Stripe logoS

IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg

Stripe

Luxembourg, Luxembourg, LuxembourgFull Time
Apply with OnJob Free profile · takes about a minute

IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg at Stripe is a full time role based in Luxembourg, Luxembourg, Luxembourg. It was published on 4 February 2026 and was open at last check.

IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg at Stripe — key details
RoleIT Governance, Risk & Compliance (GRC) Specialist, Luxembourg
CompanyStripe
LocationLuxembourg, Luxembourg, Luxembourg
Employment typeFull Time
Published4 February 2026
StatusOpen at last check

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

Bridge Building S.A. (BBSA) is the Luxembourg regulated entity of Bridge, a Stripe company. We operate as an EMI and future CASP in one of Europe's most demanding regulatory environments (CSSF, DORA, MiCA).

BBSA is building a local regulated platform powered by a global-first technology model.

What you'll do

In this context, we're looking for an IT GRC Analyst to act as the bridge between strict European regulations and high-velocity global engineering.

This role is the control and risk right hand of the Bridge Global CISO. While our global teams build the tech, you ensure it is compliant, resilient, and audit-ready. You'll translate requirements like DORA and MiCA into tangible IT controls, oversee third-party risks, and maintain the integrity of our governance framework.

This is not a tick-the-box compliance role. It is an operational position for a professional who understands technology well enough to govern it effectively. You'll have high visibility, owning the frameworks that allow us to scale securely.

Responsibilities

IT governance and risk management • Maintain and evolve the IT Risk Register, ensuring risks are identified, assessed, and treated in line with the company's risk appetite. • Drive the local implementation of the DORA (Digital Operational Resilience Act) framework, including ICT risk management and incident classification. • Bridge the gap between technical reality and policy by drafting, reviewing, and updating IT policies and procedures. • Perform periodic control testing to ensure global engineering practices align with local regulatory requirements. • Act as the primary support to the local Head of IT.

Third-party risk management (TPRM) • Support ICT due diligence and risk assessments of critical vendors and service providers, while assisting with Developer and Customer Oversight. • Monitor service level agreements and performance metrics of critical vendors, challenging performance where necessary. • Act as the primary support to the outsourcing manager regarding technical vendor oversight.

Access governance and control (IAG) • Oversee the identity and access governance strategy, including adherence to Segregation of Duties, principle of least privilege, and others. • Conduct periodic user access reviews for critical systems.

Regulatory compliance and audit readiness • Act as the primary liaison for internal audit regarding IT topics. • Prepare technical inputs and evidence for CSSF notifications and regulatory reporting. • Monitor compliance with GDPR and data privacy controls (e.g., DLP oversight, data residency). • Coordinate business continuity (BCP) and disaster recovery (DR) testing documentation and reporting.

Incident governance • Oversee the IT incident management process to ensure proper classification, reporting, and root cause analysis (RCA). • Ensure major incidents are reported to regulators within mandated timeframes, in collaboration with Compliance.

Who you are

Minimum requirements

  • Bachelor's or Master's degree in Information Systems, Cybersecurity, or Business Administration, with a strong IT focus.
  • 3–6 years of experience in IT audit, IT risk, GRC, or information security. • High professional fluency in English.

Preferred qualifications

  • Experience in a regulated sector (Banking, Fintech, or Insurance).
  • Experience at a large-scale public accounting firm in IT risk advisory.
  • Experience with CSSF circulars, EBA guidelines, or DORA.
  • Strong understanding of ISO 27001, NIST, or COBIT.
  • Understanding of cloud fundamentals (AWS).
Share:WhatsAppLinkedIn

Create your free OnJob profile to apply — we'll take you to Stripe's application after sign-up. · Posted 4 Feb 2026.

IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg at Stripe — questions answered

What does the IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg role at Stripe pay?

Stripe does not publish a salary on this IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg listing, so OnJob shows no figure for it rather than an estimate. For what this role pays across the market, the OnJob salary guides aggregate the live listings that do disclose pay.

Where is the IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg role at Stripe based?

Stripe lists this IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg role in Luxembourg, Luxembourg, Luxembourg, advertised as full time work at that location. Larger employers sometimes cover several sites under one city name, so confirm the exact office with Stripe before you apply.

Is the IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg role at Stripe still open?

The IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg posting at Stripe was open at OnJob's last check of the employer's careers page, having been published on 4 February 2026. OnJob re-checks source listings on each build and marks a role closed once it disappears, but listings can close without notice, so the employer's own page is the final word.

How do you apply for the IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg role at Stripe?

Apply to the IT Governance, Risk & Compliance (GRC) Specialist, Luxembourg at Stripe role through OnJob with a free profile: OnJob scores your fit against the listing, shows the skills lowering that score, and submits an ATS-ready profile to Stripe's own application page. Creating a profile is free and needs no card.

Explore more on OnJob

Hiring for a role like this?

Post a job on OnJob and reach AI-matched candidates.

Post a Job