRC Analyst to act as the bridge between strict European regulations and high-velocity global engineering.

This role is the control and risk right hand of the Bridge Global CISO. While our global teams build the tech, you ensure it is compliant, resilient, and audit-ready. You'll translate requirements like DORA and MiCA into tangible IT controls, oversee third-party risks, and maintain the integrity of our governance framework.

This is not a tick-the-box compliance role. It is an operational position for a professional who understands technology well enough to govern it effectively. You'll have high visibility, owning the frameworks that allow us to scale securely.

Responsibilities

IT governance and risk management • Maintain and evolve the IT Risk Register, ensuring risks are identified, assessed, and treated in line with the company's risk appetite. • Drive the local implementation of the DORA (Digital Operational Resilience Act) framework, including ICT risk management and incident classification. • Bridge the gap between technical reality and policy by drafting, reviewing, and updating IT policies and procedures. • Perform periodic control testing to ensure global engineering practices align with local regulatory requirements. • Act as the primary support to the local Head of IT.

Third-party risk management (TPRM) • Support ICT due diligence and risk assessments of critical vendors and service providers, while assisting with Developer and Customer Oversight. • Monitor service level agreements and performance metrics of critical vendors, challenging performance where necessary. • Act as the primary support to the outsourcing manager regarding technical vendor oversight.

Access governance and control (IAG) • Oversee the identity and access governance strategy, including adherence to Segregation of Duties, principle of least privilege, and others. • Conduct periodic user access reviews for critical systems.

Regulatory compliance and audit readiness • Act as the primary liaison for internal audit regarding IT topics. • Prepare technical inputs and evidence for CSSF notifications and regulatory reporting. • Monitor compliance with GDPR and data privacy controls (e.g., DLP oversight, data residency). • Coordinate business continuity (BCP) and disaster recovery (DR) testing documentation and reporting.

Incident governance • Oversee the IT incident management process to ensure proper classification, reporting, and root cause analysis (RCA). • Ensure major incidents are reported to regulators within mandated timeframes, in collaboration with Compliance.

Who you are

Minimum requirements

Preferred qualifications

Similar Roles

More at Stripe
Chief Operating Officer (COO) & Deputy Trust Officer, Bridge
San Francisco, New York, Seattle
Customer Funds Reconciliation and Safeguarding Specialist, Luxembourg
Luxembourg
Commercial Counsel
NYC, SF, Chicago or Remote
Commercial Counsel,APAC
Singapore
EMEA Regulatory Counsel
Dubai , UAE
Similar roles at other companies
AI Compliance Officer
Anthropic · Dublin, IE
Member of Technical Staff, Safety for Agents
Cohere · London
Member of Technical Staff (AI Policy and Strategic Initiatives)
Perplexity AI · San Francisco
Commercial Legal Counsel - Singapore
Mistral AI · Singapore
Counsel, Commercial
Databricks · Bellevue, Washington; Denver, Colorado; Mountain View, California; New York City, New York; San Francisco, California; Seattle, Washington; Washington, D.C.

Frequently Asked Questions

What is the work-life balance like at Stripe?
Stripe has a work-life balance score of 3.6/5 based on employee reviews. This is about average for the AI/tech industry.
What is Stripe’s culture like?
Stripe is characterized by these culture values: eng-driven, learning, equity, product-impact, transparent. Based on employee reviews, the company has an overall rating of 4/5. Engineering culture is elite — code quality and writing culture are best-in-class
How many open roles does Stripe have?
Stripe currently has 484 open roles across departments including engineering, product, sales, and more. Roles are refreshed daily from their careers page.
Is this role remote-friendly?
This role is located in Luxembourg. Check the job description above for specific location and remote work details.
Apply for this role at Stripe →